v2.166.0 Model Updates
The following model updates were made during the v2.166.0 Synapse release.
New Forms
inet:tls:handshakeAn instance of a TLS handshake between a server and client.
inet:tls:ja3:sampleA JA3 sample taken from a client.
inet:tls:ja3s:sampleA JA3 sample taken from a server.
inet:tls:servercertAn x509 certificate sent by a server for TLS.
inet:tls:clientcertAn x509 certificate sent by a client for TLS.
New Properties
risk:extortionThe form had the following property added to it:
deadlineThe time that the demand must be met.
risk:leakThe form had the following properties added on it:
extortionThe extortion event which used the threat of the leak as leverage.
size:bytesThe approximate uncompressed size of the total data leaked.
it:mitre:attack:techniqueThe form had the following properties updated on it:
nameThis property is now lower-cased and single spaced.
Deprecated Forms
The following forms have been marked as deprecated:
inet:ssl:certPlease use
inet:tls:clientcertorinet:tls:servercert.
Column Display Hints
The following forms had column display hints added to them:
ou:campaignou:conferenceou:goalou:orgou:teamou:techniqueps:contactps:skillps:proficiencyrisk:threatrisk:compromiserisk:mitigationrisk:tool:software
Light Edges
usesWhen used with a
risk:extortionand anou:techniquenode, the edge indicates the attacker used the technique to extort the victim.