
Plantillas de objetos JSON seleccionadas que definen atributos MISP y tipos de relaciones para la compartición estructurada de inteligencia de amenazas y el intercambio interoperable de IOC.

Los objetos MISP se utilizan en el sistema MISP y pueden ser usados por otras herramientas de intercambio de información. Los objetos MISP son adicionales a los atributos MISP para permitir combinaciones avanzadas de atributos. La creación de estos objetos y sus atributos asociados se basa en casos de uso reales de ciberseguridad y en prácticas existentes en el intercambio de información.
Siéntase libre de proponer sus propias plantillas de objetos MISP para que se incluyan en MISP. El sistema es similar al de misp-taxonomies, donde cualquiera puede contribuir con sus propios objetos para que se incluyan en MISP sin modificar el software.
{ "attributes": { "domain": { "categories": [ "Network activity", "External analysis" ], "description": "Domain name", "misp-attribute": "domain", "multiple": true, "ui-priority": 1 }, "first-seen": { "description": "First time the tuple has been seen", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 }, "ip": { "categories": [ "Network activity", "External analysis" ], "description": "IP Address", "misp-attribute": "ip-dst", "multiple": true, "ui-priority": 1 }, "last-seen": { "description": "Last time the tuple has been seen", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 }, "port": { "categories": [ "Network activity", "External analysis" ], "description": "Associated TCP port with the domain", "misp-attribute": "port", "multiple": true, "ui-priority": 1 }, "registration-date": { "description": "Registration date of domain", "disable_correlation": false, "misp-attribute": "datetime", "ui-priority": 0 }, "text": { "description": "A description of the tuple", "disable_correlation": true, "misp-attribute": "text", "ui-priority": 1 } }, "description": "A domain and IP address seen as a tuple in a specific time frame.", "meta-category": "network", "name": "domain-ip", "required": [ "ip", "domain" ], "uuid": "43b3b146-77eb-4931-b4cc-b66c60f28734", "version": 8 }
A MISP object is described in a simple JSON file containing the following elements.
* **name** is the name of the your object.
* **meta-category** is the category where the object falls into. (such as file, network, financial, misc, internal...)
* **description** is a summary of the object description.
* **version** is the version number as a decimal value.
* **required** is an array containing the minimal required attributes to describe the object.
* **requiredOneOf** is an array containing the attributes where at least one needs to be present to describe the object.
* **attributes** contains another JSON object listing all the attributes composing the object.
Each attribute must contain a reference **misp-attribute** to reference an existing attribute definition in MISP (MISP attributes types are case-sensitive).
An array **categories** shall be used to describe in which categories the attribute is. The **ui-priority**
describes the usage frequency of an attribute. This helps to only display the most frequently used attributes and
allowing advanced users to show all the attributes depending of their configuration. An optional **multiple** field
shall be set to true if multiple elements of the same key can be used in the object. An optional **values_list**
where this list of values can be selected as a value for an attribute. An optional **sane_default** where this list of value recommend
potential a sane default for an attribute. An optional **disable_correlation** boolean field to suggest the disabling of correlation
for a specific attribute. An optional **to_ids** boolean field to disable the IDS flag of an attribute.