Skip to content

Commit e94facd

Browse files
committed
Merge branch 'main' of github.com:MISP/misp-objects
2 parents e062377 + a3c8d30 commit e94facd

7 files changed

Lines changed: 119 additions & 28 deletions

File tree

README.md

Lines changed: 15 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -193,9 +193,10 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
193193
- [objects/fail2ban](https://github.com/MISP/misp-objects/blob/main/objects/fail2ban/definition.json) - Fail2ban event.
194194
- [objects/favicon](https://github.com/MISP/misp-objects/blob/main/objects/favicon/definition.json) - A favicon, also known as a shortcut icon, website icon, tab icon, URL icon, or bookmark icon, is a file containing one or more small icons, associated with a particular website or web page. The object template can include the murmur3 hash of the favicon to facilitate correlation.
195195
- [objects/file](https://github.com/MISP/misp-objects/blob/main/objects/file/definition.json) - File object describing a file with meta-information.
196-
- [objects/flowintel-cm-case](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-cm-case/definition.json) - A case as defined by flowintel-cm.
197-
- [objects/flowintel-cm-task](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-cm-task/definition.json) - A task as defined by flowintel-cm.
198-
- [objects/flowintel-cm-task-note](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-cm-task-note/definition.json) - A task's note as defined by flowintel-cm.
196+
- [objects/flowintel-case](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-case/definition.json) - A case as defined by flowintel.
197+
- [objects/flowintel-task](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-task/definition.json) - A task as defined by flowintel.
198+
- [objects/flowintel-task-note](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-task-note/definition.json) - A task's note as defined by flowintel.
199+
- [objects/flowintel-task-resource](https://github.com/MISP/misp-objects/blob/main/objects/flowintel-task-resource/definition.json) - A task's resource as defined by flowintel.
199200
- [objects/forensic-case](https://github.com/MISP/misp-objects/blob/main/objects/forensic-case/definition.json) - An object template to describe a digital forensic case.
200201
- [objects/forensic-evidence](https://github.com/MISP/misp-objects/blob/main/objects/forensic-evidence/definition.json) - An object template to describe a digital forensic evidence.
201202
- [objects/forged-document](https://github.com/MISP/misp-objects/blob/main/objects/forged-document/definition.json) - Object describing a forged document.
@@ -255,8 +256,11 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
255256
- [objects/Generalizing Persuasion Framework](https://github.com/MISP/misp-objects/blob/main/objects/Generalizing Persuasion Framework/definition.json) - By placing their work within the GP Framework, scholars will help the field resolve inconsistencies, identify and address open questions, and ensure collective progress. The GP Framework is not meant to compete with other theories (such as the ELM) but rather to fill in two gaps. First, it allows one to consider how individual persuasion studies connect to one another and why studies may arrive at contradictory conclusions. Second, it highlights the sources of variations that should be studied. (James N. Druckman).
256257
- [objects/geolocation](https://github.com/MISP/misp-objects/blob/main/objects/geolocation/definition.json) - An object to describe a geographic location.
257258
- [objects/git-vuln-finder](https://github.com/MISP/misp-objects/blob/main/objects/git-vuln-finder/definition.json) - Export from git-vuln-finder.
259+
- [objects/github-action](https://github.com/MISP/misp-objects/blob/main/objects/github-action/definition.json) - GitHub Actions.
260+
- [objects/github-repo](https://github.com/MISP/misp-objects/blob/main/objects/github-repo/definition.json) - GitHub repository.
258261
- [objects/github-user](https://github.com/MISP/misp-objects/blob/main/objects/github-user/definition.json) - GitHub user.
259262
- [objects/gitlab-user](https://github.com/MISP/misp-objects/blob/main/objects/gitlab-user/definition.json) - GitLab user. Gitlab.com user or self-hosted GitLab instance.
263+
- [objects/google-account](https://github.com/MISP/misp-objects/blob/main/objects/google-account/definition.json) - An object containing subscriber information received from Google.
260264
- [objects/google-safe-browsing](https://github.com/MISP/misp-objects/blob/main/objects/google-safe-browsing/definition.json) - Google Safe checks a URL against Google's constantly updated list of unsafe web resources.
261265
- [objects/google-threat-intelligence-report](https://github.com/MISP/misp-objects/blob/main/objects/google-threat-intelligence-report/definition.json) - Google Threat Intelligence report that provides an assessment (verdict, severity and scoring) and combined information from VirusTotal and Mandiant.
262266
- [objects/greynoise-ip](https://github.com/MISP/misp-objects/blob/main/objects/greynoise-ip/definition.json) - GreyNoise IP Information.
@@ -309,6 +313,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
309313
- [objects/narrative](https://github.com/MISP/misp-objects/blob/main/objects/narrative/definition.json) - Object describing a narrative.
310314
- [objects/netflow](https://github.com/MISP/misp-objects/blob/main/objects/netflow/definition.json) - Netflow object describes an network object based on the Netflowv5/v9 minimal definition.
311315
- [objects/network-connection](https://github.com/MISP/misp-objects/blob/main/objects/network-connection/definition.json) - A local or remote network connection.
316+
- [objects/network-data](https://github.com/MISP/misp-objects/blob/main/objects/network-data/definition.json) - network data, including payloads/logs, relevant timestamps, data volume and enrichment of the TCP/IP 5-tuple connection information.
312317
- [objects/network-profile](https://github.com/MISP/misp-objects/blob/main/objects/network-profile/definition.json) - Elements that can be used to profile, pivot or identify a network infrastructure, including domains, ip and urls.
313318
- [objects/network-socket](https://github.com/MISP/misp-objects/blob/main/objects/network-socket/definition.json) - Network socket object describes a local or remote network connections based on the socket data structure.
314319
- [objects/network-traffic](https://github.com/MISP/misp-objects/blob/main/objects/network-traffic/definition.json) - Generic network traffic that originates from a source and is addressed to a destination.
@@ -411,6 +416,7 @@ for a specific attribute. An optional **to_ids** boolean field to disable the ID
411416
- [objects/stix2-pattern](https://github.com/MISP/misp-objects/blob/main/objects/stix2-pattern/definition.json) - An object describing a STIX pattern. The object can be linked via a relationship to other attributes or objects to describe how it can be represented as a STIX pattern.
412417
- [objects/stock](https://github.com/MISP/misp-objects/blob/main/objects/stock/definition.json) - Object to describe stock market.
413418
- [objects/submarine](https://github.com/MISP/misp-objects/blob/main/objects/submarine/definition.json) - Submarine description.
419+
- [objects/summariser-output](https://github.com/MISP/misp-objects/blob/main/objects/summariser-output/definition.json) - Summariser output from an AI-based or NLP summariser.
414420
- [objects/suricata](https://github.com/MISP/misp-objects/blob/main/objects/suricata/definition.json) - An object describing one or more Suricata rule(s) along with version and contextual information.
415421
- [objects/target-system](https://github.com/MISP/misp-objects/blob/main/objects/target-system/definition.json) - Description about an targeted system, this could potentially be a compromised internal system.
416422
- [objects/task](https://github.com/MISP/misp-objects/blob/main/objects/task/definition.json) - Task object as described in STIX 2.1 Incident object extension.
@@ -517,12 +523,12 @@ The MISP objects (JSON files) are dual-licensed under:
517523
or
518524

519525
~~~~
520-
Copyright (c) 2016-2024 Alexandre Dulaunoy - a@foo.be
521-
Copyright (c) 2016-2024 CIRCL - Computer Incident Response Center Luxembourg
522-
Copyright (c) 2016-2024 Andras Iklody
523-
Copyright (c) 2016-2024 Raphael Vinot
524-
Copyright (c) 2016-2024 Christian Studer
525-
Copyright (c) 2016-2024 Various contributors to MISP Project
526+
Copyright (c) 2016-2025 Alexandre Dulaunoy - a@foo.be
527+
Copyright (c) 2016-2025 CIRCL - Computer Incident Response Center Luxembourg
528+
Copyright (c) 2016-2025 Andras Iklody
529+
Copyright (c) 2016-2025 Raphael Vinot
530+
Copyright (c) 2016-2025 Christian Studer
531+
Copyright (c) 2016-2025 Various contributors to MISP Project
526532
527533
Redistribution and use in source and binary forms, with or without modification,
528534
are permitted provided that the following conditions are met:
Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -88,9 +88,9 @@
8888
"ui-priority": 1
8989
}
9090
},
91-
"description": "A case as defined by flowintel-cm.",
91+
"description": "A case as defined by flowintel.",
9292
"meta-category": "misc",
93-
"name": "flowintel-cm-case",
93+
"name": "flowintel-case",
9494
"uuid": "19df57c7-b315-4fd2-84e5-d81ab221425e",
95-
"version": 3
95+
"version": 4
9696
}

objects/flowintel-cm-task-note/definition.json renamed to objects/flowintel-task-note/definition.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,9 +27,9 @@
2727
"ui-priority": 2
2828
}
2929
},
30-
"description": "A task's note as defined by flowintel-cm.",
30+
"description": "A task's note as defined by flowintel.",
3131
"meta-category": "misc",
32-
"name": "flowintel-cm-task-note",
32+
"name": "flowintel-task-note",
3333
"uuid": "2c6f6aba-48b6-482f-a810-81934d29be9a",
34-
"version": 1
34+
"version": 2
3535
}
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
{
2+
"attributes": {
3+
"origin-url": {
4+
"description": "Origin of the task",
5+
"disable_correlation": true,
6+
"misp-attribute": "url",
7+
"to_ids": false,
8+
"ui-priority": 1
9+
},
10+
"resource": {
11+
"description": "Resources of the task",
12+
"disable_correlation": true,
13+
"misp-attribute": "text",
14+
"to_ids": false,
15+
"ui-priority": 0
16+
},
17+
"resource-uuid": {
18+
"description": "UUID of the resource",
19+
"disable_correlation": true,
20+
"misp-attribute": "text",
21+
"ui-priority": 2
22+
},
23+
"task-uuid": {
24+
"description": "UUID of the parent task",
25+
"disable_correlation": true,
26+
"misp-attribute": "text",
27+
"ui-priority": 2
28+
}
29+
},
30+
"description": "A task's note as defined by flowintel.",
31+
"meta-category": "misc",
32+
"name": "flowintel-task-resource",
33+
"uuid": "dc1d5bae-3611-499c-bbd6-1ca3ad4048dd",
34+
"version": 1
35+
}
Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -78,9 +78,9 @@
7878
"ui-priority": 0
7979
}
8080
},
81-
"description": "A task as defined by flowintel-cm.",
81+
"description": "A task as defined by flowintel.",
8282
"meta-category": "misc",
83-
"name": "flowintel-cm-task",
83+
"name": "flowintel-task",
8484
"uuid": "2f525f6e-d3f2-4cb9-9ca0-f1160d99397d",
85-
"version": 4
85+
"version": 5
8686
}

objects/greynoise-ip/definition.json

Lines changed: 56 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -4,59 +4,107 @@
44
"description": "GreyNoise Actor",
55
"disable_correlation": true,
66
"misp-attribute": "text",
7+
"ui-priority": 4
8+
},
9+
"asn": {
10+
"description": "GreyNoise ASN",
11+
"disable_correlation": true,
12+
"misp-attribute": "AS",
13+
"ui-priority": 3
14+
},
15+
"bot": {
16+
"description": "GreyNoise Is Bot Flag",
17+
"disable_correlation": true,
18+
"misp-attribute": "boolean",
719
"ui-priority": 1
820
},
921
"classification": {
1022
"description": "GreyNoise Classification",
1123
"disable_correlation": true,
1224
"misp-attribute": "text",
13-
"ui-priority": 1
25+
"ui-priority": 6
26+
},
27+
"domain": {
28+
"description": "GreyNoise Domain",
29+
"disable_correlation": false,
30+
"misp-attribute": "domain",
31+
"ui-priority": 6
1432
},
1533
"first-seen": {
1634
"description": "First Seen",
1735
"disable_correlation": true,
1836
"misp-attribute": "datetime",
19-
"ui-priority": 2
37+
"ui-priority": 5
2038
},
2139
"ip-src": {
2240
"description": "Source IP address of the network connection.",
2341
"misp-attribute": "ip-src",
24-
"ui-priority": 1
42+
"ui-priority": 7
2543
},
2644
"last-seen": {
2745
"description": "Last Seen",
2846
"disable_correlation": true,
2947
"misp-attribute": "datetime",
30-
"ui-priority": 1
48+
"ui-priority": 5
3149
},
3250
"link": {
3351
"description": "GreyNoise Visualizer Link",
3452
"disable_correlation": true,
3553
"misp-attribute": "link",
36-
"ui-priority": 2
54+
"ui-priority": 4
3755
},
3856
"noise": {
3957
"description": "GreyNoise Internet Scanning Flag",
4058
"disable_correlation": true,
4159
"misp-attribute": "text",
42-
"ui-priority": 1
60+
"ui-priority": 4
4361
},
4462
"provider": {
4563
"description": "GreyNoise Service Provider",
4664
"disable_correlation": true,
4765
"misp-attribute": "text",
48-
"ui-priority": 1
66+
"ui-priority": 4
67+
},
68+
"rdns": {
69+
"description": "GreyNoise Reverse DNS Hostname",
70+
"disable_correlation": false,
71+
"misp-attribute": "hostname",
72+
"ui-priority": 2
73+
},
74+
"rdns_parent": {
75+
"description": "GreyNoise Reverse DNS Domain",
76+
"disable_correlation": true,
77+
"misp-attribute": "domain",
78+
"ui-priority": 2
4979
},
5080
"riot": {
5181
"description": "GreyNoise Common Business Service Flag",
5282
"disable_correlation": true,
5383
"misp-attribute": "text",
84+
"ui-priority": 4
85+
},
86+
"source_country": {
87+
"description": "GreyNoise Source Country",
88+
"disable_correlation": true,
89+
"misp-attribute": "text",
90+
"ui-priority": 3
91+
},
92+
"tor": {
93+
"description": "GreyNoise Is Tor Flag",
94+
"disable_correlation": true,
95+
"misp-attribute": "boolean",
5496
"ui-priority": 1
5597
},
5698
"trust-level": {
5799
"description": "GreyNoise RIOT Trust Level",
58100
"disable_correlation": true,
59101
"misp-attribute": "text",
102+
"ui-priority": 4
103+
},
104+
"vpn": {
105+
"description": "GreyNoise Is VPN Flag",
106+
"disable_correlation": true,
107+
"misp-attribute": "boolean",
60108
"ui-priority": 1
61109
}
62110
},
@@ -67,5 +115,5 @@
67115
"ip-src"
68116
],
69117
"uuid": "6B14A94A-46E4-4B82-B24D-0DBF8E8B3FD9",
70-
"version": 1
118+
"version": 2
71119
}

objects/query/definition.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,9 @@
2727
"Google search query",
2828
"Ariel Query Language (qradar)",
2929
"Grep",
30-
"Devo LINQ"
30+
"Devo LINQ",
31+
"Microsoft Defender XDR",
32+
"Sentinel Advanced Security Information Model"
3133
],
3234
"ui-priority": 0
3335
},
@@ -49,5 +51,5 @@
4951
"query"
5052
],
5153
"uuid": "006539b3-f68a-4a02-a213-e600762d39b5",
52-
"version": 3
54+
"version": 4
5355
}

0 commit comments

Comments
 (0)