diff --git a/objects.html b/objects.html index f03006b..2db7254 100755 --- a/objects.html +++ b/objects.html @@ -472,6 +472,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
type
-text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
--
duplicate_number
counter
Number of known duplicates.
--
sensor
text
origin
text
The link where the leak is (or was) accessible at first-seen.
++
text
text
origin
text
The link where the leak is (or was) accessible at first-seen.
--
first-seen
datetime
last-seen
datetime
When the leak has been accessible or seen for the last time.
++
duplicate
text
last-seen
datetime
duplicate_number
counter
When the leak has been accessible or seen for the last time.
+Number of known duplicates.
+
+
type
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
+
comment
-comment
permission
text
Comment about the set of android permission(s)
+Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
permission
text
comment
comment
Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
+Comment about the set of android permission(s)
@@ -754,16 +755,6 @@ asn is a MISP object available in JSON format at
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
--
export
text
import
text
asn
AS
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
+Autonomous System Number
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
subnet-announced
ip-src
Subnet announced
++
first-seen
datetime
First time the ASN was seen
++
description
text
asn
AS
Autonomous System Number
--
first-seen
datetime
First time the ASN was seen
--
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
--
subnet-announced
ip-src
Subnet announced
--
country
text
import
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
++
datetime
-datetime
text
text
Datetime
+Free text value to attach to the file
@@ -922,10 +923,10 @@ av-signature is a MISP object available in JSON format at
text
text
datetime
datetime
Free text value to attach to the file
+Datetime
@@ -970,20 +971,10 @@ coin-address is a MISP object available in JSON format at
address
btc
first-seen
datetime
Address used as a payment destination in a cryptocurrency
--
text
text
Free text value
+First time this payment destination address has been seen
@@ -1000,6 +991,16 @@ coin-address is a MISP object available in JSON format at
text
text
Free text value
++
symbol
text
first-seen
datetime
address
btc
First time this payment destination address has been seen
+Address used as a payment destination in a cryptocurrency
+
type
+text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
++
text
text
A description of the cookie.
++
cookie-value
text
type
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
--
text
text
A description of the cookie.
--
format
+origin
text
Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
--
notification
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
--
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
+Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
@@ -1186,6 +1167,16 @@ credential is a MISP object available in JSON format at
notification
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
++
text
text
origin
format
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
+Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
++
cc-number
-cc-number
credit-card number as encoded on the card.
--
version
card-security-code
text
Version of the card.
+Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
@@ -1294,6 +1285,26 @@ credit-card is a MISP object available in JSON format at
issued
datetime
Initial date of validity or issued date.
++
cc-number
cc-number
credit-card number as encoded on the card.
++
name
text
card-security-code
version
text
Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
--
issued
datetime
Initial date of validity or issued date.
+Version of the card.
@@ -1362,16 +1363,6 @@ ddos is a MISP object available in JSON format at
domain-dst
domain
Destination domain (victim)
--
ip-src
ip-src
ip-dst
ip-dst
Destination IP (victim)
--
dst-port
port
Destination port of the attack
--
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
--
text
text
Description of the DDoS
--
total-bps
counter
Bits per second
--
src-port
port
first-seen
datetime
text
text
Beginning of the attack
+Description of the DDoS
@@ -1462,6 +1403,46 @@ ddos is a MISP object available in JSON format at
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
domain-dst
domain
Destination domain (victim)
++
first-seen
datetime
Beginning of the attack
++
dst-port
port
Destination port of the attack
++
last-seen
datetime
total-bps
counter
Bits per second
++
ip-dst
ip-dst
Destination IP (victim)
++
ip
-ip-dst
IP Address
--
first-seen
last-seen
datetime
First time the tuple has been seen
+Last time the tuple has been seen
@@ -1540,20 +1531,30 @@ domain-ip is a MISP object available in JSON format at
last-seen
datetime
text
text
Last time the tuple has been seen
+A description of the tuple
text
text
ip
ip-dst
A description of the tuple
+IP Address
++
first-seen
datetime
First time the tuple has been seen
@@ -1598,26 +1599,6 @@ elf is a MISP object available in JSON format at
type
text
Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
--
entrypoint-address
text
Address of the entry point
--
number-sections
counter
text
entrypoint-address
text
Free text value to attach to the ELF
+Address of the entry point
text
text
Free text value to attach to the ELF
++
type
text
Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
++
sha224
-sha224
md5
md5
Secure Hash Algorithm 2 (224 bits)
+[Insecure] MD5 hash (128 bits)
type
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
text
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
+Free text value to attach to the section
@@ -1726,6 +1747,16 @@ elf-section is a MISP object available in JSON format at
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
sha1
sha1
sha512
sha512
sha224
sha224
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (224 bits)
name
text
Name of the section
--
text
text
Free text value to attach to the section
--
entropy
float
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
++
name
text
Name of the section
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
size-in-bytes
size-in-bytes
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
flag
text
ssdeep
ssdeep
sha512
sha512
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (512 bits)
@@ -1894,30 +1895,10 @@ email is a MISP object available in JSON format at
header
email-header
screenshot
attachment
Full headers
--
reply-to
email-reply-to
Email address the reply will be sent to
--
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
+Screenshot of email
@@ -1944,40 +1925,10 @@ email is a MISP object available in JSON format at
subject
email-subject
Subject
--
screenshot
attachment
Screenshot of email
--
from
email-src
Sender email address
--
cc
to
email-dst
Carbon copy
+Destination email address
@@ -1994,10 +1945,20 @@ email is a MISP object available in JSON format at
attachment
email-attachment
message-id
email-message-id
Attachment
+Message ID
++
cc
email-dst
Carbon copy
@@ -2024,20 +1985,60 @@ email is a MISP object available in JSON format at
message-id
email-message-id
reply-to
email-reply-to
Message ID
+Email address the reply will be sent to
to
email-dst
x-mailer
email-x-mailer
Destination email address
+X-Mailer generally tells the program that was used to draft and send the original email
++
from
email-src
Sender email address
++
header
email-header
Full headers
++
subject
email-subject
Subject
++
attachment
email-attachment
Attachment
@@ -2082,60 +2083,30 @@ file is a MISP object available in JSON format at
tlsh
tlsh
md5
md5
Fuzzy hash by Trend Micro: Locality Sensitive Hash
+[Insecure] MD5 hash (128 bits)
sha224
sha224
sha512/256
sha512/256
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (256 bits)
certificate
x509-fingerprint-sha1
sha384
sha384
Certificate value if the binary is signed with another authentication scheme than authenticode
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
+Secure Hash Algorithm 2 (384 bits)
@@ -2152,6 +2123,16 @@ file is a MISP object available in JSON format at
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
authentihash
authentihash
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
++
filename
filename
Filename on disk
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
++
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
entropy
float
sha384
sha384
mimetype
text
Secure Hash Algorithm 2 (384 bits)
+Mime type
-
filename
filename
Filename on disk
-+
mimetype
-text
malware-sample
malware-sample
Mime type
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
+The file itself (binary)
@@ -2242,40 +2273,10 @@ file is a MISP object available in JSON format at
malware-sample
malware-sample
sha512
sha512
The file itself (binary)
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (512 bits)
@@ -2320,16 +2321,46 @@ geolocation is a MISP object available in JSON format at
region
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
text
text
Region.
+A generic description of the location.
++
country
text
Country.
first-seen
datetime
When the location was seen for the first time.
++
longitude
float
region
text
Region.
++
altitude
float
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
city
text
text
text
A generic description of the location.
--
first-seen
datetime
When the location was seen for the first time.
--
country
text
Country.
--
method
-http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
--
proxy-user
basicauth-user
text
HTTP Proxy Username
+HTTP Basic Authentication Username
@@ -2478,56 +2469,6 @@ http-request is a MISP object available in JSON format at
url
url
Full HTTP Request URL
--
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
--
basicauth-user
text
HTTP Basic Authentication Username
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
--
user-agent
user-agent
The user agent string of the user agent
--
uri
uri
proxy-password
text
HTTP Proxy Password
--
basicauth-password
text
content-type
other
user-agent
user-agent
The MIME type of the body of the request
+The user agent string of the user agent
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
++
host
hostname
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
++
proxy-password
text
HTTP Proxy Password
++
url
url
Full HTTP Request URL
++
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
++
proxy-user
text
HTTP Proxy Username
++
content-type
other
The MIME type of the body of the request
++
text
+text
Description of the tuple
++
dst-port
port
last-seen
datetime
Last time the tuple has been seen
--
first-seen
datetime
text
text
last-seen
datetime
Description of the tuple
+Last time the tuple has been seen
@@ -2714,16 +2715,6 @@ ja3 is a MISP object available in JSON format at
ja3-fingerprint-md5
md5
Hash identifying source
--
ip-src
ip-src
ip-dst
ip-dst
ja3-fingerprint-md5
md5
Destination IP address
+Hash identifying source
last-seen
datetime
Last seen of the SSL/TLS handshake
--
first-seen
datetime
last-seen
datetime
Last seen of the SSL/TLS handshake
++
ip-dst
ip-dst
Destination IP address
++
type
+text
text
Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
--
entrypoint-address
text
Address of the entry point
+Free text value to attach to the Mach-O file
@@ -2852,15 +2843,25 @@ macho is a MISP object available in JSON format at
text
entrypoint-address
text
Free text value to attach to the Mach-O file
+Address of the entry point
type
text
Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
++
sha224
-sha224
md5
md5
Secure Hash Algorithm 2 (224 bits)
+[Insecure] MD5 hash (128 bits)
sha512/224
sha512/224
sha512/256
sha512/256
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (256 bits)
sha1
sha1
sha384
sha384
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (384 bits)
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
name
text
Name of the section
--
text
text
entropy
float
sha512/224
sha512/224
Entropy of the whole section
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -3000,6 +2961,46 @@ macho-section is a MISP object available in JSON format at
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
entropy
float
Entropy of the whole section
++
name
text
Name of the section
++
sha256
sha256
sha512/256
sha512/256
size-in-bytes
size-in-bytes
Secure Hash Algorithm 2 (256 bits)
+Size of the section, in bytes
+
md5
md5
sha512
sha512
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (512 bits)
@@ -3068,36 +3069,6 @@ microblog is a MISP object available in JSON format at
removal-date
datetime
When the microblog post was removed
--
post
text
Raw post
--
type
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
--
username
text
link
url
creation-date
datetime
Link into the microblog post
+Initial creation of the microblog post
@@ -3128,6 +3099,16 @@ microblog is a MISP object available in JSON format at
link
url
Link into the microblog post
++
username-quoted
text
post
text
Raw post
++
modification-date
datetime
creation-date
type
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
++
removal-date
datetime
Initial creation of the microblog post
+When the microblog post was removed
@@ -3196,6 +3197,26 @@ netflow is a MISP object available in JSON format at
ip-src
ip-src
IP address source of the netflow
++
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
++
direction
text
src-as
AS
first-packet-seen
datetime
Source AS number for this flow
+First packet seen in this flow
@@ -3226,13 +3247,23 @@ netflow is a MISP object available in JSON format at
byte-count
counter
dst-as
AS
Bytes counted in this flow
+Destination AS number for this flow
+
+
dst-port
port
Destination port of the netflow
+
dst-as
-AS
Destination AS number for this flow
--
ip-protocol-number
size-in-bytes
IP protocol number of this flow
--
packet-count
ip_version
counter
Packets counted in this flow
+IP version of this flow
@@ -3306,40 +3317,10 @@ netflow is a MISP object available in JSON format at
ip-src
ip-src
IP address source of the netflow
--
dst-port
port
Destination port of the netflow
--
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
--
ip_version
byte-count
counter
IP version of this flow
+Bytes counted in this flow
@@ -3356,15 +3337,35 @@ netflow is a MISP object available in JSON format at
first-packet-seen
datetime
ip-protocol-number
size-in-bytes
First packet seen in this flow
+IP protocol number of this flow
++
src-as
AS
Source AS number for this flow
packet-count
counter
Packets counted in this flow
++
zone_time_last
-datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
text
bailiwick
text
+
Best estimate of the apex of the zone where this data is authoritative
@@ -3444,61 +3425,11 @@ passive-dns is a MISP object available in JSON format at
rdata
text
text
Resource records of the queried resource
-
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
--
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
--
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
origin
text
Origin of the Passive DNS response
--
sensor_id
text
Sensor information where the record was seen
-
bailiwick
+time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
++
sensor_id
text
Best estimate of the apex of the zone where this data is authoritative
+Sensor information where the record was seen
++
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
origin
text
Origin of the Passive DNS response
++
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
++
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
rdata
text
Resource records of the queried resource
++
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
@@ -3562,30 +3563,10 @@ paste is a MISP object available in JSON format at
title
origin
text
Title of the paste or post.
--
last-seen
datetime
When the paste has been accessible or seen for the last time.
--
paste
text
Raw text of the paste or post
+Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
@@ -3602,20 +3583,40 @@ paste is a MISP object available in JSON format at
origin
text
url
url
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
+Link to the original source of the paste or post.
url
url
paste
text
Link to the original source of the paste or post.
+Raw text of the paste or post
++
last-seen
datetime
When the paste has been accessible or seen for the last time.
++
title
text
Title of the paste or post.
@@ -3660,30 +3661,30 @@ pe is a MISP object available in JSON format at
file-version
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
++
company-name
text
FileVersion in the resources
+CompanyName in the resources
type
product-version
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
legal-copyright
text
LegalCopyright in the resources
+ProductVersion in the resources
@@ -3700,6 +3701,16 @@ pe is a MISP object available in JSON format at
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
entrypoint-section-at-position
text
company-name
file-version
text
CompanyName in the resources
+FileVersion in the resources
imphash
imphash
Hash (md5) calculated from the import table
--
product-name
text
ProductName in the resources
--
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
internal-filename
filename
InternalFilename in the resources
--
pehash
pehash
number-sections
counter
imphash
imphash
Number of sections
--
original-filename
filename
OriginalFilename in the resources
+Hash (md5) calculated from the import table
product-version
type
text
ProductVersion in the resources
+Type of PE ['exe', 'dll', 'driver', 'unknown']
++
product-name
text
ProductName in the resources
++
number-sections
counter
Number of sections
@@ -3810,6 +3791,26 @@ pe is a MISP object available in JSON format at
original-filename
filename
OriginalFilename in the resources
++
legal-copyright
text
LegalCopyright in the resources
++
file-description
text
internal-filename
filename
InternalFilename in the resources
++
lang-id
text
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
--
sha224
-sha224
md5
md5
Secure Hash Algorithm 2 (224 bits)
+[Insecure] MD5 hash (128 bits)
characteristic
text
sha512/256
sha512/256
Characteristic of the section ['read', 'write', 'executable']
+Secure Hash Algorithm 2 (256 bits)
sha512/224
sha512/224
sha384
sha384
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (384 bits)
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
--
text
text
entropy
float
sha512/224
sha512/224
Entropy of the whole section
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -3988,6 +3939,56 @@ pe-section is a MISP object available in JSON format at
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
characteristic
text
Characteristic of the section ['read', 'write', 'executable']
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
entropy
float
Entropy of the whole section
++
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
++
sha256
sha256
sha512/256
sha512/256
size-in-bytes
size-in-bytes
Secure Hash Algorithm 2 (256 bits)
+Size of the section, in bytes
+
md5
md5
sha512
sha512
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (512 bits)
@@ -4056,66 +4057,6 @@ person is a MISP object available in JSON format at
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
--
passport-number
passport-number
The passport number of a natural person.
--
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
--
text
text
A description of the person or identity.
--
last-name
last-name
Last name of a natural person.
--
first-name
first-name
First name of a natural person.
--
place-of-birth
place-of-birth
nationality
nationality
The nationality of a natural person.
--
passport-expiration
passport-expiration
The expiration date of a passport.
--
middle-name
middle-name
passport-country
passport-country
first-name
first-name
The country in which the passport was issued.
+First name of a natural person.
last-name
last-name
Last name of a natural person.
++
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
++
passport-number
passport-number
The passport number of a natural person.
++
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
++
nationality
nationality
The nationality of a natural person.
++
passport-country
passport-country
The country in which the passport was issued.
++
passport-expiration
passport-expiration
The expiration date of a passport.
++
text
text
A description of the person or identity.
++
gummei
+msisdn
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
@@ -4234,60 +4235,10 @@ phone is a MISP object available in JSON format at
imei
gummei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
--
last-seen
datetime
When the phone has been accessible or seen for the last time.
--
msisdn
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
--
text
text
A description of the phone.
--
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
--
imsi
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
+Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
@@ -4304,6 +4255,46 @@ phone is a MISP object available in JSON format at
text
text
A description of the phone.
++
imsi
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
++
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
++
last-seen
datetime
When the phone has been accessible or seen for the last time.
++
serial-number
text
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
++
memory-allocations
-counter
Amount of memory allocations
--
text
text
Description of the r2graphity object
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
not-referenced-strings
counter
Amount of not referenced strings
--
total-functions
counter
total-api
counter
Total amount of API calls
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
callback-average
counter
Average size of a callback
--
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
--
gml
attachment
Graph export in G>raph Modelling Language format
--
r2-commit-version
text
text
Radare2 commit ID used to generate this object
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
+Description of the r2graphity object
@@ -4502,20 +4393,40 @@ r2graphity is a MISP object available in JSON format at
ratio-functions
float
gml
attachment
Ratio: amount of functions per kilobyte of code section
+Graph export in G>raph Modelling Language format
callback-largest
total-api
counter
Largest callback
+Total amount of API calls
++
not-referenced-strings
counter
Amount of not referenced strings
++
r2-commit-version
text
Radare2 commit ID used to generate this object
@@ -4542,10 +4453,70 @@ r2graphity is a MISP object available in JSON format at
local-references
memory-allocations
counter
Amount of API calls inside a code section
+Amount of memory allocations
++
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
callback-largest
counter
Largest callback
++
get-proc-address
counter
Amount of calls to GetProcAddress
++
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
@@ -4562,10 +4533,40 @@ r2graphity is a MISP object available in JSON format at
unknown-references
local-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Amount of API calls inside a code section
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
callback-average
counter
Average size of a callback
++
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
@@ -4620,16 +4621,6 @@ regexp is a MISP object available in JSON format at
type
text
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
--
regexp
text
type
text
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
++
key
-regkey
data
text
Full key path
--
last-modified
datetime
Last time the registry key has been modified
+Data stored in the registry key
@@ -4718,16 +4709,6 @@ registry-key is a MISP object available in JSON format at
data-type
text
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
--
name
text
data
data-type
text
Data stored in the registry key
+Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
++
last-modified
datetime
Last time the registry key has been modified
++
key
regkey
Full key path
@@ -4786,20 +4787,20 @@ report is a MISP object available in JSON format at
summary
case-number
text
Free text summary of the report
+Case number
case-number
summary
text
Case number
+Free text summary of the report
@@ -4844,16 +4845,6 @@ rtir is a MISP object available in JSON format at
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
--
status
text
ticket-number
text
ip
ip-dst
ticket-number of the RTIR ticket
+IPs automatically extracted from the RTIR ticket
classification
queue
text
Classification of the RTIR ticket
+Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
++
ticket-number
text
ticket-number of the RTIR ticket
@@ -4904,10 +4905,68 @@ rtir is a MISP object available in JSON format at
ip
ip-dst
classification
text
IPs automatically extracted from the RTIR ticket
+Classification of the RTIR ticket
++
An object describing a STIX pattern. The object can be linked via a relationship to other attributes or objects to describe how it can be represented as a STIX pattern..
++ + | ++stix2-pattern is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +|||||
---|---|---|---|---|---|---|---|---|
comment |
+comment |
+
+ A description of the stix2-pattern. + |
+
+ + |
+|||||
stix2-pattern |
+stix2-pattern |
+
+ STIX 2 pattern |
@@ -4952,30 +5011,10 @@ tor-node is a MISP object available in JSON format at published |
-datetime |
-
- router’s publication time. This can be different from first-seen and last-seen. - |
-
- - |
-||
description |
+flags |
text |
- Tor node description. - |
-
- - |
-||||
version |
-text |
-
- parsed version of tor, this is None if the relay’s using a new versioning scheme. +list of flag associated with the node. |
@@ -4992,13 +5031,13 @@ tor-node is a MISP object available in JSON format at first-seen |
-datetime |
+fingerprint |
+text |
- When the Tor node designed by the IP address has been seen for the first time. +router’s fingerprint. |
- +
|
text |
-
- router’s nickname. - |
-
- - |
-||||||
version_line |
text |
@@ -5032,16 +5061,56 @@ tor-node is a MISP object available in JSON format at flags |
+nickname |
text |
- list of flag associated with the node. +router’s nickname. |
|
||
version |
+text |
+
+ parsed version of tor, this is None if the relay’s using a new versioning scheme. + |
+
+ + |
+|||||
first-seen |
+datetime |
+
+ When the Tor node designed by the IP address has been seen for the first time. + |
+
+ + |
+|||||
description |
+text |
+
+ Tor node description. + |
+
+ + |
+|||||
document |
+text |
+
+ Raw document from the consensus. + |
+
+ + |
+|||||
last-seen |
datetime |
@@ -5052,20 +5121,10 @@ tor-node is a MISP object available in JSON format at fingerprint |
-text |
+published |
+datetime |
- router’s fingerprint. - |
-
- - |
-|
document |
-text |
-
- Raw document from the consensus. +router’s publication time. This can be different from first-seen and last-seen. |
@@ -5110,60 +5169,10 @@ url is a MISP object available in JSON format at tld |
+query_string |
text |
- Top-Level Domain - |
-
- - |
-|
credential |
-text |
-
- Credential (username, password) - |
-
- - |
-|||||
fragment |
-text |
-
- Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource. - |
-
- - |
-|||||
first-seen |
-datetime |
-
- First time this URL has been seen - |
-
- - |
-|||||
port |
-port |
-
- Port number - |
-
- - |
-|||||
url |
-url |
-
- Full URL +Query (after path, preceded by '?') |
@@ -5180,40 +5189,20 @@ url is a MISP object available in JSON format at scheme |
+domain_without_tld |
text |
- Scheme ['http', 'https', 'ftp', 'gopher', 'sip'] - |
-
- - |
-|
query_string |
-text |
-
- Query (after path, preceded by '?') +Domain without Top-Level Domain |
|
|||||
resource_path |
-text |
+url |
+url |
- Path (between hostname:port and query) - |
-
- - |
-|||
domain |
-domain |
-
- Full domain +Full URL |
@@ -5230,20 +5219,10 @@ url is a MISP object available in JSON format at domain_without_tld |
+scheme |
text |
- Domain without Top-Level Domain - |
-
- - |
-|
subdomain |
-text |
-
- Subdomain +Scheme ['http', 'https', 'ftp', 'gopher', 'sip'] |
||||||
credential |
+text |
+
+ Credential (username, password) + |
+
+ + |
+|||||
domain |
+domain |
+
+ Full domain + |
+
+ + |
+|||||
port |
+port |
+
+ Port number + |
+
+ + |
+|||||
tld |
+text |
+
+ Top-Level Domain + |
+
+ + |
+|||||
first-seen |
+datetime |
+
+ First time this URL has been seen + |
+
+ + |
+|||||
fragment |
+text |
+
+ Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource. + |
+
+ + |
+|||||
resource_path |
+text |
+
+ Path (between hostname:port and query) + |
+
+ + |
+|||||
subdomain |
+text |
+
+ Subdomain + |
+
+ + |
+
roles
-text
The list of roles targeted within the victim.
--
sectors
text
description
text
target-email
Description of the victim
+The email address(es) of the user targeted.
ip-address
ip-dst
user
target-user
IP address(es) of the node targeted.
+The username(s) of the user targeted.
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
--
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
--
node
target-machine
user
target-user
ip-address
ip-dst
The username(s) of the user targeted.
+IP address(es) of the node targeted.
++
description
text
Description of the victim
@@ -5398,15 +5437,35 @@ victim is a MISP object available in JSON format at
target-email
roles
text
The email address(es) of the user targeted.
+The list of roles targeted within the victim.
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
++
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
++
last-submission
-datetime
Last Submission
--
permalink
link
Permalink Reference
--
community-score
text
detection-ratio
text
Detection Ratio
++
first-submission
datetime
detection-ratio
text
permalink
link
Detection Ratio
+Permalink Reference
+
+
last-submission
datetime
Last Submission
+
published
-datetime
Initial publication date
--
references
link
text
text
Description of the vulnerability
--
vulnerable_configuration
text
summary
text
text
Summary of the vulnerability
+Description of the vulnerability
published
datetime
Initial publication date
++
summary
text
Summary of the vulnerability
++
registrant-org
-whois-registrant-org
nameserver
hostname
Registrant organisation
+Nameserver
-
registrant-email
whois-registrant-email
Registrant email address
--
domain
domain
Domain of the whois entry
-+
+
+
registrant-org
whois-registrant-org
Registrant organisation
+
-
modification-date
datetime
Last update of the whois entry
-+
domain
+domain
Domain of the whois entry
++
registrant-name
whois-registrant-name
registrant-email
whois-registrant-email
Registrant email address
++
modification-date
datetime
Last update of the whois entry
++
text
+text
Free text description of hte certificate
++
raw-base64
text
Raw certificate base64 encoded
++
validity-not-before
datetime
Certificate invalid before that date
++
pubkey-info-exponent
text
serial-number
text
Serial number of the certificate
++
issuer
text
Issuer of the certificate
++
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
x509-fingerprint-sha256
x509-fingerprint-sha256
text
text
x509-fingerprint-md5
x509-fingerprint-md5
Free text description of hte certificate
--
issuer
text
Issuer of the certificate
--
subject
text
Subject of the certificate
--
raw-base64
text
Raw certificate base64 encoded
--
serial-number
text
Serial number of the certificate
--
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
validity-not-before
datetime
Certificate invalid before that date
+[Insecure] MD5 hash (128 bits)
@@ -5890,10 +5959,20 @@ x509 is a MISP object available in JSON format at
pubkey-info-algorithm
subject
text
Algorithm of the public key
+Subject of the certificate
++
pubkey-info-size
text
Length of the public key (in bits)
@@ -5910,20 +5989,10 @@ x509 is a MISP object available in JSON format at
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
--
pubkey-info-size
pubkey-info-algorithm
text
Length of the public key (in bits)
+Algorithm of the public key
@@ -5978,10 +6047,10 @@ yabin is a MISP object available in JSON format at
whitelist
version
comment
Whitelist name used to generate the rules.
+yabin.py and regex.txt version used for the generation of the yara rules.
@@ -6008,10 +6077,10 @@ yabin is a MISP object available in JSON format at
version
whitelist
comment
yabin.py and regex.txt version used for the generation of the yara rules.
+Whitelist name used to generate the rules.