|
|
|
@ -502,6 +502,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
|
|
|
|
|
<li><a href="#_ddos">ddos</a></li>
|
|
|
|
|
<li><a href="#_device">device</a></li>
|
|
|
|
|
<li><a href="#_diameter_attack">diameter-attack</a></li>
|
|
|
|
|
<li><a href="#_diamond_event">diamond-event</a></li>
|
|
|
|
|
<li><a href="#_directory">directory</a></li>
|
|
|
|
|
<li><a href="#_dkim">dkim</a></li>
|
|
|
|
|
<li><a href="#_dns_record">dns-record</a></li>
|
|
|
|
@ -586,6 +587,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
|
|
|
|
|
<li><a href="#_greynoise_ip">greynoise-ip</a></li>
|
|
|
|
|
<li><a href="#_gtp_attack">gtp-attack</a></li>
|
|
|
|
|
<li><a href="#_hashlookup">hashlookup</a></li>
|
|
|
|
|
<li><a href="#_hhhash">hhhash</a></li>
|
|
|
|
|
<li><a href="#_http_request">http-request</a></li>
|
|
|
|
|
<li><a href="#_identity">identity</a></li>
|
|
|
|
|
<li><a href="#_ilr_impact">ilr-impact</a></li>
|
|
|
|
@ -9494,6 +9496,228 @@ diameter-attack is a MISP object available in JSON format at <a href="https://gi
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
<div class="sect1">
|
|
|
|
|
<h2 id="_diamond_event"><a class="anchor" href="#_diamond_event"></a><a class="link" href="#_diamond_event">diamond-event</a></h2>
|
|
|
|
|
<div class="sectionbody">
|
|
|
|
|
<div class="paragraph">
|
|
|
|
|
<p>A diamond model event object consisting of the four diamond features advesary, infrastructure, capability and victim, several meta-features and ioc attributes.</p>
|
|
|
|
|
</div>
|
|
|
|
|
<div class="admonitionblock note">
|
|
|
|
|
<table>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="icon">
|
|
|
|
|
<i class="fa icon-note" title="Note"></i>
|
|
|
|
|
</td>
|
|
|
|
|
<td class="content">
|
|
|
|
|
diamond-event is a MISP object available in JSON format at <a href="https://github.com/MISP/misp-objects/blob/main/objects/diamond-event/definition.json"><strong>this location</strong></a> The JSON format can be freely reused in your application or automatically enabled in <a href="https://www.github.com/MISP/MISP">MISP</a>.
|
|
|
|
|
</td>
|
|
|
|
|
</tr>
|
|
|
|
|
</table>
|
|
|
|
|
</div>
|
|
|
|
|
<table class="tableblock frame-all grid-all stretch">
|
|
|
|
|
<colgroup>
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
</colgroup>
|
|
|
|
|
<thead>
|
|
|
|
|
<tr>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Object attribute</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">MISP attribute type</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Description</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Disable correlation</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Multiple</th>
|
|
|
|
|
</tr>
|
|
|
|
|
</thead>
|
|
|
|
|
<tbody>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Advesary</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The advesary who attacks the victim</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Capability</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The capability used to attack the victim</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Description</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Further context to the event</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Direction</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The network-based direction of the event ['Victim-to-Infrastructure', 'Infrastructure-to-Victim', 'Infrastructure-to-Infrastructure', 'Adversary-to-Infrastructure', 'Infrastructure-to-Adversary', 'Bidirectional', 'Unknown']</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">EventID</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">counter</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Id of the event</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Infrastructure</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The infrastructure used in the attack</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Methodology</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Mitre-Attack mapping of the event</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Phase</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The event mapped to a phase of the killchain ['Reconnaissance', 'Weaponization', 'Delivery', 'Exploitation', 'Installation', 'C2', 'Action on Objectives']</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Resources</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The resources the attacker needed for the event to succeed</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Result</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The result of the event</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Timestamp</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">datetime</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Timestamp when the event happened</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">Victim</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>The attacked victim</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">ioc</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Generic IOC</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-check"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">textfield</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Generic textfield</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-check"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
</tbody>
|
|
|
|
|
</table>
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
<div class="sect1">
|
|
|
|
|
<h2 id="_directory"><a class="anchor" href="#_directory"></a><a class="link" href="#_directory">directory</a></h2>
|
|
|
|
|
<div class="sectionbody">
|
|
|
|
|
<div class="paragraph">
|
|
|
|
@ -39930,6 +40154,111 @@ hashlookup is a MISP object available in JSON format at <a href="https://github.
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
<div class="sect1">
|
|
|
|
|
<h2 id="_hhhash"><a class="anchor" href="#_hhhash"></a><a class="link" href="#_hhhash">hhhash</a></h2>
|
|
|
|
|
<div class="sectionbody">
|
|
|
|
|
<div class="paragraph">
|
|
|
|
|
<p>An object describing a HHHash object with the hash value along with the crawling parameters. For more information: <a href="https://www.foo.be/2023/07/HTTP-Headers-Hashing_HHHash" class="bare">https://www.foo.be/2023/07/HTTP-Headers-Hashing_HHHash</a>.</p>
|
|
|
|
|
</div>
|
|
|
|
|
<div class="admonitionblock note">
|
|
|
|
|
<table>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="icon">
|
|
|
|
|
<i class="fa icon-note" title="Note"></i>
|
|
|
|
|
</td>
|
|
|
|
|
<td class="content">
|
|
|
|
|
hhhash is a MISP object available in JSON format at <a href="https://github.com/MISP/misp-objects/blob/main/objects/hhhash/definition.json"><strong>this location</strong></a> The JSON format can be freely reused in your application or automatically enabled in <a href="https://www.github.com/MISP/MISP">MISP</a>.
|
|
|
|
|
</td>
|
|
|
|
|
</tr>
|
|
|
|
|
</table>
|
|
|
|
|
</div>
|
|
|
|
|
<table class="tableblock frame-all grid-all stretch">
|
|
|
|
|
<colgroup>
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
<col style="width: 20%;">
|
|
|
|
|
</colgroup>
|
|
|
|
|
<thead>
|
|
|
|
|
<tr>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Object attribute</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">MISP attribute type</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Description</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Disable correlation</th>
|
|
|
|
|
<th class="tableblock halign-left valign-top">Multiple</th>
|
|
|
|
|
</tr>
|
|
|
|
|
</thead>
|
|
|
|
|
<tbody>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">comment</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">comment</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>A description of the HHHash object.</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">hhhash</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>HHHash hash in format hhh:version:hash_value</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">hhhash-headers</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>HHHash value before being hash in the format each header is separated by a :.</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">hhhash-query-headers</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Set of headers used for the query in the format where each header is separated by a : .</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-check"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">hhhash-tool</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>HHHash crawling infrastructure or tool used to produce the HHHash value. ['python-hhhash', 'c-hhhash', 'go-hhhash', 'r-hhhash', 'lacus', 'Common Crawl', 'other']</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-check"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
</tbody>
|
|
|
|
|
</table>
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
<div class="sect1">
|
|
|
|
|
<h2 id="_http_request"><a class="anchor" href="#_http_request"></a><a class="link" href="#_http_request">http-request</a></h2>
|
|
|
|
|
<div class="sectionbody">
|
|
|
|
|
<div class="paragraph">
|
|
|
|
@ -49773,6 +50102,19 @@ organization is a MISP object available in JSON format at <a href="https://githu
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">contact_information</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Generic contact information (e-mail, phone number, etc.) for this Organization, with no specific format requirement.</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">date-of-inception</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">datetime</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
@ -49877,6 +50219,19 @@ organization is a MISP object available in JSON format at <a href="https://githu
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">sector</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p>Describing the organization’s sector of activity. ['agriculture', 'aerospace', 'automotive', 'chemical', 'commercial', 'communication', 'construction', 'defense', 'education', 'energy', 'entertainment', 'financial-services', 'government', 'government emergency-services', 'government government-local', 'government-national', 'government-public-services', 'government-regional', 'healthcare', 'hospitality-leasure', 'infrastructure', 'infrastructure dams', 'infrastructure nuclear', 'infrastructure water', 'insurance', 'manufacturing', 'mining', 'non-profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunication', 'transportation', 'utilities']</p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-minus"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
|
<p><span class="icon"><i class="fa fa-check"></i></span></p>
|
|
|
|
|
</div></div></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">type-of-organization</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">text</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
|
|
|
|
@ -74301,6 +74656,21 @@ youtube-video is a MISP object available in JSON format at <a href="https://gith
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">The source object refers to the target object as themself or a representation of themself. Can be a profile on social-networking for example. This value is exclusive of all other XFN values.</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">['XFN']</p></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">redirects-to</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">The source object is redirected to the target object.</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">['misp']</p></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">rendered-as</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">The source object is rendered to the target object.</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">['misp']</p></td>
|
|
|
|
|
</tr>
|
|
|
|
|
<tr>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">known-as</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">The source object is known as the target object.</p></td>
|
|
|
|
|
<td class="tableblock halign-left valign-top"><p class="tableblock">['misp']</p></td>
|
|
|
|
|
</tr>
|
|
|
|
|
</tbody>
|
|
|
|
|
</table>
|
|
|
|
|
</div>
|
|
|
|
@ -74308,7 +74678,7 @@ youtube-video is a MISP object available in JSON format at <a href="https://gith
|
|
|
|
|
</div>
|
|
|
|
|
<div id="footer">
|
|
|
|
|
<div id="footer-text">
|
|
|
|
|
Last updated 2023-06-13 10:07:26 +0200
|
|
|
|
|
Last updated 2023-07-10 16:42:20 +0200
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
</body>
|
|
|
|
|