The advesary who attacks the victim
+A diamond model event object consisting of the four diamond features advesary, infrastructure, capability and victim, several meta-features and ioc attributes.
++ + | ++diamond-event is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +Multiple | +
---|---|---|---|---|
Advesary |
+text |
+
+ The advesary who attacks the victim + |
+
+ + |
+
+ + |
+
Capability |
+text |
+
+ The capability used to attack the victim + |
+
+ + |
+
+ + |
+
Description |
+text |
+
+ Further context to the event + |
+
+ + |
+
+ + |
+
Direction |
+text |
+
+ The network-based direction of the event ['Victim-to-Infrastructure', 'Infrastructure-to-Victim', 'Infrastructure-to-Infrastructure', 'Adversary-to-Infrastructure', 'Infrastructure-to-Adversary', 'Bidirectional', 'Unknown'] + |
+
+ + |
+
+ + |
+
EventID |
+counter |
+
+ Id of the event + |
+
+ + |
+
+ + |
+
Infrastructure |
+text |
+
+ The infrastructure used in the attack + |
+
+ + |
+
+ + |
+
Methodology |
+text |
+
+ Mitre-Attack mapping of the event + |
+
+ + |
+
+ + |
+
Phase |
+text |
+
+ The event mapped to a phase of the killchain ['Reconnaissance', 'Weaponization', 'Delivery', 'Exploitation', 'Installation', 'C2', 'Action on Objectives'] + |
+
+ + |
+
+ + |
+
Resources |
+text |
+
+ The resources the attacker needed for the event to succeed + |
+
+ + |
+
+ + |
+
Result |
+text |
+
+ The result of the event + |
+
+ + |
+
+ + |
+
Timestamp |
+datetime |
+
+ Timestamp when the event happened + |
+
+ + |
+
+ + |
+
Victim |
+text |
+
+ The attacked victim + |
+
+ + |
+
+ + |
+
ioc |
+text |
+
+ Generic IOC + |
+
+ + |
+
+ + |
+
textfield |
+text |
+
+ Generic textfield + |
+
+ + |
+
+ + |
+
An object describing a HHHash object with the hash value along with the crawling parameters. For more information: https://www.foo.be/2023/07/HTTP-Headers-Hashing_HHHash.
++ + | ++hhhash is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +Multiple | +
---|---|---|---|---|
comment |
+comment |
+
+ A description of the HHHash object. + |
+
+ + |
+
+ + |
+
hhhash |
+text |
+
+ HHHash hash in format hhh:version:hash_value + |
+
+ + |
+
+ + |
+
hhhash-headers |
+text |
+
+ HHHash value before being hash in the format each header is separated by a :. + |
+
+ + |
+
+ + |
+
hhhash-query-headers |
+text |
+
+ Set of headers used for the query in the format where each header is separated by a : . + |
+
+ + |
+
+ + |
+
hhhash-tool |
+text |
+
+ HHHash crawling infrastructure or tool used to produce the HHHash value. ['python-hhhash', 'c-hhhash', 'go-hhhash', 'r-hhhash', 'lacus', 'Common Crawl', 'other'] + |
+
+ + |
+
+ + |
+
contact_information
+text
Generic contact information (e-mail, phone number, etc.) for this Organization, with no specific format requirement.
++
+
date-of-inception
datetime
sector
text
Describing the organization’s sector of activity. ['agriculture', 'aerospace', 'automotive', 'chemical', 'commercial', 'communication', 'construction', 'defense', 'education', 'energy', 'entertainment', 'financial-services', 'government', 'government emergency-services', 'government government-local', 'government-national', 'government-public-services', 'government-regional', 'healthcare', 'hospitality-leasure', 'infrastructure', 'infrastructure dams', 'infrastructure nuclear', 'infrastructure water', 'insurance', 'manufacturing', 'mining', 'non-profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunication', 'transportation', 'utilities']
++
+
type-of-organization
text
The source object refers to the target object as themself or a representation of themself. Can be a profile on social-networking for example. This value is exclusive of all other XFN values.
['XFN']
redirects-to
The source object is redirected to the target object.
['misp']
rendered-as
The source object is rendered to the target object.
['misp']
known-as
The source object is known as the target object.
['misp']