diff --git a/objects.html b/objects.html
index 190b0d9..814beb2 100755
--- a/objects.html
+++ b/objects.html
@@ -589,40 +589,10 @@ ail-leak is a MISP object available in JSON format at last-seen
original-date
datetime
When the leak has been accessible or seen for the last time.
--
duplicate_number
counter
Number of known duplicates.
--
origin
text
The link where the leak is (or was) accessible at first-seen.
--
first-seen
datetime
When the leak has been accessible or seen for the first time.
+When the information available in the leak was created. It’s usually before the first-seen.
@@ -639,6 +609,16 @@ ail-leak is a MISP object available in JSON format at
origin
text
The link where the leak is (or was) accessible at first-seen.
++
duplicate
text
first-seen
datetime
When the leak has been accessible or seen for the first time.
++
last-seen
datetime
When the leak has been accessible or seen for the last time.
++
raw-data
attachment
original-date
datetime
duplicate_number
counter
When the information available in the leak was created. It’s usually before the first-seen.
+Number of known duplicates.
+
creation-date
-datetime
ref
link
Initial creation of the annotation
+Reference(s) to the annotation
ref
link
creation-date
datetime
Reference(s) to the annotation
+Initial creation of the annotation
@@ -873,13 +873,13 @@ asn is a MISP object available in JSON format at
last-seen
datetime
description
text
Last time the ASN was seen
+Description of the autonomous system
+
mp-import
-text
first-seen
datetime
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+First time the ASN was seen
-
description
text
Description of the autonomous system
-+
mp-export
-text
last-seen
datetime
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+Last time the ASN was seen
+
mp-export
+text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
subnet-announced
ip-src
first-seen
datetime
mp-import
text
First time the ASN was seen
+The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+
text
-text
datetime
datetime
Free text value to attach to the file
+Datetime
@@ -1031,10 +1031,10 @@ av-signature is a MISP object available in JSON format at
datetime
datetime
text
text
Datetime
+Free text value to attach to the file
@@ -1089,40 +1089,20 @@ bank-account is a MISP object available in JSON format at
status-code
report-code
text
Account status at the time of the transaction processed. ['A - Active', 'B - Inactive', 'C - Dormant']
+Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic']
institution-name
balance
text
Name of the bank or financial organisation.
--
swift
bic
SWIFT or BIC as defined in ISO 9362.
--
beneficiary
text
Final beneficiary of the bank account.
+The balance of the account after the suspicious transaction was processed.
@@ -1139,130 +1119,10 @@ bank-account is a MISP object available in JSON format at
text
currency-code
text
A description of the bank account.
--
report-code
text
Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic']
--
iban
iban
IBAN of the bank account.
--
branch
text
Branch code or name
--
non-banking-institution
boolean
A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation.
--
comments
text
Comments about the bank account.
--
client-number
text
Client number as seen by the bank.
--
balance
text
The balance of the account after the suspicious transaction was processed.
--
date-balance
datetime
When the balance was reported.
--
beneficiary-comment
text
Comment about the final beneficiary.
--
account-name
text
A field to freely describe the bank account details.
--
opened
datetime
When the account was opened.
--
institution-code
text
Institution code of the bank.
+Currency of the account. ['USD', 'EUR']
@@ -1279,6 +1139,56 @@ bank-account is a MISP object available in JSON format at
iban
iban
IBAN of the bank account.
++
comments
text
Comments about the bank account.
++
institution-code
text
Institution code of the bank.
++
beneficiary-comment
text
Comment about the final beneficiary.
++
status-code
text
Account status at the time of the transaction processed. ['A - Active', 'B - Inactive', 'C - Dormant']
++
closed
datetime
currency-code
text
text
Currency of the account. ['USD', 'EUR']
+A description of the bank account.
++
institution-name
text
Name of the bank or financial organisation.
++
non-banking-institution
boolean
A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation.
++
opened
datetime
When the account was opened.
++
swift
bic
SWIFT or BIC as defined in ISO 9362.
++
client-number
text
Client number as seen by the bank.
++
date-balance
datetime
When the balance was reported.
branch
text
Branch code or name
++
beneficiary
text
Final beneficiary of the bank account.
++
account-name
text
A field to freely describe the bank account details.
++
code
+note
text
The code denoting the special handling of the alert message.
+The text describing the purpose or significance of the alert message.
@@ -1367,40 +1367,10 @@ cap-alert is a MISP object available in JSON format at
sent
datetime
The time and date of the origination of the alert message.
--
identifier
source
text
The identifier of the alert message in a number or string uniquely identifying this message, assigned by the sender.
--
sender
text
The identifier of the sender of the alert message which identifies the originator of this alert. Guaranteed by assigner to be unique globally; e.g., may be based on an Internet domain name.
--
msgType
text
The code denoting the nature of the alert message. ['Alert', 'Update', 'Cancel', 'Ack', 'Error']
+The text identifying the source of the alert message. The particular source of this alert; e.g., an operator or a specific device.
@@ -1417,40 +1387,40 @@ cap-alert is a MISP object available in JSON format at
restriction
msgType
text
The text describing the rule for limiting distribution of the restricted alert message.
+The code denoting the nature of the alert message. ['Alert', 'Update', 'Cancel', 'Ack', 'Error']
source
text
sent
datetime
The text identifying the source of the alert message. The particular source of this alert; e.g., an operator or a specific device.
+The time and date of the origination of the alert message.
references
sender
text
The group listing identifying earlier message(s) referenced by the alert message. (1) The extended message identifier(s) (in the form sender,identifier,sent) of an earlier CAP message or messages referenced by this one. (2) If multiple messages are referenced, they SHALL be separated by whitespace.
+The identifier of the sender of the alert message which identifies the originator of this alert. Guaranteed by assigner to be unique globally; e.g., may be based on an Internet domain name.
addresses
code
text
The group listing of intended recipients of the alert message. (1) Required when <scope> is “Private”, optional when <scope> is “Public” or “Restricted”. (2) Each recipient SHALL be identified by an identifier or an address. (3) Multiple space-delimited addresses MAY be included. Addresses including whitespace MUST be enclosed in double-quotes.
+The code denoting the special handling of the alert message.
@@ -1467,10 +1437,40 @@ cap-alert is a MISP object available in JSON format at
note
identifier
text
The text describing the purpose or significance of the alert message.
+The identifier of the alert message in a number or string uniquely identifying this message, assigned by the sender.
++
references
text
The group listing identifying earlier message(s) referenced by the alert message. (1) The extended message identifier(s) (in the form sender,identifier,sent) of an earlier CAP message or messages referenced by this one. (2) If multiple messages are referenced, they SHALL be separated by whitespace.
++
restriction
text
The text describing the rule for limiting distribution of the restricted alert message.
++
addresses
text
The group listing of intended recipients of the alert message. (1) Required when <scope> is “Private”, optional when <scope> is “Public” or “Restricted”. (2) Each recipient SHALL be identified by an identifier or an address. (3) Multiple space-delimited addresses MAY be included. Addresses including whitespace MUST be enclosed in double-quotes.
@@ -1515,6 +1515,76 @@ cap-info is a MISP object available in JSON format at
effective
datetime
The effective time of the information of the alert message.
++
audience
text
The text describing the intended audience of the alert message.
++
expires
datetime
The expiry time of the information of the alert message.
++
certainty
text
The code denoting the certainty of the subject event of the alert message. For backward compatibility with CAP 1.0, the deprecated value of “Very Likely” SHOULD be treated as equivalent to “Likely”. ['Likely', 'Possible', 'Unlikely', 'Unknown']
++
language
text
The code denoting the language of the info sub-element of the alert message.
++
instruction
text
The text describing the recommended action to be taken by recipients of the alert message.
++
category
text
The code denoting the category of the subject event of the alert message. ['Geo', 'Met', 'Safety', 'Security', 'Rescue', 'Fire', 'Health', 'Env', 'Transport', 'Infra', 'CBRNE', 'Other']
++
responseType
text
headline
text
The text headline of the alert message.
++
senderName
text
The text naming the originator of the alert message.
++
parameter
text
language
severity
text
The code denoting the language of the info sub-element of the alert message.
+The code denoting the severity of the subject event of the alert message. ['Extreme', 'Severe', 'Moderate', 'Minor', 'Unknown']
@@ -1575,76 +1665,6 @@ cap-info is a MISP object available in JSON format at
onset
datetime
The expected time of the beginning of the subject event of the alert message.
--
severity
text
The code denoting the severity of the subject event of the alert message. ['Extreme', 'Severe', 'Moderate', 'Minor', 'Unknown']
--
headline
text
The text headline of the alert message.
--
expires
datetime
The expiry time of the information of the alert message.
--
category
text
The code denoting the category of the subject event of the alert message. ['Geo', 'Met', 'Safety', 'Security', 'Rescue', 'Fire', 'Health', 'Env', 'Transport', 'Infra', 'CBRNE', 'Other']
--
web
link
The identifier of the hyperlink associating additional information with the alert message.
--
instruction
text
The text describing the recommended action to be taken by recipients of the alert message.
--
event
text
effective
datetime
The effective time of the information of the alert message.
--
certainty
text
The code denoting the certainty of the subject event of the alert message. For backward compatibility with CAP 1.0, the deprecated value of “Very Likely” SHOULD be treated as equivalent to “Likely”. ['Likely', 'Possible', 'Unlikely', 'Unknown']
--
senderName
text
The text naming the originator of the alert message.
--
urgency
text
audience
text
web
link
The text describing the intended audience of the alert message.
+The identifier of the hyperlink associating additional information with the alert message.
++
onset
datetime
The expected time of the beginning of the subject event of the alert message.
@@ -1743,26 +1743,6 @@ cap-resource is a MISP object available in JSON format at
digest
sha1
The code representing the digital digest (“hash”) computed from the resource file (OPTIONAL).
--
size
text
The integer indicating the size of the resource file.
--
resourceDesc
text
mimeType
mime-type
The identifier of the MIME content type and sub-type describing the resource file.
--
derefUri
attachment
The base-64 encoded data content of the resource file.
--
uri
link
digest
sha1
The code representing the digital digest (“hash”) computed from the resource file (OPTIONAL).
++
mimeType
mime-type
The identifier of the MIME content type and sub-type describing the resource file.
++
size
text
The integer indicating the size of the resource file.
++
derefUri
attachment
The base-64 encoded data content of the resource file.
++
last-seen
+first-seen
datetime
Last time this payment destination address has been seen
--
text
text
Free text value
+First time this payment destination address has been seen
@@ -1881,10 +1871,20 @@ coin-address is a MISP object available in JSON format at
first-seen
text
text
Free text value
++
last-seen
datetime
First time this payment destination address has been seen
+Last time this payment destination address has been seen
@@ -1929,20 +1929,10 @@ cookie is a MISP object available in JSON format at
text
type
text
A description of the cookie.
--
cookie
cookie
Full cookie
+Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
@@ -1959,10 +1949,20 @@ cookie is a MISP object available in JSON format at
type
text
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
+A description of the cookie.
++
cookie
cookie
Full cookie
@@ -2027,10 +2027,10 @@ course-of-action is a MISP object available in JSON format at
stage
impact
text
The stage of the threat management lifecycle that the course of action is applicable to. ['Remedy', 'Response']
+The estimated impact of applying the course of action. ['High', 'Medium', 'Low', 'None', 'Unknown']
@@ -2047,16 +2047,6 @@ course-of-action is a MISP object available in JSON format at
cost
text
The estimated cost of applying the course of action. ['High', 'Medium', 'Low', 'None', 'Unknown']
--
name
text
impact
objective
text
The estimated impact of applying the course of action. ['High', 'Medium', 'Low', 'None', 'Unknown']
+The objective of the course of action.
++
cost
text
The estimated cost of applying the course of action. ['High', 'Medium', 'Low', 'None', 'Unknown']
++
stage
text
The stage of the threat management lifecycle that the course of action is applicable to. ['Remedy', 'Response']
objective
text
The objective of the course of action.
--
isError
+password
text
isError
--
encCS
text
SSH symmetric encryption algorithm supported in the session
--
system
text
System origin in cowrie honeypot
--
src_ip
ip-src
Source IP address of the session
--
keyAlgs
text
SSH public-key algorithm supported in the session
--
input
text
Input of the session
--
message
text
Message of the cowrie honeypot
--
username
text
Username related to the password(s)
+Password
@@ -2225,36 +2155,6 @@ cowrie is a MISP object available in JSON format at
dst_port
port
Destination port of the session
--
src_port
port
Source port of the session
--
eventid
text
Eventid of the session in the cowrie honeypot
--
timestamp
datetime
password
text
src_ip
ip-src
Password
+Source IP address of the session
@@ -2285,10 +2185,10 @@ cowrie is a MISP object available in JSON format at
dst_ip
ip-dst
message
text
Destination IP address of the session
+Message of the cowrie honeypot
@@ -2305,10 +2205,40 @@ cowrie is a MISP object available in JSON format at
sensor
dst_ip
ip-dst
Destination IP address of the session
++
src_port
port
Source port of the session
++
input
text
Cowrie sensor name
+Input of the session
++
keyAlgs
text
SSH public-key algorithm supported in the session
sensor
text
Cowrie sensor name
++
system
text
System origin in cowrie honeypot
++
dst_port
port
Destination port of the session
++
username
text
Username related to the password(s)
++
eventid
text
Eventid of the session in the cowrie honeypot
++
encCS
text
SSH symmetric encryption algorithm supported in the session
++
isError
text
isError
++
origin
-text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
--
text
text
password
text
Password
--
username
text
password
text
Password
++
origin
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
++
comment
-comment
issued
datetime
A description of the card.
+Initial date of validity or issued date.
issued
datetime
name
text
Initial date of validity or issued date.
+Name of the card owner.
@@ -2501,10 +2501,10 @@ credit-card is a MISP object available in JSON format at
card-security-code
text
comment
comment
Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
+A description of the card.
@@ -2531,10 +2531,10 @@ credit-card is a MISP object available in JSON format at
name
card-security-code
text
Name of the card owner.
+Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
@@ -2579,26 +2579,6 @@ ddos is a MISP object available in JSON format at
domain-dst
domain
Destination domain (victim)
--
dst-port
port
Destination port of the attack
--
first-seen
datetime
total-bps
counter
dst-port
port
Bits per second
+Destination port of the attack
protocol
text
domain-dst
domain
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
+Destination domain (victim)
++
src-port
port
Port originating the attack
@@ -2659,10 +2649,10 @@ ddos is a MISP object available in JSON format at
total-pps
total-bps
counter
Packets per second
+Bits per second
@@ -2679,10 +2669,20 @@ ddos is a MISP object available in JSON format at
src-port
port
protocol
text
Port originating the attack
+Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
total-pps
counter
Packets per second
@@ -2727,20 +2727,20 @@ diameter-attack is a MISP object available in JSON format at
IdrFlags
Destination-Realm
text
IDR-Flags.
+Destination-Realm.
+
first-seen
datetime
text
text
When the attack has been seen for the first time.
+A description of the attack seen.
@@ -2757,6 +2757,16 @@ diameter-attack is a MISP object available in JSON format at
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
++
Destination-Host
text
Destination-Realm
text
Destination-Realm.
--
SessionId
text
text
IdrFlags
text
A description of the attack seen.
+IDR-Flags.
++
first-seen
datetime
When the attack has been seen for the first time.
++
CmdCode
text
A decimal representation of the diameter Command Code.
@@ -2817,16 +2837,6 @@ diameter-attack is a MISP object available in JSON format at
ApplicationId
text
Application-ID is used to identify for which Diameter application the message is applicable. Application-ID is a decimal representation.
--
Origin-Host
text
CmdCode
text
A decimal representation of the diameter Command Code.
--
text
-text
domain
domain
A description of the tuple
+Domain name
+
first-seen
-datetime
text
text
First time the tuple has been seen
+A description of the tuple
@@ -2925,13 +2925,13 @@ domain-ip is a MISP object available in JSON format at
domain
domain
first-seen
datetime
Domain name
+First time the tuple has been seen
+
text
+text
Free text value to attach to the ELF
++
os_abi
text
entrypoint-address
text
Address of the entry point
++
number-sections
counter
text
text
Free text value to attach to the ELF
--
entrypoint-address
text
Address of the entry point
--
sha512
-sha512
Secure Hash Algorithm 2 (512 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
flag
type
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
+Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
@@ -3111,40 +3091,30 @@ elf-section is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
type
text
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
+Free text value to attach to the section
sha1
sha1
sha512
sha512
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (512 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
@@ -3161,8 +3131,18 @@ elf-section is a MISP object available in JSON format at
sha256
sha256
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
sha224
-sha224
Secure Hash Algorithm 2 (224 bits)
--
text
name
text
Free text value to attach to the section
+Name of the section
md5
md5
sha224
sha224
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -3211,15 +3181,45 @@ elf-section is a MISP object available in JSON format at
name
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
flag
text
Name of the section
+Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
reply-to
-email-reply-to
Email address the reply will be sent to
--
subject
email-subject
Subject
--
header
email-header
Full headers
--
email-body
email-body
Body of the email
--
to
email-dst
thread-index
email-thread-index
Identifies a particular conversation thread
--
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
--
cc
email-dst
Carbon copy
--
to-display-name
email-dst-display-name
Display name of the receiver
--
mime-boundary
email-mime-boundary
MIME Boundary
--
send-date
datetime
Date the email has been sent
--
from
email-src
Sender email address
--
message-id
email-message-id
Message ID
--
return-path
text
Message return path
--
attachment
email-attachment
screenshot
attachment
message-id
email-message-id
Screenshot of email
+Message ID
++
header
email-header
Full headers
++
from
email-src
Sender email address
++
reply-to
email-reply-to
Email address the reply will be sent to
++
mime-boundary
email-mime-boundary
MIME Boundary
++
to-display-name
email-dst-display-name
Display name of the receiver
screenshot
attachment
Screenshot of email
++
send-date
datetime
Date the email has been sent
++
cc
email-dst
Carbon copy
++
subject
email-subject
Subject
++
return-path
text
Message return path
++
email-body
email-body
Body of the email
++
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
++
thread-index
email-thread-index
Identifies a particular conversation thread
++
processing-timestamp
-datetime
victim
text
Timestamp of the report
--
logfile
attachment
Full logfile related to the attack.
+Identifier of the victim
@@ -3497,10 +3487,20 @@ fail2ban is a MISP object available in JSON format at
victim
text
logfile
attachment
Identifier of the victim
+Full logfile related to the attack.
++
processing-timestamp
datetime
Timestamp of the report
@@ -3517,6 +3517,16 @@ fail2ban is a MISP object available in JSON format at
banned-ip
ip-src
IP Address banned by fail2ban
++
failures
counter
banned-ip
ip-src
IP Address banned by fail2ban
--
sha512
-sha512
tlsh
tlsh
Secure Hash Algorithm 2 (512 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
authentihash
authentihash
Authenticode executable signature hash
+Fuzzy hash by Trend Micro: Locality Sensitive Hash
@@ -3625,76 +3605,26 @@ file is a MISP object available in JSON format at
sha384
sha384
authentihash
authentihash
Secure Hash Algorithm 2 (384 bits)
+Authenticode executable signature hash
sha512/256
sha512/256
mimetype
mime-type
Secure Hash Algorithm 2 (256 bits)
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
+Mime type
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
--
malware-sample
malware-sample
The file itself (binary)
--
entropy
float
sha256
sha256
md5
md5
Secure Hash Algorithm 2 (256 bits)
+[Insecure] MD5 hash (128 bits)
@@ -3725,10 +3655,50 @@ file is a MISP object available in JSON format at
sha224
sha224
sha512
sha512
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (512 bits)
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
++
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
@@ -3745,30 +3715,10 @@ file is a MISP object available in JSON format at
filename
filename
sha224
sha224
Filename on disk
--
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
md5
md5
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -3785,15 +3735,65 @@ file is a MISP object available in JSON format at
mimetype
mime-type
sha512/224
sha512/224
Mime type
+Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
filename
filename
Filename on disk
malware-sample
malware-sample
The file itself (binary)
++
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
latitude
-float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
first-seen
datetime
When the location was seen for the first time.
--
last-seen
datetime
When the location was seen for the last time.
--
city
region
text
City.
--
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
--
country
text
Country.
+Region.
@@ -3923,16 +3873,46 @@ geolocation is a MISP object available in JSON format at
region
first-seen
datetime
When the location was seen for the first time.
++
country
text
Region.
+Country.
last-seen
datetime
When the location was seen for the last time.
++
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
longitude
float
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
++
city
text
City.
++
GtpImei
+GtpVersion
text
GTP IMEI (International Mobile Equipment Identity).
+GTP version ['0', '1', '2']
+
ipDest
ip-dst
first-seen
datetime
IP destination address.
+When the attack has been seen for the first time.
+
text
-text
A description of the GTP attack.
--
PortDest
text
Destination port.
--
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
--
GtpServingNetwork
text
GTP Serving Network.
--
PortSrc
port
Source port.
--
GtpImsi
text
GtpVersion
text
PortSrc
port
GTP version ['0', '1', '2']
+Source port.
ipDest
ip-dst
IP destination address.
++
GtpImei
text
GTP IMEI (International Mobile Equipment Identity).
++
ipSrc
ip-src
first-seen
datetime
GtpServingNetwork
text
When the attack has been seen for the first time.
+GTP Serving Network.
++
text
text
A description of the GTP attack.
++
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
++
PortDest
text
Destination port.
@@ -4149,80 +4149,10 @@ http-request is a MISP object available in JSON format at
proxy-user
text
url
url
HTTP Proxy Username
--
basicauth-password
text
HTTP Basic Authentication Password
--
content-type
other
The MIME type of the body of the request
--
proxy-password
text
HTTP Proxy Password
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
--
referer
other
This is the address of the previous web page from which a link to the currently requested page was followed
--
uri
uri
Request URI
--
user-agent
user-agent
The user agent string of the user agent
+Full HTTP Request URL
@@ -4249,20 +4179,10 @@ http-request is a MISP object available in JSON format at
host
hostname
cookie
text
The domain name of the server
--
url
url
Full HTTP Request URL
+An HTTP cookie previously sent by the server with Set-Cookie
content-type
other
The MIME type of the body of the request
++
host
hostname
The domain name of the server
++
proxy-password
text
HTTP Proxy Password
++
basicauth-password
text
HTTP Basic Authentication Password
++
user-agent
user-agent
The user agent string of the user agent
++
referer
other
This is the address of the previous web page from which a link to the currently requested page was followed
++
uri
uri
Request URI
++
proxy-user
text
HTTP Proxy Username
++
last-seen
-datetime
domain
domain
Last time the tuple has been seen
+Domain
++
src-port
port
Source port
++
text
text
Description of the tuple
@@ -4347,16 +4367,6 @@ ip-port is a MISP object available in JSON format at
text
text
Description of the tuple
--
hostname
hostname
domain
domain
last-seen
datetime
Domain
+Last time the tuple has been seen
+
src-port
port
Source port
--
first-seen
-datetime
First seen of the SSL/TLS handshake
--
ip-dst
ip-dst
last-seen
description
text
Type of detected software ie software, malware
++
first-seen
datetime
Last seen of the SSL/TLS handshake
+First seen of the SSL/TLS handshake
@@ -4475,6 +4475,16 @@ ja3 is a MISP object available in JSON format at
last-seen
datetime
Last seen of the SSL/TLS handshake
++
ip-src
ip-src
description
text
Type of detected software ie software, malware
--
registration-number
+text
text
Registration number of an entity in the relevant authority.
+A description of the entity.
+
legal-form
+registration-number
text
Legal form of an entity.
+Registration number of an entity in the relevant authority.
name
text
Name of an entity.
--
text
text
A description of the entity.
--
business
text
name
text
Name of an entity.
++
legal-form
text
Legal form of an entity.
++
text
+name
text
Free text value to attach to the Mach-O file
+Binary’s name
++
entrypoint-address
text
Address of the entry point
@@ -4671,25 +4681,15 @@ macho is a MISP object available in JSON format at
entrypoint-address
text
text
Address of the entry point
+Free text value to attach to the Mach-O file
name
text
Binary’s name
--
sha512
-sha512
Secure Hash Algorithm 2 (512 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
size-in-bytes
size-in-bytes
sha384
sha384
text
text
Secure Hash Algorithm 2 (384 bits)
+Free text value to attach to the section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
sha512/256
sha512/256
md5
md5
Secure Hash Algorithm 2 (256 bits)
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
+[Insecure] MD5 hash (128 bits)
@@ -4799,8 +4779,18 @@ macho-section is a MISP object available in JSON format at
sha256
sha256
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
sha224
-sha224
Secure Hash Algorithm 2 (224 bits)
--
text
name
text
Free text value to attach to the section
+Name of the section
md5
md5
sha224
sha224
[Insecure] MD5 hash (128 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -4849,13 +4829,33 @@ macho-section is a MISP object available in JSON format at
name
text
sha512/224
sha512/224
Name of the section
+Secure Hash Algorithm 2 (224 bits)
+
+
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+
post
-text
url
url
Raw post
+Original URL location of the microblog post
@@ -4917,56 +4917,6 @@ microblog is a MISP object available in JSON format at
url
url
Original URL location of the microblog post
--
removal-date
datetime
When the microblog post was removed
--
modification-date
datetime
Last update of the microblog post
--
creation-date
datetime
Initial creation of the microblog post
--
username-quoted
text
Username who are quoted into the microblog post
--
link
url
post
text
Raw post
++
username-quoted
text
Username who are quoted into the microblog post
++
creation-date
datetime
Initial creation of the microblog post
++
modification-date
datetime
Last update of the microblog post
++
removal-date
datetime
When the microblog post was removed
++
name
+description
text
name of the mutex
+Description
description
name
text
Description
+name of the mutex
@@ -5093,70 +5093,10 @@ netflow is a MISP object available in JSON format at
dst-as
AS
Destination AS number for this flow
--
ip-protocol-number
size-in-bytes
IP protocol number of this flow
--
direction
text
Direction of this flow ['Ingress', 'Egress']
--
first-packet-seen
datetime
First packet seen in this flow
--
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
--
flow-count
ip_version
counter
Flows counted in this flow
--
packet-count
counter
Packets counted in this flow
+IP version of this flow
@@ -5173,46 +5113,6 @@ netflow is a MISP object available in JSON format at
src-port
port
Source port of the netflow
--
ip_version
counter
IP version of this flow
--
ip-dst
ip-dst
IP address destination of the netflow
--
last-packet-seen
datetime
Last packet seen in this flow
--
dst-port
port
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
--
src-as
AS
ip-src
ip-src
dst-as
AS
IP address source of the netflow
+Destination AS number for this flow
last-packet-seen
datetime
Last packet seen in this flow
++
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
++
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
++
ip-dst
ip-dst
IP address destination of the netflow
++
packet-count
counter
Packets counted in this flow
++
tcp-flags
text
direction
text
Direction of this flow ['Ingress', 'Egress']
++
flow-count
counter
Flows counted in this flow
++
src-port
port
Source port of the netflow
++
ip-src
ip-src
IP address source of the netflow
++
ip-protocol-number
size-in-bytes
IP protocol number of this flow
++
first-packet-seen
datetime
First packet seen in this flow
++
bailiwick
+rdata
text
Best estimate of the apex of the zone where this data is authoritative
+Resource records of the queried resource
-
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
-+
rrtype
+text
Resource Record type as seen by the passive DNS. ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
++
origin
text
rdata
text
zone_time_first
datetime
Resource records of the queried resource
--
text
text
Description of the passive DNS record.
+First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
rrname
text
time_first
datetime
Resource Record name of the queried resource.
+First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
+
text
+text
Description of the passive DNS record.
++
zone_time_last
datetime
rrtype
bailiwick
text
Resource Record type as seen by the passive DNS. ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
+Best estimate of the apex of the zone where this data is authoritative
rrname
text
Resource Record name of the queried resource.
++
origin
-text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
--
url
url
last-seen
datetime
When the paste has been accessible or seen for the last time.
--
title
origin
text
Title of the paste or post.
--
paste
text
Raw text of the paste or post
+Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
last-seen
datetime
When the paste has been accessible or seen for the last time.
++
paste
text
Raw text of the paste or post
++
title
text
Title of the paste or post.
++
text
+text
Free text value to attach to the PE
++
file-description
text
FileDescription in the resources
++
number-sections
counter
lang-id
text
Lang ID in the resources
--
product-version
text
ProductVersion in the resources
--
original-filename
filename
OriginalFilename in the resources
--
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
product-name
text
ProductName in the resources
--
entrypoint-address
text
Address of the entry point
--
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
--
internal-filename
filename
InternalFilename in the resources
--
legal-copyright
text
LegalCopyright in the resources
--
file-version
text
imphash
imphash
Hash (md5) calculated from the import table
--
text
text
Free text value to attach to the PE
--
pehash
pehash
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
--
company-name
text
file-description
original-filename
filename
OriginalFilename in the resources
++
product-name
text
FileDescription in the resources
+ProductName in the resources
++
product-version
text
ProductVersion in the resources
++
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
++
lang-id
text
Lang ID in the resources
++
entrypoint-address
text
Address of the entry point
++
imphash
imphash
Hash (md5) calculated from the import table
++
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
legal-copyright
text
LegalCopyright in the resources
++
internal-filename
filename
InternalFilename in the resources
++
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
@@ -5775,26 +5775,6 @@ pe-section is a MISP object available in JSON format at
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
size-in-bytes
size-in-bytes
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
characteristic
text
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
entropy
float
Entropy of the whole section
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
text
text
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
md5
md5
entropy
float
Entropy of the whole section
++
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
ssdeep
ssdeep
name
text
sha512/224
sha512/224
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
+Secure Hash Algorithm 2 (224 bits)
+
+
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+
passport-expiration
-passport-expiration
text
text
The expiration date of a passport.
+A description of the person or identity.
alias
text
passport-expiration
passport-expiration
Alias name or known as.
--
place-of-birth
place-of-birth
Place of birth of a natural person.
+The expiration date of a passport.
@@ -5993,6 +5983,46 @@ person is a MISP object available in JSON format at
middle-name
middle-name
Middle name of a natural person.
++
social-security-number
text
Social security number
++
passport-country
passport-country
The country in which the passport was issued.
++
alias
text
Alias name or known as.
++
first-name
first-name
nationality
nationality
redress-number
redress-number
The nationality of a natural person.
--
title
text
Title of the natural person such as Dr. or equivalent.
--
passport-number
passport-number
The passport number of a natural person.
+The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
redress-number
redress-number
date-of-birth
date-of-birth
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
+Date of birth of a natural person (in YYYY-MM-DD format).
@@ -6063,43 +6073,43 @@ person is a MISP object available in JSON format at
middle-name
middle-name
nationality
nationality
Middle name of a natural person.
--
text
text
A description of the person or identity.
+The nationality of a natural person.
social-security-number
text
passport-number
passport-number
Social security number
+The passport number of a natural person.
date-of-birth
date-of-birth
place-of-birth
place-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
+Place of birth of a natural person.
+
+
title
text
Title of the natural person such as Dr. or equivalent.
+
passport-country
passport-country
The country in which the passport was issued.
--
text
-text
A description of the phone.
--
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
--
first-seen
datetime
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
++
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
++
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
++
msisdn
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
++
gummei
text
msisdn
text
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
+A description of the phone.
-
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
-+
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
--
local-references
-counter
gml
attachment
Amount of API calls inside a code section
--
total-functions
counter
Total amount of functions in the file.
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
callbacks
counter
Amount of callbacks (functions started as thread)
--
not-referenced-strings
counter
Amount of not referenced strings
+Graph export in G>raph Modelling Language format
@@ -6359,60 +6319,10 @@ r2graphity is a MISP object available in JSON format at
text
text
Description of the r2graphity object
--
ratio-functions
ratio-string
float
Ratio: amount of functions per kilobyte of code section
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
gml
attachment
Graph export in G>raph Modelling Language format
--
total-api
counter
Total amount of API calls
+Ratio: amount of referenced strings per kilobyte of code section
@@ -6429,50 +6339,10 @@ r2graphity is a MISP object available in JSON format at
create-thread
local-references
counter
Amount of calls to CreateThread
--
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
--
callback-average
counter
Average size of a callback
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
--
memory-allocations
counter
Amount of memory allocations
+Amount of API calls inside a code section
@@ -6489,6 +6359,96 @@ r2graphity is a MISP object available in JSON format at
callbacks
counter
Amount of callbacks (functions started as thread)
++
get-proc-address
counter
Amount of calls to GetProcAddress
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
callback-average
counter
Average size of a callback
++
not-referenced-strings
counter
Amount of not referenced strings
++
text
text
Description of the r2graphity object
++
create-thread
counter
Amount of calls to CreateThread
++
total-api
counter
Total amount of API calls
++
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
++
refsglobalvar
counter
callback-largest
shortest-path-to-create-thread
counter
Largest callback
+Shortest path to the first time the binary calls CreateThread
++
memory-allocations
counter
Amount of memory allocations
++
total-functions
counter
Total amount of functions in the file.
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
callback-largest
counter
Largest callback
++
+
+
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
+
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
--
last-modified
-datetime
name
text
Last time the registry key has been modified
+Name of the registry key
@@ -6655,30 +6655,10 @@ registry-key is a MISP object available in JSON format at
name
data-type
text
Name of the registry key
--
key
regkey
Full key path
--
hive
text
Hive used to store the registry key (file on disk)
+Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
@@ -6695,15 +6675,35 @@ registry-key is a MISP object available in JSON format at
data-type
hive
text
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
+Hive used to store the registry key (file on disk)
last-modified
datetime
Last time the registry key has been modified
++
key
regkey
Full key path
++
summary
+case-number
text
Free text summary of the report
+Case number
case-number
summary
text
Case number
+Free text summary of the report
@@ -6801,6 +6801,16 @@ rtir is a MISP object available in JSON format at
classification
text
Classification of the RTIR ticket
++
constituency
text
ticket-number
text
ticket-number of the RTIR ticket
--
classification
text
Classification of the RTIR ticket
--
status
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
--
ip
ip-dst
ticket-number
text
ticket-number of the RTIR ticket
++
queue
text
status
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
++
results
-text
Freetext result values
--
web-sandbox
text
on-premise-sandbox
results
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
+Freetext result values
@@ -6959,16 +6949,6 @@ sandbox-report is a MISP object available in JSON format at
permalink
link
Permalink reference
--
saas-sandbox
text
on-premise-sandbox
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
++
permalink
link
Permalink reference
++
text
-text
datetime
datetime
Additional signature description
+Datetime
@@ -7047,10 +7047,10 @@ sb-signature is a MISP object available in JSON format at
datetime
datetime
text
text
Datetime
+Additional signature description
@@ -7105,46 +7105,6 @@ ss7-attack is a MISP object available in JSON format at
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
--
SccpCdPC
text
Signaling Connection Control Part (SCCP) CdPC - Phone number.
--
text
text
A description of the attack seen via SS7 logging.
--
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
--
MapUssdCoding
text
MapGsmscfGT
SccpCgGT
text
MAP GSMSCF GT. Phone number.
+Signaling Connection Control Part (SCCP) CgGT - Phone number.
@@ -7175,96 +7135,6 @@ ss7-attack is a MISP object available in JSON format at
MapVlrGT
text
MAP VLR GT. Phone number.
--
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
--
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
MapApplicationContext
text
MAP application context in OID format.
--
MapImsi
text
MAP IMSI. Phone number starting with MCC/MNC.
--
MapSmsTP-DCS
text
MAP SMS TP-DCS.
--
MapGmlc
text
MAP GMLC. Phone number.
--
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
--
MapVersion
text
Map version. ['1', '2', '3']
--
first-seen
datetime
MapMscGT
text
MAP MSC GT. Phone number.
--
MapSmscGT
text
MAP SMSC. Phone number.
--
MapUssdContent
text
MAP USSD Content.
--
MapSmsTP-PID
text
MAP SMS TP-PID.
--
MapMsisdn
text
Category
MapMscGT
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
+MAP MSC GT. Phone number.
++
MapVersion
text
Map version. ['1', '2', '3']
++
MapApplicationContext
text
MAP application context in OID format.
++
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
++
MapGsmscfGT
text
MAP GSMSCF GT. Phone number.
++
MapGmlc
text
MAP GMLC. Phone number.
++
MapSmsTP-DCS
text
MAP SMS TP-DCS.
++
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
@@ -7345,6 +7245,96 @@ ss7-attack is a MISP object available in JSON format at
text
text
A description of the attack seen via SS7 logging.
++
MapSmsTP-PID
text
MAP SMS TP-PID.
++
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
++
MapUssdContent
text
MAP USSD Content.
++
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
++
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
++
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
SccpCdPC
text
Signaling Connection Control Part (SCCP) CdPC - Phone number.
++
MapVlrGT
text
MAP VLR GT. Phone number.
++
MapSmsTP-OA
text
SccpCgSSN
MapSmscGT
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
+MAP SMSC. Phone number.
+
+
MapImsi
text
MAP IMSI. Phone number starting with MCC/MNC.
+
stix2-pattern
-stix2-pattern
version
text
STIX 2 pattern
+Version of STIX 2 pattern. ['stix 2.0']
@@ -7423,10 +7423,10 @@ stix2-pattern is a MISP object available in JSON format at
version
text
stix2-pattern
stix2-pattern
Version of STIX 2 pattern. ['stix 2.0']
+STIX 2 pattern
@@ -7471,26 +7471,6 @@ suricata is a MISP object available in JSON format at
comment
comment
A description of the Suricata rule.
--
ref
link
Reference to the Suricata rule such as origin of the rule or alike.
--
version
text
comment
comment
A description of the Suricata rule.
++
ref
link
Reference to the Suricata rule such as origin of the rule or alike.
++
targeted_machine
-target-machine
targeted_ip_of_system
ip-src
Targeted system
+Targeted system IP address
@@ -7569,10 +7569,10 @@ target-system is a MISP object available in JSON format at
targeted_ip_of_system
ip-src
targeted_machine
target-machine
Targeted system IP address
+Targeted system
@@ -7695,46 +7695,6 @@ tor-node is a MISP object available in JSON format at
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
document
text
Raw document from the consensus.
--
description
text
Tor node description.
--
fingerprint
text
router’s fingerprint.
--
nickname
text
flags
text
list of flag associated with the node.
--
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
--
text
text
published
datetime
router’s publication time. This can be different from first-seen and last-seen.
--
address
ip-src
IP address of the Tor node seen.
--
version_line
text
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
++
flags
text
list of flag associated with the node.
++
description
text
Tor node description.
++
address
ip-src
IP address of the Tor node seen.
++
fingerprint
text
router’s fingerprint.
++
published
datetime
router’s publication time. This can be different from first-seen and last-seen.
++
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
document
text
Raw document from the consensus.
++
from-country
-text
Origin country of a transaction.
--
to-funds-code
text
Type of funds used to finalize a transaction. ['A Deposit', 'C Currency exchange', 'D Casino chips', 'E Bank draft', 'F Money order', 'G Traveler’s cheques', 'H Life insurance policy', 'I Real estate', 'J Securities', 'K Cash', 'O Other', 'P Cheque']
--
transmode-comment
text
transmode-code
text
text
How the transaction was conducted.
+A description of the transaction.
+
amount
transaction-number
text
The value of the transaction in local currency.
+A unique number identifying a transaction.
@@ -7913,10 +7893,20 @@ transaction is a MISP object available in JSON format at
authorized
text
date-posting
datetime
Person who autorized the transaction.
+Date of posting, if different from date of transaction.
++
date
datetime
Date and time of the transaction.
@@ -7943,36 +7933,46 @@ transaction is a MISP object available in JSON format at
date
datetime
from-country
text
Date and time of the transaction.
+Origin country of a transaction.
transaction-number
to-funds-code
text
A unique number identifying a transaction.
--
text
text
A description of the transaction.
+Type of funds used to finalize a transaction. ['A Deposit', 'C Currency exchange', 'D Casino chips', 'E Bank draft', 'F Money order', 'G Traveler’s cheques', 'H Life insurance policy', 'I Real estate', 'J Securities', 'K Cash', 'O Other', 'P Cheque']
transmode-code
text
How the transaction was conducted.
++
amount
text
The value of the transaction in local currency.
++
teller
text
date-posting
datetime
authorized
text
Date of posting, if different from date of transaction.
+Person who autorized the transaction.
@@ -8031,20 +8031,20 @@ url is a MISP object available in JSON format at
subdomain
text
url
url
Subdomain
+Full URL
+
query_string
resource_path
text
Query (after path, preceded by '?')
+Path (between hostname:port and query)
@@ -8061,6 +8061,36 @@ url is a MISP object available in JSON format at
query_string
text
Query (after path, preceded by '?')
++
port
port
Port number
++
tld
text
Top-Level Domain
++
first-seen
datetime
resource_path
subdomain
text
Path (between hostname:port and query)
--
domain
domain
Full domain
--
tld
text
Top-Level Domain
+Subdomain
@@ -8111,20 +8121,10 @@ url is a MISP object available in JSON format at
credential
text
host
hostname
Credential (username, password)
--
text
text
Description of the URL
+Full hostname
@@ -8141,30 +8141,10 @@ url is a MISP object available in JSON format at
port
port
text
text
Port number
--
host
hostname
Full hostname
--
url
url
Full URL
+Description of the URL
credential
text
Credential (username, password)
++
domain
domain
Full domain
++
external
-target-external
External target organisations affected by this attack.
--
roles
classification
text
The list of roles targeted within the victim.
+The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
+
classification
-text
name
target-org
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
--
node
target-machine
Name(s) of node that was targeted.
+The name of the department(s) or organisation(s) targeted.
@@ -8289,6 +8269,16 @@ victim is a MISP object available in JSON format at
roles
text
The list of roles targeted within the victim.
++
target-email
regions
target-location
external
target-external
The list of regions or locations from the victim targeted. ISO 3166 should be used.
+External target organisations affected by this attack.
++
node
target-machine
Name(s) of node that was targeted.
@@ -8319,10 +8319,10 @@ victim is a MISP object available in JSON format at
name
target-org
regions
target-location
The name of the department(s) or organisation(s) targeted.
+The list of regions or locations from the victim targeted. ISO 3166 should be used.
@@ -8367,6 +8367,46 @@ virustotal-report is a MISP object available in JSON format at
detection-ratio
text
Detection Ratio
++
community-score
text
Community Score
++
comment
text
Comment related to this hash
++
last-submission
datetime
Last Submission
++
first-submission
datetime
community-score
text
Community Score
--
detection-ratio
text
Detection Ratio
--
last-submission
datetime
Last Submission
--
vulnerable_configuration
+text
The vulnerable configuration is described in CPE format
++
text
text
Description of the vulnerability
++
created
datetime
First time when the vulnerability was discovered
++
id
vulnerability
published
datetime
Initial publication date
++
references
link
text
text
Description of the vulnerability
--
modified
datetime
created
datetime
First time when the vulnerability was discovered
--
published
datetime
Initial publication date
--
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
domain
+domain
Domain of the whois entry
++
registrant-org
whois-registrant-org
text
text
Full whois entry
++
registrant-email
whois-registrant-email
comment
text
Comment of the whois entry
--
registrar
whois-registrar
Registrar of the whois entry
--
registrant-phone
whois-registrant-phone
Registrant phone number
--
domain
domain
Domain of the whois entry
--
creation-date
datetime
registrant-phone
whois-registrant-phone
Registrant phone number
++
expiration-date
datetime
text
text
Full whois entry
--
modification-date
datetime
Last update of the whois entry
--
nameserver
hostname
Nameserver
--
registrant-name
whois-registrant-name
nameserver
hostname
Nameserver
++
registrar
whois-registrar
Registrar of the whois entry
++
comment
text
Comment of the whois entry
++
modification-date
datetime
Last update of the whois entry
++
self_signed
+boolean
Self-signed certificate
++
text
text
Free text description of hte certificate
++
pubkey-info-size
text
Length of the public key (in bits)
++
serial-number
text
Serial number of the certificate
++
is_ca
boolean
CA certificate
++
dns_names
text
DNS names
++
validity-not-after
datetime
Certificate invalid after that date
++
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
++
raw-base64
text
Raw certificate base64 encoded (DER format)
++
pem
text
Raw certificate in PEM formati (Unix-like newlines)
++
pubkey-info-exponent
text
Exponent of the public key
++
pubkey-info-modulus
text
self_signed
boolean
x509-fingerprint-sha1
x509-fingerprint-sha1
Self-signed certificate
--
pubkey-info-size
text
Length of the public key (in bits)
--
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
--
raw-base64
text
Raw certificate base64 encoded (DER format)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -8831,6 +8921,16 @@ x509 is a MISP object available in JSON format at
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
++
validity-not-before
datetime
pem
text
Raw certificate in PEM formati (Unix-like newlines)
--
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
serial-number
text
Serial number of the certificate
--
dns_names
text
DNS names
--
is_ca
boolean
CA certificate
--
validity-not-after
datetime
Certificate invalid after that date
--
text
text
Free text description of hte certificate
--
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
--
issuer
text
pubkey-info-exponent
text
Exponent of the public key
--
yara
+version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
++
yara-hunt
yara
Yara rule generated from -y.
+Wide yara rule generated from -yh.
@@ -9009,20 +9029,10 @@ yabin is a MISP object available in JSON format at
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
--
yara-hunt
yara
yara
Wide yara rule generated from -yh.
+Yara rule generated from -y.
@@ -9067,10 +9077,10 @@ yara is a MISP object available in JSON format at
yara
yara
version
text
YARA rule.
+Version of the YARA rule depending where the yara rule is known to work as expected. ['3.7.1']
@@ -9087,10 +9097,10 @@ yara is a MISP object available in JSON format at
version
text
yara
yara
Version of the YARA rule depending where the yara rule is known to work as expected. ['3.7.1']
+YARA rule.
@@ -9144,6 +9154,16 @@ yara is a MISP object available in JSON format at
['misp', 'stix-1.1']
contains
The references source is containing the target object.
['misp', 'stix-1.1']
resolved-to
The referenced source is resolved to the target object.
['misp', 'stix-1.1']
attributed-to
This referenced source is attributed to the target object.
['misp', 'stix-2.0']