Skip to content

Commit 16d8bf7

Browse files
authored
Merge branch 'MISP:main' into main
2 parents 21775db + e3288ef commit 16d8bf7

41 files changed

Lines changed: 1167 additions & 83 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

README.md

Lines changed: 19 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
135135
- [objects/cap-alert](https://github.com/MISP/misp-objects/blob/main/objects/cap-alert/definition.json) - Common Alerting Protocol Version (CAP) alert object.
136136
- [objects/cap-info](https://github.com/MISP/misp-objects/blob/main/objects/cap-info/definition.json) - Common Alerting Protocol Version (CAP) info object.
137137
- [objects/cap-resource](https://github.com/MISP/misp-objects/blob/main/objects/cap-resource/definition.json) - Common Alerting Protocol Version (CAP) resource object.
138+
- [objects/cert-pl-phishing](https://github.com/MISP/misp-objects/blob/main/objects/cert-pl-phishing/definition.json) - cert.pl phishing object template representing an url along with some metadata as such phash, html-structure or partial-hash.
138139
- [objects/cloth](https://github.com/MISP/misp-objects/blob/main/objects/cloth/definition.json) - Describes clothes a natural person wears.
139140
- [objects/coin-address](https://github.com/MISP/misp-objects/blob/main/objects/coin-address/definition.json) - An address used in a cryptocurrency.
140141
- [objects/command](https://github.com/MISP/misp-objects/blob/main/objects/command/definition.json) - Command functionalities related to specific commands executed by a program, whether it is malicious or not. Command-line are attached to this object for the related commands.
@@ -161,6 +162,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
161162
- [objects/cytomic-orion-machine](https://github.com/MISP/misp-objects/blob/main/objects/cytomic-orion-machine/definition.json) - Cytomic Orion File at Machine Detection.
162163
- [objects/dark-pattern-item](https://github.com/MISP/misp-objects/blob/main/objects/dark-pattern-item/definition.json) - An Item whose User Interface implements a dark pattern.
163164
- [objects/ddos](https://github.com/MISP/misp-objects/blob/main/objects/ddos/definition.json) - DDoS object describes a current DDoS activity from a specific or/and to a specific target. Type of DDoS can be attached to the object as a taxonomy or using the type field.
165+
- [objects/ddos-claim](https://github.com/MISP/misp-objects/blob/main/objects/ddos-claim/definition.json) - DDoS-claim object describes a current claim of DDoS activity.
164166
- [objects/device](https://github.com/MISP/misp-objects/blob/main/objects/device/definition.json) - An object to define a device.
165167
- [objects/diameter-attack](https://github.com/MISP/misp-objects/blob/main/objects/diameter-attack/definition.json) - Attack as seen on the diameter signaling protocol supporting LTE networks.
166168
- [objects/diamond-event](https://github.com/MISP/misp-objects/blob/main/objects/diamond-event/definition.json) - A diamond model event object consisting of the four diamond features advesary, infrastructure, capability and victim, several meta-features and ioc attributes.
@@ -190,6 +192,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
190192
- [objects/file](https://github.com/MISP/misp-objects/blob/main/objects/file/definition.json) - File object describing a file with meta-information.
191193
- [objects/flowintel-cm-case](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-cm-case/definition.json) - A case as defined by flowintel-cm.
192194
- [objects/flowintel-cm-task](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-cm-task/definition.json) - A task as defined by flowintel-cm.
195+
- [objects/flowintel-cm-task-note](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-cm-task-note/definition.json) - A task's note as defined by flowintel-cm.
193196
- [objects/forensic-case](https://github.com/MISP/misp-objects/blob/main/objects/forensic-case/definition.json) - An object template to describe a digital forensic case.
194197
- [objects/forensic-evidence](https://github.com/MISP/misp-objects/blob/main/objects/forensic-evidence/definition.json) - An object template to describe a digital forensic evidence.
195198
- [objects/forged-document](https://github.com/MISP/misp-objects/blob/main/objects/forged-document/definition.json) - Object describing a forged document.
@@ -246,6 +249,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
246249
- [objects/ftm-Video](https://github.com/MISP/misp-objects/blob/main/objects/ftm-Video/definition.json) - Video.
247250
- [objects/ftm-Workbook](https://github.com/MISP/misp-objects/blob/main/objects/ftm-Workbook/definition.json) - Workbook.
248251
- [objects/game-cheat](https://github.com/MISP/misp-objects/blob/main/objects/game-cheat/definition.json) - Describes a game cheat or a cheatware.
252+
- [objects/Generalizing Persuasion Framework](https://github.com/MISP/misp-objects/blob/main/objects/Generalizing Persuasion Framework/definition.json) - By placing their work within the GP Framework, scholars will help the field resolve inconsistencies, identify and address open questions, and ensure collective progress. The GP Framework is not meant to compete with other theories (such as the ELM) but rather to fill in two gaps. First, it allows one to consider how individual persuasion studies connect to one another and why studies may arrive at contradictory conclusions. Second, it highlights the sources of variations that should be studied. (James N. Druckman).
249253
- [objects/geolocation](https://github.com/MISP/misp-objects/blob/main/objects/geolocation/definition.json) - An object to describe a geographic location.
250254
- [objects/git-vuln-finder](https://github.com/MISP/misp-objects/blob/main/objects/git-vuln-finder/definition.json) - Export from git-vuln-finder.
251255
- [objects/github-user](https://github.com/MISP/misp-objects/blob/main/objects/github-user/definition.json) - GitHub user.
@@ -301,6 +305,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
301305
- [objects/network-connection](https://github.com/MISP/misp-objects/blob/main/objects/network-connection/definition.json) - A local or remote network connection.
302306
- [objects/network-profile](https://github.com/MISP/misp-objects/blob/main/objects/network-profile/definition.json) - Elements that can be used to profile, pivot or identify a network infrastructure, including domains, ip and urls.
303307
- [objects/network-socket](https://github.com/MISP/misp-objects/blob/main/objects/network-socket/definition.json) - Network socket object describes a local or remote network connections based on the socket data structure.
308+
- [objects/network-traffic](https://github.com/MISP/misp-objects/blob/main/objects/network-traffic/definition.json) - Generic network traffic that originates from a source and is addressed to a destination.
304309
- [objects/news-agency](https://github.com/MISP/misp-objects/blob/main/objects/news-agency/definition.json) - News agencies compile news and disseminate news in bulk.
305310
- [objects/news-media](https://github.com/MISP/misp-objects/blob/main/objects/news-media/definition.json) - News media are forms of mass media delivering news to the general public.
306311
- [objects/open-data-security](https://github.com/MISP/misp-objects/blob/main/objects/open-data-security/definition.json) - An object describing an open dataset available and described under the open data security model. ref. https://github.com/CIRCL/open-data-security.
@@ -316,6 +321,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
316321
- [objects/paste](https://github.com/MISP/misp-objects/blob/main/objects/paste/definition.json) - Paste or similar post from a website allowing to share privately or publicly posts.
317322
- [objects/pcap-metadata](https://github.com/MISP/misp-objects/blob/main/objects/pcap-metadata/definition.json) - Network packet capture metadata.
318323
- [objects/pe](https://github.com/MISP/misp-objects/blob/main/objects/pe/definition.json) - Object describing a Portable Executable.
324+
- [objects/pe-optional-header](https://github.com/MISP/misp-objects/blob/main/objects/pe-optional-header/definition.json) - Object describing a Portable Executable Optional Header.
319325
- [objects/pe-section](https://github.com/MISP/misp-objects/blob/main/objects/pe-section/definition.json) - Object describing a section of a Portable Executable.
320326
- [objects/Deception PersNOna](https://github.com/MISP/misp-objects/blob/main/objects/Deception PersNOna/definition.json) - Fake persona with tasks.
321327
- [objects/person](https://github.com/MISP/misp-objects/blob/main/objects/person/definition.json) - An object which describes a person or an identity.
@@ -324,6 +330,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
324330
- [objects/phishing](https://github.com/MISP/misp-objects/blob/main/objects/phishing/definition.json) - Phishing template to describe a phishing website and its analysis.
325331
- [objects/phishing-kit](https://github.com/MISP/misp-objects/blob/main/objects/phishing-kit/definition.json) - Object to describe a phishing-kit.
326332
- [objects/phone](https://github.com/MISP/misp-objects/blob/main/objects/phone/definition.json) - A phone or mobile phone object which describe a phone.
333+
- [objects/phone-number](https://github.com/MISP/misp-objects/blob/main/objects/phone-number/definition.json) - Phone number based on the E.164 international public telecommunication numbering plan.
327334
- [objects/physical-impact](https://github.com/MISP/misp-objects/blob/main/objects/physical-impact/definition.json) - Physical Impact object as described in STIX 2.1 Incident object extension.
328335
- [objects/postal-address](https://github.com/MISP/misp-objects/blob/main/objects/postal-address/definition.json) - A postal address.
329336
- [objects/probabilistic-data-structure](https://github.com/MISP/misp-objects/blob/main/objects/probabilistic-data-structure/definition.json) - Probabilistic data structure object describe a space-efficient data structure such as Bloom filter or similar structure.
@@ -333,7 +340,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
333340
- [objects/query](https://github.com/MISP/misp-objects/blob/main/objects/query/definition.json) - An object describing a query, along with its format.
334341
- [objects/r2graphity](https://github.com/MISP/misp-objects/blob/main/objects/r2graphity/definition.json) - Indicators extracted from files using radare2 and graphml.
335342
- [objects/ransom-negotiation](https://github.com/MISP/misp-objects/blob/main/objects/ransom-negotiation/definition.json) - An object to describe ransom negotiations, as seen in ransomware incidents.
336-
- [objects/ransomware-group-post](https://github.com/MISP/misp-objects/blob/main/objects/ransomware-group-post/definition.json) - Ransomware group post as monitored by ransomlook.io.
343+
- [objects/ransomware-group-post](https://github.com/MISP/misp-objects/blob/main/objects/ransomware-group-post/definition.json) - Ransomware group post as monitored by ransomlook.io or others.
337344
- [objects/reddit-account](https://github.com/MISP/misp-objects/blob/main/objects/reddit-account/definition.json) - Reddit account.
338345
- [objects/reddit-comment](https://github.com/MISP/misp-objects/blob/main/objects/reddit-comment/definition.json) - A Reddit post comment.
339346
- [objects/reddit-post](https://github.com/MISP/misp-objects/blob/main/objects/reddit-post/definition.json) - A Reddit post.
@@ -390,6 +397,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
390397
- [objects/splunk](https://github.com/MISP/misp-objects/blob/main/objects/splunk/definition.json) - Splunk / Splunk ES object.
391398
- [objects/ss7-attack](https://github.com/MISP/misp-objects/blob/main/objects/ss7-attack/definition.json) - SS7 object of an attack as seen on the SS7 signaling protocol supporting GSM/GPRS/UMTS networks.
392399
- [objects/ssh-authorized-keys](https://github.com/MISP/misp-objects/blob/main/objects/ssh-authorized-keys/definition.json) - An object to store ssh authorized keys file.
400+
- [objects/stairwell](https://github.com/MISP/misp-objects/blob/main/objects/stairwell/definition.json) - Stairwell leverages automated analysis, YARA rule libraries, shared malware feeds, privately run AV verdicts, static & dynamic analysis, malware unpacking, and variant discovery.
393401
- [objects/stix2-pattern](https://github.com/MISP/misp-objects/blob/main/objects/stix2-pattern/definition.json) - An object describing a STIX pattern. The object can be linked via a relationship to other attributes or objects to describe how it can be represented as a STIX pattern.
394402
- [objects/stock](https://github.com/MISP/misp-objects/blob/main/objects/stock/definition.json) - Object to describe stock market.
395403
- [objects/submarine](https://github.com/MISP/misp-objects/blob/main/objects/submarine/definition.json) - Submarine description.
@@ -470,7 +478,7 @@ When the object is created, the `validate_all.sh` and `jq_all_the_things.sh` is
470478
- Add a description in the object template explaining the scope and use-cases of your object templates
471479
- If the object is the mapping of an existing format, add a reference into the description of the object template
472480
- `first-seen` and `last-seen` are not required in a object template as an object has those fields by default. If you need additional temporal information, add new specific field(s).
473-
- Be lax on the number of fields required by default (e.g. use `requiredOneOf`).
481+
- Be lax on the number of fields required by default (e.g. use `requiredOneOf`).
474482
- Review existing object templates before creating a new one. When doing a pull-request, don't hesitate to add the logic why a new template is required.
475483

476484
## MISP objects documentation
@@ -498,11 +506,12 @@ The MISP objects (JSON files) are dual-licensed under:
498506
or
499507

500508
~~~~
501-
Copyright (c) 2016-2023 Alexandre Dulaunoy - a@foo.be
502-
Copyright (c) 2016-2023 CIRCL - Computer Incident Response Center Luxembourg
503-
Copyright (c) 2016-2023 Andras Iklody
504-
Copyright (c) 2016-2023 Raphael Vinot
505-
Copyright (c) 2016-2023 Various contributors to MISP Project
509+
Copyright (c) 2016-2024 Alexandre Dulaunoy - a@foo.be
510+
Copyright (c) 2016-2024 CIRCL - Computer Incident Response Center Luxembourg
511+
Copyright (c) 2016-2024 Andras Iklody
512+
Copyright (c) 2016-2024 Raphael Vinot
513+
Copyright (c) 2016-2024 Christian Studer
514+
Copyright (c) 2016-2024 Various contributors to MISP Project
506515
507516
Redistribution and use in source and binary forms, with or without modification,
508517
are permitted provided that the following conditions are met:
@@ -532,9 +541,9 @@ If a specific author of a taxonomy wants to license it under a different license
532541
533542
~~~~
534543

535-
Copyright (C) 2016-2023 Andras Iklody
536-
Copyright (C) 2016-2023 Alexandre Dulaunoy
537-
Copyright (C) 2016-2023 CIRCL - Computer Incident Response Center Luxembourg
544+
Copyright (C) 2016-2024 Andras Iklody
545+
Copyright (C) 2016-2024 Alexandre Dulaunoy
546+
Copyright (C) 2016-2024 CIRCL - Computer Incident Response Center Luxembourg
538547

539548
This program is free software: you can redistribute it and/or modify
540549
it under the terms of the GNU Affero General Public License as published by

objects/abuseipdb/definition.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
"attributes": {
33
"abuse-confidence-score": {
44
"description": "Rating (0-100) of how confident AbuseIPDB is that an IP address is entirely malicious",
5-
"misp-attribute": "counter",
5+
"misp-attribute": "integer",
66
"ui-priority": 0
77
},
88
"is-malicious": {
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"attributes": {
3+
"favicon-mmh3": {
4+
"description": "Favicon of the phishing url in Murmurhash3 format (base64).",
5+
"misp-attribute": "text",
6+
"ui-priority": 0
7+
},
8+
"html-structure": {
9+
"description": "HTML tags defining the structure of the HTML page.",
10+
"disable_correlation": true,
11+
"misp-attribute": "text",
12+
"ui-priority": 0
13+
},
14+
"phash-dct-base64": {
15+
"description": "pHash (DCT hash) - as described in https://github.com/thorn-oss/perception.",
16+
"misp-attribute": "text",
17+
"ui-priority": 0
18+
},
19+
"truncated-hash-html-structure": {
20+
"description": "Truncated hash value of the html-structure.",
21+
"misp-attribute": "text",
22+
"ui-priority": 0
23+
},
24+
"url": {
25+
"description": "Full URL of the phishing object.",
26+
"misp-attribute": "url",
27+
"ui-priority": 1
28+
}
29+
},
30+
"description": "cert.pl phishing object template representing an url along with some metadata as such phash, html-structure or partial-hash",
31+
"meta-category": "network",
32+
"name": "cert-pl-phishing",
33+
"requiredOneOf": [
34+
"url",
35+
"phash-dct-base64",
36+
"html-structure",
37+
"truncated-hash-html-structure",
38+
"favicon-mmh3"
39+
],
40+
"uuid": "4c37c9af-ca71-4365-bcfb-6393c22dd88e",
41+
"version": 1
42+
}

objects/concordia-mtmf-intrusion-set/definition.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,14 +10,14 @@
1010
"CMTMF_ATCKID": {
1111
"description": "Identifier of the Attack",
1212
"disable_correlation": false,
13-
"misp-attribute": "counter",
13+
"misp-attribute": "integer",
1414
"recommended": true,
1515
"ui-priority": 1
1616
},
1717
"FeedbackLoop": {
1818
"description": "Feedback Loop Sequence",
1919
"disable_correlation": false,
20-
"misp-attribute": "counter",
20+
"misp-attribute": "integer",
2121
"ui-priority": 0
2222
},
2323
"PhName": {
@@ -30,7 +30,7 @@
3030
"PhSequence": {
3131
"description": "Phase Sequence",
3232
"disable_correlation": true,
33-
"misp-attribute": "counter",
33+
"misp-attribute": "integer",
3434
"recommended": true,
3535
"ui-priority": 0
3636
},

objects/covid19-csse-daily-report/definition.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
"county": {
2222
"description": "US County (US Only)",
2323
"disable_correlation": true,
24-
"misp-attribute": "counter",
24+
"misp-attribute": "integer",
2525
"ui-priority": 0
2626
},
2727
"death": {
@@ -33,7 +33,7 @@
3333
"fips": {
3434
"description": "Federal Information Processing Standard county code (US Only)",
3535
"disable_correlation": true,
36-
"misp-attribute": "counter",
36+
"misp-attribute": "integer",
3737
"ui-priority": 0
3838
},
3939
"latitude": {

0 commit comments

Comments
 (0)