-
Notifications
You must be signed in to change notification settings - Fork 419
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[RFC] Create Threat Fieldset - Stage 2 Proposal (#1293)
* initial stage 2 commit * added stage 2 PR number * Update rfcs/text/0008-threat-intel.md Co-authored-by: Eric Beahan <[email protected]> * changed indicator.description to keyword * typo for t.i.dataset * updated tlp examples to match * updated people * changed .type to have 1 example * Update rfcs/text/0008/threat.yml Co-authored-by: Eric Beahan <[email protected]> * Add event fieldset under threat.indicator fieldset This is used to preserve the event fields of the original indicator event in the case of said indicator enriching another event. * Remove threat enrichment proposal/documentation This is going to become a separate RFC that proposes this use case under a slightly different schema: a nested list of objects conforming to the indicator fieldset. * removed matched in prep for future RFC * removed fieldsets that are not to be nested under threat.indicator.* * removed as.yml * removed threat.indicator from reused fields from readme * Update rfcs/text/0008-threat-intel.md Co-authored-by: Eric Beahan <[email protected]> * Update rfcs/text/0008-threat-intel.md Co-authored-by: Eric Beahan <[email protected]> * Update rfcs/text/0008-threat-intel.md Co-authored-by: Eric Beahan <[email protected]> * updated example documents * fix example formatting * another formatting fix * moved proposed fields to existing event and url fieldsets * Update threat.yml fixed a formatting issue for indicatory.type * added modified_at field * typo * Correct expected indicator.type value for X509 Certificates The documentation for the `indicator.type` field lists `x-509-certificate` as an expected value. However, the correct STIX 2.0 Cyber Observable type name for X509 Certificates is `x509-certificate`. * missing colon * set advance date Co-authored-by: Eric Beahan <[email protected]> Co-authored-by: Ryland Herrick <[email protected]> Co-authored-by: Dominic Page <[email protected]> Co-authored-by: Adrian Serrano <[email protected]>
- Loading branch information
1 parent
6200e56
commit 44d2ecd
Showing
10 changed files
with
174 additions
and
356 deletions.
There are no files selected for viewing
Large diffs are not rendered by default.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.