From eabf9baaf46edbd360ed95eec8cf349304153177 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Sat, 16 Sep 2017 09:36:16 +0200
Subject: [PATCH] Objects updated to the latest version
---
objects.html | 2753 +-
objects.pdf | 77912 +++++++++++++++++++++++++------------------------
2 files changed, 40821 insertions(+), 39844 deletions(-)
diff --git a/objects.html b/objects.html
index 42374a4..2af6c0f 100755
--- a/objects.html
+++ b/objects.html
@@ -452,6 +452,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
origin
url
The link where the leak is (or was) accessible at first-seen.
++
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
++
last-seen
datetime
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
--
sensor
text
origin
url
The link where the leak is (or was) accessible at first-seen.
--
first-seen
datetime
cookie-value
text
Value of the cookie (if splitted)
--
type
text
cookie
cookie
Full cookie
--
text
text
cookie
cookie
Full cookie
++
cookie-value
text
Value of the cookie (if splitted)
++
comment
-comment
card-security-code
text
A description of the card.
+Card security code as embossed or printed on the card.
++
issued
datetime
Initial date of validity or issued date.
++
cc-number
cc-number
credit-card number as encoded on the card.
@@ -730,6 +751,16 @@ credit-card is a MISP object available in JSON format at
comment
comment
A description of the card.
++
name
text
cc-number
cc-number
credit-card number as encoded on the card.
--
issued
datetime
Initial date of validity or issued date.
--
card-security-code
text
Card security code as embossed or printed on the card.
--
ip-src
+ip-src
IP address originating the attack
++
dst-port
port
Destination port of the attack
++
ip-dst
ip-dst
Destination ID (victim)
++
total-pps
counter
protocol
text
total-bps
counter
Protocol used for the attack
+Bits per second
@@ -868,30 +899,10 @@ ddos is a MISP object available in JSON format at
dst-port
port
protocol
text
Destination port of the attack
--
ip-dst
ip-dst
Destination ID (victim)
--
ip-src
ip-src
IP address originating the attack
+Protocol used for the attack
total-bps
counter
Bits per second
--
text
+text
A description of the tuple
++
last-seen
datetime
text
text
A description of the tuple
--
first-seen
datetime
type
entrypoint-address
text
Type of ELF
--
text
text
Free text value to attach to the ELF
+Address of the entry point
os_abi
type
text
Header operating system application binary interface (ABI)
+Type of ELF
@@ -1084,6 +1075,16 @@ elf is a MISP object available in JSON format at
text
text
Free text value to attach to the ELF
++
number-sections
counter
entrypoint-address
os_abi
text
Address of the entry point
+Header operating system application binary interface (ABI)
+
sha1
-sha1
sha384
sha384
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (384 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
@@ -1162,23 +1193,13 @@ elf-section is a MISP object available in JSON format at
sha512/256
sha512/256
text
text
Secure Hash Algorithm 2 (256 bits)
+Free text value to attach to the section
-
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
-+
name
+text
Name of the section
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
flag
text
sha256
sha256
md5
md5
Secure Hash Algorithm 2 (256 bits)
+[Insecure] MD5 hash (128 bits)
@@ -1222,40 +1263,20 @@ elf-section is a MISP object available in JSON format at
name
text
sha1
sha1
Name of the section
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
md5
md5
ssdeep
ssdeep
[Insecure] MD5 hash (128 bits)
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
text
text
Free text value to attach to the section
--
x-mailer
-email-x-mailer
thread-index
email-thread-index
X-Mailer generally tells the program that was used to draft and send the original email
+Identifies a particular conversation thread
++
header
email-header
Full headers
++
to
email-dst
Destination email address
++
from-display-name
email-src-display-name
Display name of the sender
@@ -1370,16 +1401,6 @@ email is a MISP object available in JSON format at
header
email-header
Full headers
--
message-id
email-message-id
thread-index
email-thread-index
Identifies a particular conversation thread
--
send-date
datetime
Date the email has been sent
--
reply-to
email-reply-to
send-date
datetime
Date the email has been sent
++
to-display-name
email-dst-display-name
from-display-name
email-src-display-name
x-mailer
email-x-mailer
Display name of the sender
--
to
email-dst
Destination email address
+X-Mailer generally tells the program that was used to draft and send the original email
@@ -1498,116 +1499,16 @@ file is a MISP object available in JSON format at
filename
filename
sha384
sha384
Filename on disk
+Secure Hash Algorithm 2 (384 bits)
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
authentihash
authentihash
Authenticode executable signature hash
--
mimetype
text
Mime type
--
malware-sample
malware-sample
The file itself (binary)
--
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
entropy
float
Entropy of the whole file
--
tlsh
tlsh
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha224
sha224
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
mimetype
text
Mime type
++
size-in-bytes
size-in-bytes
Size of the file, in bytes
++
authentihash
authentihash
Authenticode executable signature hash
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
++
filename
filename
Filename on disk
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
entropy
float
Entropy of the whole file
++
malware-sample
malware-sample
The file itself (binary)
++
country
+region
text
Country.
+Region.
last-seen
datetime
When the location was seen for the last time.
--
text
text
A generic description of the location.
--
city
text
region
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
++
last-seen
datetime
When the location was seen for the last time.
++
country
text
Region.
+Country.
first-seen
datetime
text
text
When the location was seen for the first time.
+A generic description of the location.
++
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
@@ -1786,20 +1797,10 @@ geolocation is a MISP object available in JSON format at
latitude
float
first-seen
datetime
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
+When the location was seen for the first time.
@@ -1844,26 +1845,6 @@ http-request is a MISP object available in JSON format at
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
--
uri
uri
Request URI
--
basicauth-password
text
proxy-password
text
method
http-method
HTTP Proxy Password
+HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
-
user-agent
user-agent
The user agent string of the user agent
--
content-type
other
The MIME type of the body of the request
--
basicauth-user
text
HTTP Basic Authentication Username
--
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
-+
uri
+uri
Request URI
++
user-agent
user-agent
The user agent string of the user agent
++
basicauth-user
text
HTTP Basic Authentication Username
++
host
hostname
content-type
other
The MIME type of the body of the request
++
proxy-password
text
HTTP Proxy Password
++
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
++
url
url
last-seen
datetime
dst-port
port
Last time the tuple has been seen
+Destination port
@@ -2032,6 +2033,26 @@ ip|port is a MISP object available in JSON format at
ip
ip-dst
IP Address
++
last-seen
datetime
Last time the tuple has been seen
++
text
text
dst-port
port
Destination port
--
first-seen
datetime
ip
ip-dst
IP Address
--
number-sections
-counter
entrypoint-address
text
Number of sections
+Address of the entry point
entrypoint-address
text
text
Address of the entry point
+Free text value to attach to the Mach-O file
++
number-sections
counter
Number of sections
text
text
Free text value to attach to the Mach-O file
--
sha1
-sha1
sha384
sha384
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (384 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
@@ -2218,23 +2249,13 @@ macho-section is a MISP object available in JSON format at
sha512/256
sha512/256
text
text
Secure Hash Algorithm 2 (256 bits)
+Free text value to attach to the section
-
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
-+
sha256
-sha256
Secure Hash Algorithm 2 (256 bits)
--
name
text
sha384
sha384
sha512/256
sha512/256
Secure Hash Algorithm 2 (384 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -2288,10 +2299,20 @@ macho-section is a MISP object available in JSON format at
sha224
sha224
sha1
sha1
Secure Hash Algorithm 2 (224 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
text
text
Free text value to attach to the section
--
time_first
-datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
--
rdata
origin
text
Resource records of the queried resource
+Origin of the Passive DNS response
@@ -2396,10 +2387,10 @@ passive-dns is a MISP object available in JSON format at
rrname
text
zone_time_first
datetime
Resource Record name of the queried resource
+First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
@@ -2426,6 +2417,36 @@ passive-dns is a MISP object available in JSON format at
text
text
+
+
rdata
text
Resource records of the queried resource
++
bailiwick
text
Best estimate of the apex of the zone where this data is authoritative
++
rrtype
text
text
text
time_first
datetime
+
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
@@ -2456,30 +2477,10 @@ passive-dns is a MISP object available in JSON format at
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
origin
rrname
text
Origin of the Passive DNS response
--
bailiwick
text
Best estimate of the apex of the zone where this data is authoritative
+Resource Record name of the queried resource
@@ -2524,10 +2525,110 @@ pe is a MISP object available in JSON format at
file-version
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
++
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
legal-copyright
text
FileVersion in the resources
+LegalCopyright in the resources
++
company-name
text
CompanyName in the resources
++
imphash
imphash
Hash (md5) calculated from the import table
++
text
text
Free text value to attach to the PE
++
number-sections
counter
Number of sections
++
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
++
original-filename
filename
OriginalFilename in the resources
++
entrypoint-address
text
Address of the entry point
++
lang-id
text
Lang ID in the resources
@@ -2544,40 +2645,20 @@ pe is a MISP object available in JSON format at
internal-filename
filename
InternalFilename in the resources
--
entrypoint-section-at-position
file-version
text
Name of the section and position of the section in the PE
+FileVersion in the resources
compilation-timestamp
datetime
product-name
text
Compilation timestamp defined in the PE header
--
number-sections
counter
Number of sections
+ProductName in the resources
@@ -2604,100 +2685,20 @@ pe is a MISP object available in JSON format at
imphash
imphash
Hash (md5) calculated from the import table
--
lang-id
entrypoint-section-at-position
text
Lang ID in the resources
+Name of the section and position of the section in the PE
company-name
text
CompanyName in the resources
--
text
text
Free text value to attach to the PE
--
legal-copyright
text
LegalCopyright in the resources
--
original-filename
internal-filename
filename
OriginalFilename in the resources
--
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
--
product-name
text
ProductName in the resources
--
entrypoint-address
text
Address of the entry point
--
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
+InternalFilename in the resources
@@ -2742,10 +2743,40 @@ pe-section is a MISP object available in JSON format at
sha1
sha1
sha384
sha384
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (384 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
@@ -2762,33 +2793,13 @@ pe-section is a MISP object available in JSON format at
characteristic
text
text
Characteristic of the section
+Free text value to attach to the section
-
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
-+
sha256
-sha256
Secure Hash Algorithm 2 (256 bits)
--
name
text
sha384
sha384
sha512/256
sha512/256
Secure Hash Algorithm 2 (384 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -2842,10 +2843,30 @@ pe-section is a MISP object available in JSON format at
sha224
sha224
sha1
sha1
Secure Hash Algorithm 2 (224 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
characteristic
text
Characteristic of the section
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
text
text
Free text value to attach to the section
--
place-of-birth
-place-of-birth
middle-name
middle-name
Place of birth of a natural person.
--
last-name
last-name
Last name of a natural person.
--
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
--
first-name
first-name
First name of a natural person.
--
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
+Middle name of a natural person
@@ -2980,6 +2941,16 @@ person is a MISP object available in JSON format at
first-name
first-name
First name of a natural person.
++
passport-expiration
passport-expiration
text
text
place-of-birth
place-of-birth
A description of the person or identity.
--
passport-country
passport-country
The country in which the passport was issued.
+Place of birth of a natural person.
nationality
nationality
date-of-birth
date-of-birth
The nationality of a natural person.
+Date of birth of a natural person (in YYYY-MM-DD format).
@@ -3030,15 +2991,55 @@ person is a MISP object available in JSON format at
middle-name
middle-name
nationality
nationality
Middle name of a natural person
+The nationality of a natural person.
passport-country
passport-country
The country in which the passport was issued.
++
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
++
last-name
last-name
Last name of a natural person.
++
text
text
A description of the person or identity.
++
msisdn
+serial-number
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
--
gummei
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+Serial Number.
@@ -3108,30 +3099,20 @@ phone is a MISP object available in JSON format at
imsi
tmsi
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
+Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
guti
msisdn
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
--
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
+MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
@@ -3148,6 +3129,46 @@ phone is a MISP object available in JSON format at
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
++
imsi
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
++
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
++
gummei
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
++
last-seen
datetime
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
--
serial-number
text
Serial Number.
--
refsglobalvar
+callback-average
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
memory-allocations
counter
Amount of memory allocations
--
gml
attachment
Graph export in G>raph Modelling Language format
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
--
r2-commit-version
text
Radare2 commit ID used to generate this object
+Average size of a callback
@@ -3296,56 +3237,6 @@ r2graphity is a MISP object available in JSON format at
total-functions
counter
Total amount of functions in the file.
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
callbacks
counter
Amount of callbacks (functions started as thread)
--
callback-average
counter
Average size of a callback
--
callback-largest
counter
Largest callback
--
total-api
counter
referenced-strings
counter
Amount of referenced strings
--
create-thread
counter
Amount of calls to CreateThread
--
text
text
unknown-references
counter
gml
attachment
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Graph export in G>raph Modelling Language format
shortest-path-to-create-thread
total-functions
counter
Shortest path to the first time the binary calls CreateThread
+Total amount of functions in the file.
@@ -3416,10 +3287,10 @@ r2graphity is a MISP object available in JSON format at
not-referenced-strings
referenced-strings
counter
Amount of not referenced strings
+Amount of referenced strings
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
++
callback-largest
counter
Largest callback
++
create-thread
counter
Amount of calls to CreateThread
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
not-referenced-strings
counter
Amount of not referenced strings
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
r2-commit-version
text
Radare2 commit ID used to generate this object
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
++
get-proc-address
counter
Amount of calls to GetProcAddress
++
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
++
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
++
callbacks
counter
Amount of callbacks (functions started as thread)
++
memory-allocations
counter
Amount of memory allocations
++
An object describing a regular expression (regex or regexp). The object can be linked via a relationship to other attributes or objects to describe how it can be represented as a regular expression..
++ + | ++regexp is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +
---|---|---|---|
regexp |
+text |
+
+ regexp + |
+
+ + |
+
comment |
+comment |
+
+ A description of the regular expression. + |
+
+ + |
+
regexp-type |
+text |
+
+ Type of the regular expression syntax. + |
+
+ + |
+
name
-reg-name
Name of the registry key
--
last-modified
datetime
Last time the registry key has been modified
--
data-type
reg-datatype
data
reg-data
key
reg-key
Data stored in the registry key
+Full key path
key
reg-key
last-modified
datetime
Full key path
+Last time the registry key has been modified
++
name
reg-name
Name of the registry key
++
data
reg-data
Data stored in the registry key
@@ -3572,36 +3641,6 @@ tor-node is a MISP object available in JSON format at
document
text
Raw document from the consensus.
--
nickname
text
router’s nickname.
--
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
--
last-seen
datetime
flags
text
list of flag associated with the node.
--
description
text
Tor node description.
--
version
text
text
text
Tor node comment.
--
published
datetime
fingerprint
text
text
router’s fingerprint.
+Tor node comment.
+
document
text
Raw document from the consensus.
++
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
++
description
text
Tor node description.
++
flags
text
list of flag associated with the node.
++
nickname
text
router’s nickname.
++
fingerprint
text
router’s fingerprint.
++
url
-url
Full URL
--
scheme
text
Scheme
--
subdomain
text
Subdomain
--
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
--
first-seen
datetime
First time this URL has been seen
--
query_string
text
Query (after path, preceded by '?')
--
host
hostname
tld
text
domain
domain
Top-Level Domain
--
port
port
Port number
+Full domain
@@ -3840,10 +3839,30 @@ url is a MISP object available in JSON format at
domain_without_tld
subdomain
text
Domain without Top-Level Domain
+Subdomain
++
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
++
url
url
Full URL
@@ -3860,10 +3879,50 @@ url is a MISP object available in JSON format at
domain
domain
tld
text
Full domain
+Top-Level Domain
++
first-seen
datetime
First time this URL has been seen
++
scheme
text
Scheme
++
query_string
text
Query (after path, preceded by '?')
++
port
port
Port number
domain_without_tld
text
Domain without Top-Level Domain
++
text
-text
Description of the vulnerability
--
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely)
--
modified
datetime
references
link
published
datetime
External references
--
summary
text
Summary of the vulnerability
+Initial publication date
@@ -3978,10 +4017,40 @@ vulnerability is a MISP object available in JSON format at
published
datetime
summary
text
Initial publication date
+Summary of the vulnerability
++
text
text
Description of the vulnerability
++
references
link
External references
++
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely)
@@ -4026,10 +4095,20 @@ whois is a MISP object available in JSON format at
expiration-date
datetime
registar
whois-registar
Expiration of the whois entry
+Registar of the whois entry
++
text
text
Full whois entry
@@ -4056,16 +4135,6 @@ whois is a MISP object available in JSON format at
registrant-email
whois-registrant-email
Registrant email address
--
registrant-phone
whois-registrant-phone
text
text
expiration-date
datetime
Full whois entry
+Expiration of the whois entry
++
registrant-email
whois-registrant-email
Registrant email address
registar
whois-registar
Registar of the whois entry
--
pubkey-info-exponent
+serial-number
text
Exponent of the public key
--
pubkey-info-algorithm
text
Algorithm of the public key
--
version
text
Version of the certificate
--
validity-not-after
datetime
Certificate invalid after that date
--
x509-fingerprint-sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
pubkey-info-modulus
text
Modulus of the public key
+Serial number of the certificate
@@ -4224,20 +4243,30 @@ x509 is a MISP object available in JSON format at
x509-fingerprint-md5
md5
validity-not-after
datetime
[Insecure] MD5 hash (128 bits)
+Certificate invalid after that date
serial-number
validity-not-before
datetime
Certificate invalid before that date
++
version
text
Serial number of the certificate
+Version of the certificate
@@ -4264,20 +4293,10 @@ x509 is a MISP object available in JSON format at
subject
pubkey-info-modulus
text
Subject of the certificate
--
raw-base64
text
Raw certificate base64 encoded
+Modulus of the public key
@@ -4294,10 +4313,60 @@ x509 is a MISP object available in JSON format at
validity-not-before
datetime
x509-fingerprint-sha1
sha1
Certificate invalid before that date
+[Insecure] Secure Hash Algorithm 1 (160 bits)
++
raw-base64
text
Raw certificate base64 encoded
++
x509-fingerprint-md5
md5
[Insecure] MD5 hash (128 bits)
++
subject
text
Subject of the certificate
++
pubkey-info-exponent
text
Exponent of the public key
++
pubkey-info-algorithm
text
Algorithm of the public key
@@ -4342,6 +4411,16 @@ yabin is a MISP object available in JSON format at
whitelist
comment
Whitelist name used to generate the rules.
++
yara
yara
version
comment
comment
yabin.py and regex.txt version used for the generation of the yara rules.
--
whitelist
comment
Whitelist name used to generate the rules.
+A description of Yara rule generated.
@@ -4382,10 +4451,10 @@ yabin is a MISP object available in JSON format at
comment
version
comment
A description of Yara rule generated.
+yabin.py and regex.txt version used for the generation of the yara rules.