diff --git a/objects.html b/objects.html index f57b290..c4956dc 100755 --- a/objects.html +++ b/objects.html @@ -454,6 +454,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
first-seen
+original-date
datetime
When the leak has been accessible or seen for the first time.
--
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
+When the information available in the leak was created. It’s usually before the first-seen.
@@ -589,16 +580,6 @@ ail-leak is a MISP object available in JSON format at
type
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
--
text
text
last-seen
datetime
type
text
When the leak has been accessible or seen for the last time.
+Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
+
original-date
first-seen
datetime
When the information available in the leak was created. It’s usually before the first-seen.
+When the leak has been accessible or seen for the first time.
@@ -649,6 +630,26 @@ ail-leak is a MISP object available in JSON format at
last-seen
datetime
When the leak has been accessible or seen for the last time.
++
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
++
origin
text
description
text
Description of the autonomous system
--
country
text
Country code of the main location of the autonomous system
--
asn
AS
export
import
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
@@ -835,10 +806,40 @@ asn is a MISP object available in JSON format at
import
description
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
+Description of the autonomous system
++
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
export
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
++
country
text
Country code of the main location of the autonomous system
@@ -893,30 +894,20 @@ av-signature is a MISP object available in JSON format at
software
text
datetime
datetime
Name of antivirus software
+Datetime
signature
software
text
Name of detection signature
--
datetime
datetime
Datetime
+Name of antivirus software
signature
text
Name of detection signature
++
text
-text
last-seen
datetime
Free text value
+Last time this payment destination address has been seen
symbol
text
text
The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
+Free text value
@@ -1011,10 +1012,10 @@ coin-address is a MISP object available in JSON format at
last-seen
datetime
symbol
text
Last time this payment destination address has been seen
+The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
@@ -1059,6 +1060,26 @@ cookie is a MISP object available in JSON format at
cookie
cookie
Full cookie
++
cookie-name
text
Name of the cookie (if splitted)
++
text
text
cookie
cookie
Full cookie
--
cookie-name
text
Name of the cookie (if splitted)
--
origin
+type
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
+Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
type
username
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
+Username related to the password(s)
@@ -1177,10 +1178,10 @@ credential is a MISP object available in JSON format at
notification
format
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
+Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
@@ -1197,20 +1198,20 @@ credential is a MISP object available in JSON format at
format
notification
text
Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
+Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
username
origin
text
Username related to the password(s)
+Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
@@ -1255,30 +1256,10 @@ credit-card is a MISP object available in JSON format at
expiration
datetime
Maximum date of validity
--
version
name
text
Version of the card.
--
cc-number
cc-number
credit-card number as encoded on the card.
+Name of the card owner.
@@ -1295,20 +1276,40 @@ credit-card is a MISP object available in JSON format at
name
text
comment
comment
Name of the card owner.
+A description of the card.
comment
comment
expiration
datetime
A description of the card.
+Maximum date of validity
++
cc-number
cc-number
credit-card number as encoded on the card.
++
version
text
Version of the card.
@@ -1373,20 +1374,20 @@ ddos is a MISP object available in JSON format at
first-seen
datetime
domain-dst
domain
Beginning of the attack
+Destination domain (victim)
+
total-bps
total-pps
counter
Bits per second
+Packets per second
@@ -1403,26 +1404,6 @@ ddos is a MISP object available in JSON format at
last-seen
datetime
End of the attack
--
domain-dst
domain
Destination domain (victim)
--
text
text
total-pps
total-bps
counter
Packets per second
+Bits per second
@@ -1453,6 +1434,16 @@ ddos is a MISP object available in JSON format at
first-seen
datetime
Beginning of the attack
++
dst-port
port
last-seen
datetime
End of the attack
++
protocol
text
number-sections
counter
type
text
Number of sections
+Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
++
entrypoint-address
text
Address of the entry point
++
text
text
Free text value to attach to the ELF
@@ -1619,26 +1640,6 @@ elf is a MISP object available in JSON format at
type
text
Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
--
text
text
Free text value to attach to the ELF
--
arch
text
entrypoint-address
text
number-sections
counter
Address of the entry point
+Number of sections
@@ -1697,46 +1698,16 @@ elf-section is a MISP object available in JSON format at
text
name
text
Free text value to attach to the section
+Name of the section
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
flag
text
name
text
sha512/224
sha512/224
Name of the section
+Secure Hash Algorithm 2 (224 bits)
+
sha512/256
sha512/256
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
md5
-md5
text
text
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole section
+Free text value to attach to the section
@@ -1797,20 +1758,10 @@ elf-section is a MISP object available in JSON format at
size-in-bytes
size-in-bytes
sha512/256
sha512/256
Size of the section, in bytes
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -1827,10 +1778,10 @@ elf-section is a MISP object available in JSON format at
sha1
sha1
sha384
sha384
[Insecure] Secure Hash Algorithm 1 (160 bits)
+Secure Hash Algorithm 2 (384 bits)
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
entropy
float
Entropy of the whole section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
cc
-email-dst
Carbon copy
--
screenshot
attachment
Screenshot of email
--
send-date
datetime
Date the email has been sent
--
mime-boundary
email-mime-boundary
reply-to
email-reply-to
subject
email-subject
Email address the reply will be sent to
--
message-id
email-message-id
Message ID
--
from
email-src
Sender email address
--
from-display-name
email-src-display-name
Display name of the sender
--
attachment
email-attachment
Attachment
--
to-display-name
email-dst-display-name
Display name of the receiver
+Subject
@@ -1995,23 +1916,13 @@ email is a MISP object available in JSON format at
thread-index
email-thread-index
send-date
datetime
Identifies a particular conversation thread
+Date the email has been sent
-
subject
email-subject
Subject
-+
screenshot
+attachment
Screenshot of email
++
from
email-src
Sender email address
++
message-id
email-message-id
Message ID
++
return-path
text
reply-to
email-reply-to
Email address the reply will be sent to
++
to-display-name
email-dst-display-name
Display name of the receiver
++
from-display-name
email-src-display-name
Display name of the sender
++
thread-index
email-thread-index
Identifies a particular conversation thread
++
attachment
email-attachment
Attachment
++
cc
email-dst
Carbon copy
++
state
+text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
++
mimetype
text
Mime type
++
entropy
float
Entropy of the whole file
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
malware-sample
malware-sample
The file itself (binary)
++
text
text
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
sha224
sha224
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
mimetype
text
Mime type
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole file
--
authentihash
authentihash
sha512/224
sha512/224
pattern-in-file
pattern-in-file
Secure Hash Algorithm 2 (224 bits)
+Pattern that can be found in the file
@@ -2243,6 +2204,16 @@ file is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
sha1
sha1
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
malware-sample
malware-sample
The file itself (binary)
--
certificate
x509-fingerprint-sha1
size-in-bytes
size-in-bytes
Size of the file, in bytes
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
first-seen
-datetime
When the location was seen for the first time.
--
country
region
text
Country.
+Region.
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
longitude
float
region
text
Region.
--
text
text
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
first-seen
datetime
When the location was seen for the first time.
++
altitude
float
country
text
Country.
++
last-seen
datetime
GTP attack object as seen on a GSM, UMTS or LTE network.
++ + | ++gtp-attack is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +
---|---|---|---|
PortDest |
+text |
+
+ Destination port. + |
+
+ + |
+
ipSrc |
+ip-src |
+
+ IP source address. + |
+
+ + |
+
GtpServingNetwork |
+text |
+
+ GTP Serving Network. + |
+
+ + |
+
GtpVersion |
+text |
+
+ GTP version ['0', '1', '2'] + |
+
+ + |
+
first-seen |
+datetime |
+
+ When the attack has been seen for the first time. + |
+
+ + |
+
ipDest |
+ip-dst |
+
+ IP destination address. + |
+
+ + |
+
text |
+text |
+
+ A description of the GTP attack. + |
+
+ + |
+
GtpMsisdn |
+text |
+
+ GTP MSISDN. + |
+
+ + |
+
GtpImei |
+text |
+
+ GTP IMEI (International Mobile Equipment Identity). + |
+
+ + |
+
GtpMessageType |
+text |
+
+ GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value. + |
+
+ + |
+
GtpInterface |
+text |
+
+ GTP interface. ['S5', 'S11', 'S10', 'S8'] + |
+
+ + |
+
GtpImsi |
+text |
+
+ GTP IMSI (International mobile subscriber identity). + |
+
+ + |
+
PortSrc |
+port |
+
+ Source port. + |
+
+ + |
+
content-type
other
The MIME type of the body of the request
--
proxy-user
text
HTTP Proxy Username
--
url
url
Full HTTP Request URL
--
text
text
HTTP Request comment
--
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
--
basicauth-user
text
HTTP Basic Authentication Username
--
proxy-password
text
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
--
user-agent
user-agent
The user agent string of the user agent
--
uri
uri
Request URI
--
host
hostname
text
text
HTTP Request comment
++
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
++
uri
uri
Request URI
++
proxy-user
text
HTTP Proxy Username
++
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
++
basicauth-password
text
basicauth-user
text
HTTP Basic Authentication Username
++
url
url
Full HTTP Request URL
++
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
++
content-type
other
The MIME type of the body of the request
++
user-agent
user-agent
The user agent string of the user agent
++
dst-port
+src-port
port
Destination port
--
first-seen
datetime
First time the tuple has been seen
--
ip
ip-dst
IP Address
+Source port
@@ -2657,10 +2806,30 @@ ip-port is a MISP object available in JSON format at
src-port
first-seen
datetime
First time the tuple has been seen
++
dst-port
port
Source port
+Destination port
++
ip
ip-dst
IP Address
@@ -2715,10 +2884,10 @@ ja3 is a MISP object available in JSON format at
description
text
ip-dst
ip-dst
Type of detected software ie software, malware
+Destination IP address
@@ -2745,10 +2914,10 @@ ja3 is a MISP object available in JSON format at
ip-dst
ip-dst
description
text
Destination IP address
+Type of detected software ie software, malware
@@ -2813,16 +2982,6 @@ macho is a MISP object available in JSON format at
number-sections
counter
Number of sections
--
name
text
number-sections
counter
Number of sections
++
type
text
text
entrypoint-address
text
Free text value to attach to the Mach-O file
+Address of the entry point
entrypoint-address
text
text
Address of the entry point
+Free text value to attach to the Mach-O file
@@ -2901,46 +3070,6 @@ macho-section is a MISP object available in JSON format at
text
text
Free text value to attach to the section
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
name
text
sha512/256
sha512/256
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
md5
-md5
text
text
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole section
+Free text value to attach to the section
@@ -2991,20 +3120,10 @@ macho-section is a MISP object available in JSON format at
size-in-bytes
size-in-bytes
sha512/256
sha512/256
Size of the section, in bytes
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -3021,6 +3140,16 @@ macho-section is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
sha1
sha1
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
entropy
float
Entropy of the whole section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
modification-date
-datetime
username-quoted
text
Last update of the microblog post
--
removal-date
datetime
When the microblog post was removed
--
creation-date
datetime
Initial creation of the microblog post
+Username who are quoted into the microblog post
@@ -3119,20 +3268,10 @@ microblog is a MISP object available in JSON format at
username-quoted
username
text
Username who are quoted into the microblog post
--
url
url
Original URL location of the microblog post
+Username who posted the microblog post
@@ -3149,10 +3288,40 @@ microblog is a MISP object available in JSON format at
username
text
removal-date
datetime
Username who posted the microblog post
+When the microblog post was removed
++
url
url
Original URL location of the microblog post
++
modification-date
datetime
Last update of the microblog post
++
creation-date
datetime
Initial creation of the microblog post
@@ -3197,106 +3366,16 @@ netflow is a MISP object available in JSON format at
ip-protocol-number
size-in-bytes
IP protocol number of this flow
--
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
--
first-packet-seen
datetime
First packet seen in this flow
--
flow-count
counter
Flows counted in this flow
--
packet-count
counter
Packets counted in this flow
--
dst-port
port
Destination port of the netflow
--
dst-as
src-as
AS
Destination AS number for this flow
+Source AS number for this flow
ip_version
counter
IP version of this flow
--
last-packet-seen
datetime
Last packet seen in this flow
--
direction
text
Direction of this flow ['Ingress', 'Egress']
--
ip-dst
ip-dst
byte-count
src-port
port
Source port of the netflow
++
flow-count
counter
Bytes counted in this flow
+Flows counted in this flow
direction
text
Direction of this flow ['Ingress', 'Egress']
++
ip_version
counter
IP version of this flow
++
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
++
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
++
dst-port
port
Destination port of the netflow
++
first-packet-seen
datetime
First packet seen in this flow
++
ip-src
ip-src
src-port
port
Source port of the netflow
--
src-as
dst-as
AS
Source AS number for this flow
+Destination AS number for this flow
protocol
text
ip-protocol-number
size-in-bytes
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
+IP protocol number of this flow
++
packet-count
counter
Packets counted in this flow
++
byte-count
counter
Bytes counted in this flow
++
last-packet-seen
datetime
Last packet seen in this flow
@@ -3405,20 +3574,10 @@ passive-dns is a MISP object available in JSON format at
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
--
text
bailiwick
text
+
Best estimate of the apex of the zone where this data is authoritative
@@ -3435,20 +3594,40 @@ passive-dns is a MISP object available in JSON format at
zone_time_first
datetime
text
text
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
+
count
counter
time_first
datetime
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
+First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
++
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
++
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
@@ -3475,10 +3654,10 @@ passive-dns is a MISP object available in JSON format at
bailiwick
rdata
text
Best estimate of the apex of the zone where this data is authoritative
+Resource records of the queried resource
@@ -3495,6 +3674,16 @@ passive-dns is a MISP object available in JSON format at
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
++
origin
text
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
rdata
text
Resource records of the queried resource
--
paste
+title
text
Raw text of the paste or post
+Title of the paste or post.
++
url
url
Link to the original source of the paste or post.
@@ -3583,10 +3762,10 @@ paste is a MISP object available in JSON format at
url
url
paste
text
Link to the original source of the paste or post.
+Raw text of the paste or post
@@ -3603,16 +3782,6 @@ paste is a MISP object available in JSON format at
title
text
Title of the paste or post.
--
last-seen
datetime
number-sections
counter
Number of sections
--
file-description
text
FileDescription in the resources
--
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
--
imphash
imphash
Hash (md5) calculated from the import table
--
text
text
Free text value to attach to the PE
--
original-filename
filename
OriginalFilename in the resources
--
product-name
text
ProductName in the resources
--
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
company-name
text
CompanyName in the resources
--
legal-copyright
text
LegalCopyright in the resources
--
internal-filename
filename
InternalFilename in the resources
--
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
impfuzzy
impfuzzy
pehash
pehash
product-version
text
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
+ProductVersion in the resources
++
internal-filename
filename
InternalFilename in the resources
++
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
text
text
Free text value to attach to the PE
++
company-name
text
CompanyName in the resources
++
lang-id
text
product-version
file-description
text
ProductVersion in the resources
+FileDescription in the resources
++
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
++
original-filename
filename
OriginalFilename in the resources
imphash
imphash
Hash (md5) calculated from the import table
++
product-name
text
ProductName in the resources
++
number-sections
counter
Number of sections
++
legal-copyright
text
LegalCopyright in the resources
++
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
++
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
++
text
-text
Free text value to attach to the section
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
name
text
sha512/256
sha512/256
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
text
+text
Free text value to attach to the section
++
characteristic
text
md5
md5
[Insecure] MD5 hash (128 bits)
--
entropy
float
Entropy of the whole section
--
sha224
sha224
size-in-bytes
size-in-bytes
sha512/256
sha512/256
Size of the section, in bytes
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (256 bits)
@@ -4009,6 +4128,16 @@ pe-section is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
sha1
sha1
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
entropy
float
Entropy of the whole section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
gender
-gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
--
passport-expiration
passport-expiration
The expiration date of a passport.
--
first-name
first-name
First name of a natural person.
--
passport-country
passport-country
text
text
gender
gender
A description of the person or identity.
--
middle-name
middle-name
Middle name of a natural person
+The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
@@ -4127,20 +4256,20 @@ person is a MISP object available in JSON format at
passport-number
passport-number
text
text
The passport number of a natural person.
+A description of the person or identity.
+
nationality
nationality
date-of-birth
date-of-birth
The nationality of a natural person.
+Date of birth of a natural person (in YYYY-MM-DD format).
@@ -4157,20 +4286,60 @@ person is a MISP object available in JSON format at
place-of-birth
place-of-birth
middle-name
middle-name
Place of birth of a natural person.
+Middle name of a natural person
date-of-birth
date-of-birth
first-name
first-name
Date of birth of a natural person (in YYYY-MM-DD format).
+First name of a natural person.
++
nationality
nationality
The nationality of a natural person.
++
passport-number
passport-number
The passport number of a natural person.
++
passport-expiration
passport-expiration
The expiration date of a passport.
++
place-of-birth
place-of-birth
Place of birth of a natural person.
@@ -4225,16 +4394,6 @@ phone is a MISP object available in JSON format at
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
serial-number
text
imsi
text
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
+A description of the phone.
++
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
text
text
first-seen
datetime
A description of the phone.
+When the phone has been accessible or seen for the first time.
@@ -4285,13 +4454,13 @@ phone is a MISP object available in JSON format at
tmsi
text
last-seen
datetime
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
+When the phone has been accessible or seen for the last time.
+
last-seen
-datetime
imsi
text
When the phone has been accessible or seen for the last time.
+A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
+
refsglobalvar
-counter
ratio-api
float
Amount of API calls outside of code section (glob var, dynamic API)
+Ratio: amount of API calls per kilobyte of code section
dangling-strings
unknown-references
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
r2-commit-version
text
Radare2 commit ID used to generate this object
--
get-proc-address
counter
Amount of calls to GetProcAddress
+Amount of API calls not ending in a function (Radare2 bug, probalby)
@@ -4403,56 +4552,6 @@ r2graphity is a MISP object available in JSON format at
not-referenced-strings
counter
Amount of not referenced strings
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
local-references
counter
Amount of API calls inside a code section
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
callbacks
counter
Amount of callbacks (functions started as thread)
--
ratio-string
float
callback-average
get-proc-address
counter
Average size of a callback
+Amount of calls to GetProcAddress
++
referenced-strings
counter
Amount of referenced strings
++
r2-commit-version
text
Radare2 commit ID used to generate this object
++
create-thread
counter
Amount of calls to CreateThread
@@ -4493,6 +4622,56 @@ r2graphity is a MISP object available in JSON format at
total-api
counter
Total amount of API calls
++
not-referenced-strings
counter
Amount of not referenced strings
++
callbacks
counter
Amount of callbacks (functions started as thread)
++
local-references
counter
Amount of API calls inside a code section
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
gml
attachment
create-thread
refsglobalvar
counter
Amount of calls to CreateThread
+Amount of API calls outside of code section (glob var, dynamic API)
referenced-strings
shortest-path-to-create-thread
counter
Amount of referenced strings
--
total-api
counter
Total amount of API calls
+Shortest path to the first time the binary calls CreateThread
@@ -4553,20 +4722,20 @@ r2graphity is a MISP object available in JSON format at
ratio-api
float
dangling-strings
counter
Ratio: amount of API calls per kilobyte of code section
+Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
unknown-references
callback-average
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Average size of a callback
@@ -4631,20 +4800,20 @@ regexp is a MISP object available in JSON format at
comment
comment
type
text
A description of the regular expression.
+Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
type
text
comment
comment
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
+A description of the regular expression.
@@ -4689,20 +4858,10 @@ registry-key is a MISP object available in JSON format at
last-modified
datetime
Last time the registry key has been modified
--
data
name
text
Data stored in the registry key
+Name of the registry key
@@ -4719,10 +4878,10 @@ registry-key is a MISP object available in JSON format at
name
text
last-modified
datetime
Name of the registry key
+Last time the registry key has been modified
data
text
Data stored in the registry key
++
summary
+case-number
text
Free text summary of the report
+Case number
case-number
summary
text
Case number
+Free text summary of the report
@@ -4845,46 +5014,6 @@ rtir is a MISP object available in JSON format at
constituency
text
Constituency of the RTIR ticket
--
ticket-number
text
ticket-number of the RTIR ticket
--
ip
ip-dst
IPs automatically extracted from the RTIR ticket
--
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
--
subject
text
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
++
classification
text
constituency
text
Constituency of the RTIR ticket
++
ip
ip-dst
IPs automatically extracted from the RTIR ticket
++
ticket-number
text
ticket-number of the RTIR ticket
++
comment
-comment
stix2-pattern
stix2-pattern
A description of the stix2-pattern.
+STIX 2 pattern
stix2-pattern
stix2-pattern
comment
comment
STIX 2 pattern
+A description of the stix2-pattern.
@@ -5011,23 +5180,13 @@ tor-node is a MISP object available in JSON format at
flags
text
first-seen
datetime
list of flag associated with the node.
+When the Tor node designed by the IP address has been seen for the first time.
-
nickname
text
router’s nickname.
-+
published
-datetime
router’s publication time. This can be different from first-seen and last-seen.
--
text
text
document
text
last-seen
datetime
Raw document from the consensus.
+When the Tor node designed by the IP address has been seen for the last time.
flags
text
list of flag associated with the node.
++
nickname
text
router’s nickname.
++
address
ip-src
description
document
text
Tor node description.
+Raw document from the consensus.
first-seen
datetime
description
text
When the Tor node designed by the IP address has been seen for the first time.
+Tor node description.
@@ -5121,10 +5290,10 @@ tor-node is a MISP object available in JSON format at
last-seen
published
datetime
When the Tor node designed by the IP address has been seen for the last time.
+router’s publication time. This can be different from first-seen and last-seen.
@@ -5169,16 +5338,46 @@ url is a MISP object available in JSON format at
domain
domain
subdomain
text
Full domain
+Subdomain
++
credential
text
Credential (username, password)
first-seen
datetime
First time this URL has been seen
++
port
port
Port number
++
scheme
text
tld
text
last-seen
datetime
Top-Level Domain
+Last time this URL has been seen
domain
domain
Full domain
++
resource_path
text
domain_without_tld
text
Domain without Top-Level Domain
--
first-seen
datetime
First time this URL has been seen
--
fragment
text
credential
text
Credential (username, password)
--
subdomain
text
Subdomain
--
port
port
Port number
--
query_string
text
Query (after path, preceded by '?')
--
url
url
query_string
text
Query (after path, preceded by '?')
++
tld
text
Top-Level Domain
++
domain_without_tld
text
Domain without Top-Level Domain
++
host
hostname
last-seen
datetime
Last time this URL has been seen
--
description
+name
target-org
The name of the department(s) or organisation(s) targeted.
++
sectors
text
Description of the victim
--
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
--
node
target-machine
Name(s) of node that was targeted.
+The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
@@ -5397,20 +5556,20 @@ victim is a MISP object available in JSON format at
roles
text
node
target-machine
The list of roles targeted within the victim.
+Name(s) of node that was targeted.
ip-address
ip-dst
user
target-user
IP address(es) of the node targeted.
+The username(s) of the user targeted.
@@ -5427,10 +5586,10 @@ victim is a MISP object available in JSON format at
name
target-org
roles
text
The name of the department(s) or organisation(s) targeted.
+The list of roles targeted within the victim.
@@ -5447,20 +5606,30 @@ victim is a MISP object available in JSON format at
sectors
description
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
+Description of the victim
user
target-user
ip-address
ip-dst
The username(s) of the user targeted.
+IP address(es) of the node targeted.
++
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
@@ -5505,6 +5674,16 @@ virustotal-report is a MISP object available in JSON format at
last-submission
datetime
Last Submission
++
first-submission
datetime
last-submission
datetime
Last Submission
--
vulnerable_configuration
+summary
text
The vulnerable configuration is described in CPE format
+Summary of the vulnerability
published
datetime
references
link
Initial publication date
--
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely)
+External references
@@ -5633,10 +5792,20 @@ vulnerability is a MISP object available in JSON format at
summary
published
datetime
Initial publication date
++
vulnerable_configuration
text
Summary of the vulnerability
+The vulnerable configuration is described in CPE format
@@ -5653,10 +5822,10 @@ vulnerability is a MISP object available in JSON format at
references
link
id
vulnerability
External references
+Vulnerability ID (generally CVE, but not necessarely)
@@ -5701,56 +5870,6 @@ whois is a MISP object available in JSON format at
registrant-name
whois-registrant-name
Registrant name
--
registrant-email
whois-registrant-email
Registrant email address
--
domain
domain
Domain of the whois entry
--
modification-date
datetime
Last update of the whois entry
--
creation-date
datetime
Initial creation of the whois entry
--
expiration-date
datetime
nameserver
hostname
Nameserver
++
registrant-org
whois-registrant-org
registrant-name
whois-registrant-name
Registrant name
++
registrant-phone
whois-registrant-phone
Registrant phone number
++
text
text
registrant-phone
whois-registrant-phone
domain
domain
Registrant phone number
+Domain of the whois entry
nameserver
hostname
registrant-email
whois-registrant-email
Nameserver
+Registrant email address
++
modification-date
datetime
Last update of the whois entry
++
creation-date
datetime
Initial creation of the whois entry
@@ -5849,66 +6018,6 @@ x509 is a MISP object available in JSON format at
issuer
text
Issuer of the certificate
--
pubkey-info-size
text
Length of the public key (in bits)
--
serial-number
text
Serial number of the certificate
--
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
--
text
text
Free text description of hte certificate
--
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
--
raw-base64
text
pubkey-info-algorithm
text
Algorithm of the public key
--
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
validity-not-before
datetime
Certificate invalid before that date
--
pubkey-info-exponent
text
Exponent of the public key
--
subject
text
validity-not-after
datetime
pubkey-info-algorithm
text
Certificate invalid after that date
+Algorithm of the public key
++
text
text
Free text description of hte certificate
++
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
@@ -5989,6 +6078,26 @@ x509 is a MISP object available in JSON format at
issuer
text
Issuer of the certificate
++
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
++
pubkey-info-modulus
text
pubkey-info-size
text
Length of the public key (in bits)
++
validity-not-before
datetime
Certificate invalid before that date
++
validity-not-after
datetime
Certificate invalid after that date
++
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
++
serial-number
text
Serial number of the certificate
++
pubkey-info-exponent
text
Exponent of the public key
++
comment
-comment
A description of Yara rule generated.
--
yara
yara
yara-hunt
yara
Wide yara rule generated from -yh.
--
whitelist
comment
comment
comment
A description of Yara rule generated.
++
yara-hunt
yara
Wide yara rule generated from -yh.
++