Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
78 changes: 78 additions & 0 deletions objects/container-image/definition.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
{
"attributes": {
"architecture": {
"description": "CPU architecture for the image (e.g., amd64, arm64).",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 7
},
"created": {
"description": "Date and time at which the image was created.",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 6
},
"digest": {
"description": "Image digest.",
"misp-attribute": "sha256",
"ui-priority": 9
},
"image-name": {
"description": "Name of the image (e.g., nginx).",
"misp-attribute": "text",
"ui-priority": 10
},
"labels": {
"description": "Metadata labels attached to the image.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 4
},
"layers": {
"description": "List of image layers or references to them.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 5
},
"os": {
"description": "Base OS of the image (e.g., alpine, debian).",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 7
},
"registry": {
"description": "Container registry URL or name (e.g., docker.io, ghcr.io).",
"misp-attribute": "text",
"ui-priority": 8
},
"signature": {
"description": "Signing information for the image (e.g., cosign metadata).",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 4
},
"size": {
"description": "Image size in bytes.",
"disable_correlation": true,
"misp-attribute": "counter",
"ui-priority": 6
},
"tag": {
"description": "Image tag (e.g., latest, 1.21-alpine).",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 9
}
},
"description": "Generic container-image object template to represent container images across platforms.",
"meta-category": "misc",
"name": "container-image",
"requiredOneOf": [
"image-name",
"digest"
],
"uuid": "4aa82e67-ed3d-48a2-8ecd-7a39cf2c3f3c",
"version": 1
}
126 changes: 126 additions & 0 deletions objects/container-instance/definition.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,126 @@
{
"attributes": {
"capabilities": {
"description": "Additional Linux capabilities granted to the container.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 5
},
"command": {
"description": "Command used to start the container.",
"misp-attribute": "text",
"ui-priority": 8
},
"container-id": {
"description": "Identifier of the container instance.",
"misp-attribute": "text",
"ui-priority": 10
},
"created": {
"description": "Date and time when the container was created.",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 7
},
"environment-variables": {
"description": "Environment variables configured for the container.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 3
},
"finished": {
"description": "Date and time when the container finished.",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 7
},
"hostname": {
"description": "Hostname configured for the container.",
"disable_correlation": true,
"misp-attribute": "hostname",
"ui-priority": 6
},
"image": {
"description": "Reference to image used by the container.",
"misp-attribute": "text",
"ui-priority": 9
},
"ip-address": {
"description": "IP address assigned to the container.",
"misp-attribute": "ip-dst",
"multiple": true,
"ui-priority": 4
},
"mounts": {
"description": "Mount points attached to the container.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 4
},
"network-mode": {
"description": "Networking mode configured for the container.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 4
},
"ports": {
"description": "Exposed or mapped ports for the container.",
"disable_correlation": true,
"misp-attribute": "port",
"multiple": true,
"ui-priority": 4
},
"privileged": {
"description": "Indicates whether the container was run in privileged mode.",
"disable_correlation": true,
"misp-attribute": "boolean",
"sane_default": [
"1",
"0"
],
"ui-priority": 6
},
"security-opt": {
"description": "Security options applied to the container.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 5
},
"started": {
"description": "Date and time when the container was started.",
"disable_correlation": true,
"misp-attribute": "datetime",
"ui-priority": 7
},
"state": {
"description": "Runtime state of the container (e.g., running, exited, paused).",
"disable_correlation": true,
"misp-attribute": "text",
"sane_default": [
"running",
"exited",
"paused"
],
"ui-priority": 8
},
"user": {
"description": "User configured to run inside the container.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 6
}
},
"description": "Generic container-instance object template to represent runtime container details.",
"meta-category": "misc",
"name": "container-instance",
"requiredOneOf": [
"container-id",
"image"
],
"uuid": "abbf4433-be8f-409e-8a9b-20cf0cc5bb48",
"version": 1
}
60 changes: 60 additions & 0 deletions objects/container-network/definition.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
{
"attributes": {
"connected-containers": {
"description": "Connected container identifiers or references.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 6
},
"dns": {
"description": "DNS server(s) configured for the network.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 4
},
"driver": {
"description": "Network driver type (e.g., bridge, overlay).",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 9
},
"gateway": {
"description": "Gateway address for the container network.",
"misp-attribute": "ip-dst",
"ui-priority": 7
},
"internal": {
"description": "Indicates whether the network is internal-only.",
"disable_correlation": true,
"misp-attribute": "boolean",
"sane_default": [
"1",
"0"
],
"ui-priority": 5
},
"network-name": {
"description": "Name of the container network.",
"misp-attribute": "text",
"ui-priority": 10
},
"subnet": {
"description": "Subnet used by the container network.",
"disable_correlation": true,
"misp-attribute": "text",
"multiple": true,
"ui-priority": 8
}
},
"description": "Generic container-network object template to represent container networking settings.",
"meta-category": "network",
"name": "container-network",
"requiredOneOf": [
"network-name",
"subnet"
],
"uuid": "2e821b9d-3a49-4dd8-b0bd-2b266a8cb98a",
"version": 1
}
36 changes: 36 additions & 0 deletions objects/service/definition.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"attributes": {
"command-line": {
"description": "Command line used to run the service.",
"misp-attribute": "text",
"ui-priority": 7
},
"function": {
"description": "Function or purpose of the service.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 8
},
"name": {
"description": "Name of the service.",
"misp-attribute": "text",
"ui-priority": 10
},
"port": {
"description": "Port used by the service.",
"disable_correlation": true,
"misp-attribute": "port",
"multiple": true,
"ui-priority": 9
}
},
"description": "Generic service object template to represent services that may be attacked or compromised.",
"meta-category": "misc",
"name": "service",
"requiredOneOf": [
"name",
"command-line"
],
"uuid": "c69bd10e-0829-451d-8fe5-9ee4dda4492a",
"version": 1
}
46 changes: 46 additions & 0 deletions objects/software-package/definition.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
{
"attributes": {
"description": {
"description": "Description of the software package.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 4
},
"name": {
"description": "Name of the software package.",
"misp-attribute": "text",
"ui-priority": 10
},
"state": {
"description": "Known state of the package (e.g., valid, backdoored, unknown).",
"disable_correlation": true,
"misp-attribute": "text",
"sane_default": [
"valid",
"backdoored",
"unknown"
],
"ui-priority": 7
},
"vendor": {
"description": "Vendor or maintainer of the software package.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 8
},
"version": {
"description": "Version of the software package.",
"disable_correlation": true,
"misp-attribute": "text",
"ui-priority": 9
}
},
"description": "Generic software package object template to represent software packages and their state.",
"meta-category": "misc",
"name": "software-package",
"requiredOneOf": [
"name"
],
"uuid": "77038ecf-89e3-4115-a86f-4d00f0308e1e",
"version": 1
}
Loading