Synapse Data Model - Forms
Forms
Forms are derived from types, or base types. Forms represent node types in the graph.
auth:access
An instance of using creds to access a resource.
The base type for the form can be found at auth:access.
- Properties:
name
type
doc
:credsThe credentials used to attempt access.
:timeThe time of the access attempt.
:successSet to true if the access was successful.
:personThe person who attempted access.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
auth:creds
A unique set of credentials used to access a resource.
The base type for the form can be found at auth:creds.
- Properties:
name
type
doc
opts
The email address used to identify the user.
:userThe user name used to identify the user.
:phoneThe phone number used to identify the user.
:passwdThe password used to authenticate.
:passwdhashThe password hash used to authenticate.
:accountThe account that the creds allow access to.
:websiteThe base URL of the website that the credentials allow access to.
:hostThe host that the credentials allow access to.
:wifi:ssidThe WiFi SSID that the credentials allow access to.
:web:acctDeprecated. Use :service:account.
Deprecated:
True
:service:accountThe service account that the credentials allow access to.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
belief:subscriber
A contact which subscribes to a belief system.
The base type for the form can be found at belief:subscriber.
- Properties:
name
type
doc
:contactThe contact which subscribes to the belief system.
:systemThe belief system to which the contact subscribes.
:beganThe time that the contact began to be a subscriber to the belief system.
:endedThe time when the contact ceased to be a subscriber to the belief system.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
belief:subscriber
-(follows)>
belief:tenetThe subscriber is assessed to generally adhere to the specific tenet.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
belief:system
A belief system such as an ideology, philosophy, or religion.
The base type for the form can be found at belief:system.
- Properties:
name
type
doc
opts
:nameThe name of the belief system.
:descA description of the belief system.
Display:
{'hint': 'text'}
:typeA taxonometric type for the belief system.
:beganThe time that the belief system was first observed.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
belief:system
-(has)>
belief:tenetThe belief system includes the tenet.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
belief:system:type:taxonomy
A hierarchical taxonomy of belief system types.
The base type for the form can be found at belief:system:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
belief:tenet
A concrete tenet potentially shared by multiple belief systems.
The base type for the form can be found at belief:tenet.
- Properties:
name
type
doc
opts
:nameThe name of the tenet.
:descA description of the tenet.
Display:
{'hint': 'text'}- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
belief:subscriber
-(follows)>
belief:tenetThe subscriber is assessed to generally adhere to the specific tenet.
belief:system
-(has)>
belief:tenetThe belief system includes the tenet.
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:bundle
A bundle allows construction of products which bundle instances of other products.
The base type for the form can be found at biz:bundle.
- Properties:
name
type
doc
opts
:countThe number of instances of the product or service included in the bundle.
:priceThe price of the bundle.
:productThe product included in the bundle.
:serviceThe service included in the bundle.
:dealDeprecated. Please use econ:receipt:item for instances of bundles being sold.
Deprecated:
True
:purchaseDeprecated. Please use econ:receipt:item for instances of bundles being sold.
Deprecated:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:deal
A sales or procurement effort in pursuit of a purchase.
The base type for the form can be found at biz:deal.
- Properties:
name
type
doc
opts
:id strip:TrueAn identifier for the deal.
:titleA title for the deal.
:typeThe type of deal.
Display:
{'hint': 'taxonomy'}
:statusThe status of the deal.
Display:
{'hint': 'taxonomy'}
:updatedThe last time the deal had a significant update.
:contactedThe last time the contacts communicated about the deal.
:rfpThe RFP that the deal is in response to.
:buyerThe primary contact information for the buyer.
:buyer:orgThe buyer org.
:buyer:orgnameThe reported ou:name of the buyer org.
:buyer:orgfqdnThe reported inet:fqdn of the buyer org.
:sellerThe primary contact information for the seller.
:seller:orgThe seller org.
:seller:orgnameThe reported ou:name of the seller org.
:seller:orgfqdnThe reported inet:fqdn of the seller org.
:currencyThe currency of econ:price values associated with the deal.
:buyer:budgetThe buyers budget for the eventual purchase.
:buyer:deadlineWhen the buyer intends to make a decision.
:offer:priceThe total price of the offered products.
:offer:expiresWhen the offer expires.
:purchaseRecords a purchase resulting from the deal.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:dealstatus
A deal/rfp status taxonomy.
The base type for the form can be found at biz:dealstatus.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:dealtype
A deal type taxonomy.
The base type for the form can be found at biz:dealtype.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:listing
A product or service being listed for sale at a given price by a specific seller.
The base type for the form can be found at biz:listing.
- Properties:
name
type
doc
:sellerThe contact information for the seller.
:productThe product being offered.
:serviceThe service being offered.
:currentSet to true if the offer is still current.
:timeThe first known offering of this product/service by the organization for the asking price.
:expiresSet if the offer has a known expiration date.
:priceThe asking price of the product or service.
:currencyThe currency of the asking price.
:count:total min:0The number of instances for sale.
:count:remaining min:0The current remaining number of instances for sale.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:prodtype
A product type taxonomy.
The base type for the form can be found at biz:prodtype.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:product
A product which is available for purchase.
The base type for the form can be found at biz:product.
- Properties:
name
type
doc
opts
:nameThe name of the product.
:typeThe type of product.
Display:
{'hint': 'taxonomy'}
:summaryA brief summary of the product.
Display:
{'hint': 'text'}
:makerA contact for the maker of the product.
:madeby:orgDeprecated. Please use biz:product:maker.
Deprecated:
True
:madeby:orgnameDeprecated. Please use biz:product:maker.
Deprecated:
True
:madeby:orgfqdnDeprecated. Please use biz:product:maker.
Deprecated:
True
:price:retailThe MSRP price of the product.
:price:bottomThe minimum offered or observed price of the product.
:price:currencyThe currency of the retail and bottom price properties.
:bundlesAn array of bundles included with the product.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:rfp
An RFP (Request for Proposal) soliciting proposals.
The base type for the form can be found at biz:rfp.
- Properties:
name
type
doc
opts
:ext:idAn externally specified identifier for the RFP.
:titleThe title of the RFP.
:summaryA brief summary of the RFP.
Display:
{'hint': 'text'}
:statusThe status of the RFP.
Display:
{'hint': 'enum'}
:urlThe official URL for the RFP.
:fileThe RFP document.
:postedThe date/time that the RFP was posted.
:quesdueThe date/time that questions are due.
:propdueThe date/time that proposals are due.
:contactThe contact information given for the org requesting offers.
:purchasesAny known purchases that resulted from the RFP.
:requirementsA typed array which indexes each field.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:service
A service which is performed by a specific organization.
The base type for the form can be found at biz:service.
- Properties:
name
type
doc
opts
:providerThe contact info of the entity which performs the service.
:nameThe name of the service being performed.
:summaryA brief summary of the service.
Display:
{'hint': 'text'}
:typeA taxonomy of service types.
:launchedThe time when the operator first made the service available.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
biz:stake
A stake or partial ownership in a company.
The base type for the form can be found at biz:stake.
- Properties:
name
type
doc
:vitalsThe ou:vitals snapshot this stake is part of.
:orgThe resolved org.
:orgnameThe org name as reported by the source of the vitals.
:orgfqdnThe org FQDN as reported by the source of the vitals.
:nameAn arbitrary name for this stake. Can be non-contact like “pool”.
:asofThe time the stake is being measured. Likely as part of an ou:vitals.
:sharesThe number of shares represented by the stake.
:investedThe amount of money invested in the cap table iteration.
:valueThe monetary value of the stake.
:percentThe percentage ownership represented by this stake.
:ownerContact information of the owner of the stake.
:purchaseThe purchase event for the stake.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:algorithm
A cryptographic algorithm name.
The base type for the form can be found at crypto:algorithm.
An example of crypto:algorithm:
aes256
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:currency:address
An individual crypto currency address.
The base type for the form can be found at crypto:currency:address.
An example of crypto:currency:address:
btc/1BvBMSEYstWetqTFn5Au4m4GFg7xJaNVN2
- Properties:
name
type
doc
opts
:coinThe crypto coin to which the address belongs.
Read Only:
True
:seedThe cryptographic key and or password used to generate the address.
:idenThe coin specific address identifier.
Read Only:
True
:descA free-form description of the address.
:chainThe chain where the address is defined.
:contactThe primary contact for the crypto currency address.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:currency:block
An individual crypto currency block record on the blockchain.
The base type for the form can be found at crypto:currency:block.
- Properties:
name
type
doc
opts
:coinThe coin/blockchain this block resides on.
Read Only:
True
:offsetThe index of this block.
Read Only:
True
:hashThe unique hash for the block.
:minedbyThe address which mined the block.
:timeTime timestamp embedded in the block by the miner.
:chainThe chain where the block is recorded.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:currency:chain
A crypto currency chain.
The base type for the form can be found at crypto:currency:chain.
- Properties:
name
type
doc
opts
:id strip:TrueAn ID for the chain.
Example:
eip155:8453
:nameThe name of the chain.
Example:
ethereum
:symbolThe symbol associated with the native currency of the chain.
Example:
eth- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:currency:client
A fused node representing a crypto currency address used by an Internet client.
The base type for the form can be found at crypto:currency:client.
An example of crypto:currency:client:
(1.2.3.4, (btc, 1BvBMSEYstWetqTFn5Au4m4GFg7xJaNVN2))
- Properties:
name
type
doc
opts
:inetaddrThe Internet client address observed using the crypto currency address.
Read Only:
True
:coinaddrThe crypto currency address observed in use by the Internet client.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:currency:coin
An individual crypto currency type.
The base type for the form can be found at crypto:currency:coin.
An example of crypto:currency:coin:
btc
- Properties:
name
type
doc
:nameThe full name of the crypto coin.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:currency:transaction
An individual crypto currency transaction recorded on the blockchain.
The base type for the form can be found at crypto:currency:transaction.
- Properties:
name
type
doc
opts
:hashThe unique transaction hash for the transaction.
:descAn analyst specified description of the transaction.
:blockThe block which records the transaction.
:block:coinThe coin/blockchain of the block which records this transaction.
:block:offsetThe offset of the block which records this transaction.
:block:chainThe chain where the transaction is recorded.
:successSet to true if the transaction was successfully executed and recorded.
:status:codeA coin specific status code which may represent an error reason.
:status:messageA coin specific status message which may contain an error reason.
:toThe destination address of the transaction.
:fromThe source address of the transaction.
:inputsDeprecated. Please use crypto:payment:input:transaction.
Deprecated:
True
:outputsDeprecated. Please use crypto:payment:output:transaction.
Deprecated:
True
:feeThe total fee paid to execute the transaction.
:valueThe total value of the transaction.
:timeThe time this transaction was initiated.
:eth:gasusedThe amount of gas used to execute this transaction.
:eth:gaslimitThe ETH gas limit specified for this transaction.
:eth:gaspriceThe gas price (in ETH) specified for this transaction.
:contract:inputInput value to a smart contract call.
:contract:outputOutput value of a smart contract call.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:key
A cryptographic key and algorithm.
The base type for the form can be found at crypto:key.
- Properties:
name
type
doc
opts
:algorithmThe cryptographic algorithm which uses the key material.
Example:
aes256
:modeThe algorithm specific mode in use.
:ivThe hex encoded initialization vector.
:iv:textSet only if the :iv property decodes to ASCII.
:publicThe hex encoded public key material if the algorithm has a public/private key pair.
:public:textSet only if the :public property decodes to ASCII.
:public:md5The MD5 hash of the public key in raw binary form.
:public:sha1The SHA1 hash of the public key in raw binary form.
:public:sha256The SHA256 hash of the public key in raw binary form.
:privateThe hex encoded private key material. All symmetric keys are private.
:private:textSet only if the :private property decodes to ASCII.
:private:md5The MD5 hash of the private key in raw binary form.
:private:sha1The SHA1 hash of the private key in raw binary form.
:private:sha256The SHA256 hash of the private key in raw binary form.
:seed:passwdThe seed password used to generate the key material.
:seed:algorithmThe algorithm used to generate the key from the seed password.
Example:
pbkdf2- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
crypto:key
-(decrypts)>
file:bytesThe key is used to decrypt the file.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:payment:input
A payment made into a transaction.
The base type for the form can be found at crypto:payment:input.
- Properties:
name
type
doc
:indexThe index of this input in the array of inputs for the transaction.
:transactionThe transaction the payment was input to.
:addressThe address which paid into the transaction.
:valueThe value of the currency paid into the transaction.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:payment:output
A payment received from a transaction.
The base type for the form can be found at crypto:payment:output.
- Properties:
name
type
doc
:indexThe index of this output in the array of outputs for the transaction.
:transactionThe transaction the payment was output from.
:addressThe address which received payment from the transaction.
:valueThe value of the currency received from the transaction.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:contract
A smart contract.
The base type for the form can be found at crypto:smart:contract.
- Properties:
name
type
doc
:transactionThe transaction which created the contract.
:addressThe address of the contract.
:bytecodeThe bytecode which implements the contract.
:token:nameThe ERC-20 token name.
:token:symbolThe ERC-20 token symbol.
:token:totalsupplyThe ERC-20 totalSupply value.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:burntoken
A smart contract effect which destroys a non-fungible token.
The base type for the form can be found at crypto:smart:effect:burntoken.
- Properties:
name
type
doc
:tokenThe non-fungible token that was destroyed.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:edittokensupply
A smart contract effect which increases or decreases the supply of a fungible token.
The base type for the form can be found at crypto:smart:effect:edittokensupply.
- Properties:
name
type
doc
:contractThe contract which defines the tokens.
:amountThe number of tokens added or removed if negative.
:totalsupplyThe total supply of tokens after this modification.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:minttoken
A smart contract effect which creates a new non-fungible token.
The base type for the form can be found at crypto:smart:effect:minttoken.
- Properties:
name
type
doc
:tokenThe non-fungible token that was created.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:proxytoken
A smart contract effect which grants a non-owner address the ability to manipulate a specific non-fungible token.
The base type for the form can be found at crypto:smart:effect:proxytoken.
- Properties:
name
type
doc
:ownerThe address granting proxy authority to manipulate non-fungible tokens.
:proxyThe address granted proxy authority to manipulate non-fungible tokens.
:tokenThe specific token being granted access to.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:proxytokenall
A smart contract effect which grants a non-owner address the ability to manipulate all non-fungible tokens of the owner.
The base type for the form can be found at crypto:smart:effect:proxytokenall.
- Properties:
name
type
doc
:contractThe contract which defines the tokens.
:ownerThe address granting/denying proxy authority to manipulate all non-fungible tokens of the owner.
:proxyThe address granted/denied proxy authority to manipulate all non-fungible tokens of the owner.
:approvalThe approval status.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:proxytokens
A smart contract effect which grants a non-owner address the ability to manipulate fungible tokens.
The base type for the form can be found at crypto:smart:effect:proxytokens.
- Properties:
name
type
doc
:contractThe contract which defines the tokens.
:ownerThe address granting proxy authority to manipulate fungible tokens.
:proxyThe address granted proxy authority to manipulate fungible tokens.
:amountThe hex encoded amount of tokens the proxy is allowed to manipulate.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:transfertoken
A smart contract effect which transfers ownership of a non-fungible token.
The base type for the form can be found at crypto:smart:effect:transfertoken.
- Properties:
name
type
doc
:tokenThe non-fungible token that was transferred.
:fromThe address the NFT was transferred from.
:toThe address the NFT was transferred to.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:effect:transfertokens
A smart contract effect which transfers fungible tokens.
The base type for the form can be found at crypto:smart:effect:transfertokens.
- Properties:
name
type
doc
:contractThe contract which defines the tokens.
:fromThe address the tokens were transferred from.
:toThe address the tokens were transferred to.
:amountThe number of tokens transferred.
:indexThe order of the effect within the effects of one transaction.
:transactionThe transaction where the smart contract was called.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:smart:token
A token managed by a smart contract.
The base type for the form can be found at crypto:smart:token.
- Properties:
name
type
doc
opts
:contractThe smart contract which defines and manages the token.
Read Only:
True
:tokenidThe token ID.
Read Only:
True
:ownerThe address which currently owns the token.
:nft:urlThe URL which hosts the NFT metadata.
:nft:metaThe raw NFT metadata.
:nft:meta:nameThe name field from the NFT metadata.
:nft:meta:descriptionThe description field from the NFT metadata.
Display:
{'hint': 'text'}
:nft:meta:imageThe image URL from the NFT metadata.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:x509:cert
A unique X.509 certificate.
The base type for the form can be found at crypto:x509:cert.
- Properties:
name
type
doc
:fileThe file that the certificate metadata was parsed from.
:subjectThe subject identifier, commonly in X.500/LDAP format, to which the certificate was issued.
:issuerThe Distinguished Name (DN) of the Certificate Authority (CA) which issued the certificate.
:issuer:certThe certificate used by the issuer to sign this certificate.
:serial zeropad:40The certificate serial number as a big endian hex value.
:version enums:((0, 'v1'), (2, 'v3'))The version integer in the certificate. (ex. 2 == v3 ).
:validity:notbeforeThe timestamp for the beginning of the certificate validity period.
:validity:notafterThe timestamp for the end of the certificate validity period.
:md5The MD5 fingerprint for the certificate.
:sha1The SHA1 fingerprint for the certificate.
:sha256The SHA256 fingerprint for the certificate.
:rsa:keyThe optional RSA public key associated with the certificate.
:algoThe X.509 signature algorithm OID.
:signatureThe hexadecimal representation of the digital signature.
:ext:sansThe Subject Alternate Names (SANs) listed in the certificate.
:ext:crlsA list of Subject Alternate Names (SANs) for Distribution Points.
:identities:fqdnsThe fused list of FQDNs identified by the cert CN and SANs.
:identities:emailsThe fused list of e-mail addresses identified by the cert CN and SANs.
:identities:ipv4sThe fused list of IPv4 addresses identified by the cert CN and SANs.
:identities:ipv6sThe fused list of IPv6 addresses identified by the cert CN and SANs.
:identities:urlsThe fused list of URLs identified by the cert CN and SANs.
:crl:urlsThe extracted URL values from the CRLs extension.
:selfsignedWhether this is a self-signed certificate.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:x509:crl
A unique X.509 Certificate Revocation List.
The base type for the form can be found at crypto:x509:crl.
- Properties:
name
type
doc
:fileThe file containing the CRL.
:urlThe URL where the CRL was published.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:x509:revoked
A revocation relationship between a CRL and an X.509 certificate.
The base type for the form can be found at crypto:x509:revoked.
- Properties:
name
type
doc
opts
:crlThe CRL which revoked the certificate.
Read Only:
True
:certThe certificate revoked by the CRL.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
crypto:x509:signedfile
A digital signature relationship between an X.509 certificate and a file.
The base type for the form can be found at crypto:x509:signedfile.
- Properties:
name
type
doc
opts
:certThe certificate for the key which signed the file.
Read Only:
True
:fileThe file which was signed by the certificates key.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:policy
Guiding principles used to reach a set of goals.
The base type for the form can be found at doc:policy.
- Properties:
name
type
doc
:id strip:TrueThe policy ID.
:nameThe policy name.
:typeThe type of policy.
:textThe text of the policy.
:fileThe file which contains the policy.
:createdThe time that the policy was created.
:updatedThe time that the policy was last updated.
:authorThe contact information of the primary author.
:contributorsAn array of contacts which contributed to the policy.
:versionThe version of the policy.
:supersedesAn array of policies which are superseded by this policy.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:policy:type:taxonomy
A taxonomy of policy types.
The base type for the form can be found at doc:policy:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:requirement
A single requirement, often defined by a standard.
The base type for the form can be found at doc:requirement.
- Properties:
name
type
doc
opts
:summaryA summary of the requirement definition.
Display:
{'hint': 'text'}
:optionalSet to true if the requirement is optional as defined by the standard.
:priorityThe priority of the requirement as defined by the standard.
:standardThe standard which defined the requirement.
:id strip:TrueThe requirement ID.
:nameThe requirement name.
:typeThe type of requirement.
:textThe text of the requirement.
:fileThe file which contains the requirement.
:createdThe time that the requirement was created.
:updatedThe time that the requirement was last updated.
:authorThe contact information of the primary author.
:contributorsAn array of contacts which contributed to the requirement.
:versionThe version of the requirement.
:supersedesAn array of requirements which are superseded by this requirement.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:requirement:type:taxonomy
A taxonomy of requirement types.
The base type for the form can be found at doc:requirement:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:resume
A CV/resume document.
The base type for the form can be found at doc:resume.
- Properties:
name
type
doc
opts
:contactContact information for subject of the resume.
:summaryThe summary of qualifications from the resume.
Display:
{'hint': 'text'}
:workhistWork history described in the resume.
:educationEducation experience described in the resume.
:achievementsAchievements described in the resume.
:id strip:TrueThe resume ID.
:nameThe resume name.
:typeThe type of resume.
:textThe text of the resume.
:fileThe file which contains the resume.
:createdThe time that the resume was created.
:updatedThe time that the resume was last updated.
:authorThe contact information of the primary author.
:contributorsAn array of contacts which contributed to the resume.
:versionThe version of the resume.
:supersedesAn array of resumes which are superseded by this resume.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:resume:type:taxonomy
A taxonomy of resume types.
The base type for the form can be found at doc:resume:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:standard
A group of requirements which define how to implement a policy or goal.
The base type for the form can be found at doc:standard.
- Properties:
name
type
doc
:policyThe policy which was used to derive the standard.
:id strip:TrueThe standard ID.
:nameThe standard name.
:typeThe type of standard.
:textThe text of the standard.
:fileThe file which contains the standard.
:createdThe time that the standard was created.
:updatedThe time that the standard was last updated.
:authorThe contact information of the primary author.
:contributorsAn array of contacts which contributed to the standard.
:versionThe version of the standard.
:supersedesAn array of standards which are superseded by this standard.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
doc:standard:type:taxonomy
A taxonomy of standard types.
The base type for the form can be found at doc:standard:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:acct:balance
A snapshot of the balance of an account at a point in time.
The base type for the form can be found at econ:acct:balance.
- Properties:
name
type
doc
opts
:timeThe time the balance was recorded.
:instrumentThe financial instrument holding the balance.
:pay:cardDeprecated. Please use :instrument.
Deprecated:
True
:crypto:addressDeprecated. Please use :instrument.
Deprecated:
True
:amountThe account balance at the time.
:currencyThe currency of the balance amount.
:deltaThe change since last regular sample.
:total:receivedThe total amount of currency received by the account.
:total:sentThe total amount of currency sent from the account.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:acct:invoice
An invoice issued requesting payment.
The base type for the form can be found at econ:acct:invoice.
- Properties:
name
type
doc
:issuedThe time that the invoice was issued to the recipient.
:issuerThe contact information for the entity who issued the invoice.
:purchaseThe purchase that the invoice is requesting payment for.
:recipientThe contact information for the intended recipient of the invoice.
:dueThe time by which the payment is due.
:paidSet to true if the invoice has been paid in full.
:amountThe balance due.
:currencyThe currency that the invoice specifies for payment.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:acct:payment
A payment or crypto currency transaction.
The base type for the form can be found at econ:acct:payment.
- Properties:
name
type
doc
opts
:txnid strip:TrueA payment processor specific transaction id.
:feeThe transaction fee paid by the recipient to the payment processor.
:from:cashSet to true if the payment input was in cash.
:to:instrumentThe payment instrument which received funds from the payment.
:from:instrumentThe payment instrument used to make the payment.
:from:accountDeprecated. Please use :from:instrument.
Deprecated:
True
:from:pay:cardDeprecated. Please use :from:instrument.
Deprecated:
True
:from:contractA contract used as an aggregate payment source.
:from:coinaddrDeprecated. Please use :from:instrument.
Deprecated:
True
:from:contactContact information for the entity making the payment.
:to:cashSet to true if the payment output was in cash.
:to:accountDeprecated. Please use :to:instrument.
Deprecated:
True
:to:coinaddrDeprecated. Please use :to:instrument.
Deprecated:
True
:to:contactContact information for the person/org being paid.
:to:contractA contract used as an aggregate payment destination.
:timeThe time the payment was processed.
:purchaseThe purchase which the payment was paying for.
:amountThe amount of money transferred in the payment.
:currencyThe currency of the payment.
:memoA small note specified by the payer common in financial transactions.
:crypto:transactionA crypto currency transaction that initiated the payment.
:invoiceThe invoice that the payment applies to.
:receiptThe receipt that was issued for the payment.
:placeThe place where the payment occurred.
:place:nameThe name of the place where the payment occurred.
:place:addressThe address of the place where the payment occurred.
:place:locThe loc of the place where the payment occurred.
:place:latlongThe latlong where the payment occurred.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:bank:statement
-(has)>
econ:acct:paymentThe bank statement includes the payment.
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:acct:receipt
A receipt issued as proof of payment.
The base type for the form can be found at econ:acct:receipt.
- Properties:
name
type
doc
:issuedThe time the receipt was issued.
:purchaseThe purchase that the receipt confirms payment for.
:issuerThe contact information for the entity who issued the receipt.
:recipientThe contact information for the entity who received the receipt.
:currencyThe currency that the receipt uses to specify the price.
:amountThe price that the receipt confirms was paid.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:acquired
Deprecated. Please use econ:purchase -(acquired)> *.
The base type for the form can be found at econ:acquired.
- Properties:
name
type
doc
opts
:purchaseThe purchase event which acquired an item.
Read Only:
True
:itemA reference to the item that was acquired.
Read Only:
True
:item:formThe form of item purchased.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:aba:rtn
An American Bank Association (ABA) routing transit number (RTN).
The base type for the form can be found at econ:bank:aba:rtn.
- Properties:
name
type
doc
:bankThe bank which was issued the ABA RTN.
:bank:nameThe name which is registered for this ABA RTN.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:account
A bank account.
The base type for the form can be found at econ:bank:account.
- Properties:
name
type
doc
:typeThe type of bank account.
:aba:rtnThe ABA routing transit number for the bank which issued the account.
:number regex:[0-9]+The account number.
:ibanThe IBAN for the account.
:issuerThe bank which issued the account.
:issuer:nameThe name of the bank which issued the account.
:currencyThe currency of the account balance.
:balanceThe most recently known bank balance information.
:contactThe primary contact for the bank account.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:account:type:taxonomy
A bank account type taxonomy.
The base type for the form can be found at econ:bank:account:type:taxonomy.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:balance
A balance contained by a bank account at a point in time.
The base type for the form can be found at econ:bank:balance.
- Properties:
name
type
doc
:timeThe time that the account balance was observed.
:amountThe amount of currency available at the time.
:accountThe bank account which contained the balance amount.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:iban
An International Bank Account Number.
The base type for the form can be found at econ:bank:iban.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:statement
A statement of bank account payment activity over a period of time.
The base type for the form can be found at econ:bank:statement.
- Properties:
name
type
doc
:accountThe bank account used to compute the statement.
:periodThe period that the statement includes.
:starting:balanceThe account balance at the beginning of the statement period.
:ending:balanceThe account balance at the end of the statement period.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
econ:bank:statement
-(has)>
econ:acct:paymentThe bank statement includes the payment.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:bank:swift:bic
A Society for Worldwide Interbank Financial Telecommunication (SWIFT) Business Identifier Code (BIC).
The base type for the form can be found at econ:bank:swift:bic.
- Properties:
name
type
doc
:businessThe business which is the registered owner of the SWIFT BIC.
:officeThe branch or office which is specified in the last 3 digits of the SWIFT BIC.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:currency
The name of a system of money in general use.
The base type for the form can be found at econ:currency.
An example of econ:currency:
usd
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:fin:bar
A sample of the open, close, high, low prices of a security in a specific time window.
The base type for the form can be found at econ:fin:bar.
- Properties:
name
type
doc
:securityThe security measured by the bar.
:ivalThe interval of measurement.
:price:openThe opening price of the security.
:price:closeThe closing price of the security.
:price:lowThe low price of the security.
:price:highThe high price of the security.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:fin:exchange
A financial exchange where securities are traded.
The base type for the form can be found at econ:fin:exchange.
- Properties:
name
type
doc
opts
:nameA simple name for the exchange.
Example:
nasdaq
:orgThe organization that operates the exchange.
:currencyThe currency used for all transactions in the exchange.
Example:
usd- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:fin:security
A financial security which is typically traded on an exchange.
The base type for the form can be found at econ:fin:security.
- Properties:
name
type
doc
:exchangeThe exchange on which the security is traded.
:tickerThe identifier for this security within the exchange.
:typeA user defined type such as stock, bond, option, future, or forex.
:priceThe last known/available price of the security.
:timeThe time of the last know price sample.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:fin:tick
A sample of the price of a security at a single moment in time.
The base type for the form can be found at econ:fin:tick.
- Properties:
name
type
doc
:securityThe security measured by the tick.
:timeThe time the price was sampled.
:priceThe price of the security at the time.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:pay:card
A single payment card.
The base type for the form can be found at econ:pay:card.
- Properties:
name
type
doc
:panThe payment card number.
:pan:miiThe payment card MII.
:pan:iinThe payment card IIN.
:nameThe name as it appears on the card.
:exprThe expiration date for the card.
:cvvThe Card Verification Value on the card.
:pinThe Personal Identification Number on the card.
:accountA bank account associated with the payment card.
:contactThe primary contact for the payment card.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:pay:iin
An Issuer Id Number (IIN).
The base type for the form can be found at econ:pay:iin.
- Properties:
name
type
doc
:orgThe issuer organization.
:name lower:TrueThe registered name of the issuer.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:pay:pan
A Primary Account Number (PAN) or card number.
The base type for the form can be found at econ:pay:pan.
- Properties:
name
type
doc
opts
:miiThe Major Industry Identifier (MII) of the PAN.
Read Only:
True
:iinThe Issuer Identification Number (IIN) of the PAN.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:purchase
A purchase event.
The base type for the form can be found at econ:purchase.
- Properties:
name
type
doc
:by:contactThe contact information used to make the purchase.
:from:contactThe contact information used to sell the item.
:timeThe time of the purchase.
:placeThe place where the purchase took place.
:paidSet to True if the purchase has been paid in full.
:paid:timeThe point in time where the purchase was paid in full.
:settledThe point in time where the purchase was settled.
:campaignThe campaign that the purchase was in support of.
:priceThe econ:price of the purchase.
:currencyThe econ:price of the purchase.
:listingThe purchase was made based on the given listing.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
econ:receipt:item
A line item included as part of a purchase.
The base type for the form can be found at econ:receipt:item.
- Properties:
name
type
doc
:purchaseThe purchase that contains this line item.
:count min:1The number of items included in this line item.
:priceThe total cost of this receipt line item.
:productThe product being being purchased in this line item.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
edge:has
A digraph edge which records that N1 has N2.
The base type for the form can be found at edge:has.
- Properties:
name
type
doc
opts
:n1The node definition type for a (form,valu) compound field.
Read Only:
True
:n1:formThe base string type.
Read Only:
True
:n2The node definition type for a (form,valu) compound field.
Read Only:
True
:n2:formThe base string type.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
edge:refs
A digraph edge which records that N1 refers to or contains N2.
The base type for the form can be found at edge:refs.
- Properties:
name
type
doc
opts
:n1The node definition type for a (form,valu) compound field.
Read Only:
True
:n1:formThe base string type.
Read Only:
True
:n2The node definition type for a (form,valu) compound field.
Read Only:
True
:n2:formThe base string type.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
edge:wentto
A digraph edge which records that N1 went to N2 at a specific time.
The base type for the form can be found at edge:wentto.
- Properties:
name
type
doc
opts
:n1The node definition type for a (form,valu) compound field.
Read Only:
True
:n1:formThe base string type.
Read Only:
True
:n2The node definition type for a (form,valu) compound field.
Read Only:
True
:n2:formThe base string type.
Read Only:
True
:timeA date/time value.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
edu:class
An instance of an edu:course taught at a given time.
The base type for the form can be found at edu:class.
- Properties:
name
type
doc
:courseThe course being taught in the class.
:instructorThe primary instructor for the class.
:assistantsAn array of assistant/co-instructor contacts.
:date:firstThe date of the first day of class.
:date:lastThe date of the last day of class.
:isvirtualSet if the class is known to be virtual.
:virtual:urlThe URL a student would use to attend the virtual class.
:virtual:providerContact info for the virtual infrastructure provider.
:placeThe place that the class is held.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
edu:course
A course of study taught by an org.
The base type for the form can be found at edu:course.
- Properties:
name
type
doc
opts
:nameThe name of the course.
Example:
organic chemistry for beginners
:descA brief course description.
:codeThe course catalog number or designator.
Example:
chem101
:institutionThe org or department which teaches the course.
:prereqsThe pre-requisite courses for taking this course.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
entity:name
A name used to refer to an entity.
The base type for the form can be found at entity:name.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
entity:relationship
A directional relationship between two actor entities.
The base type for the form can be found at entity:relationship.
- Properties:
name
type
doc
:typeThe type of relationship.
:periodThe time period when the relationship existed.
:sourceThe source entity in the relationship.
:targetThe target entity in the relationship.
:reporterThe organization reporting on the relationship.
:reporter:nameThe name of the organization reporting on the relationship.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
entity:relationship:type:taxonomy
A hierarchical taxonomy of entity relationship types.
The base type for the form can be found at entity:relationship:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:archive:entry
An archive entry representing a file and metadata within a parent archive file.
The base type for the form can be found at file:archive:entry.
- Properties:
name
type
doc
:parentThe parent archive file.
:fileThe file contained within the archive.
:pathThe file path of the archived file.
:userThe name of the user who owns the archived file.
:addedThe time that the file was added to the archive.
:createdThe created time of the archived file.
:modifiedThe modified time of the archived file.
:commentThe comment field for the file entry within the archive.
:posix:uidThe POSIX UID of the user who owns the archived file.
:posix:gidThe POSIX GID of the group who owns the archived file.
:posix:permsThe POSIX permissions mask of the archived file.
:archived:sizeThe encoded or compressed size of the archived file within the parent.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:attachment
A file attachment.
The base type for the form can be found at file:attachment.
- Properties:
name
type
doc
:nameThe name of the attached file.
:textAny text associated with the file such as alt-text for images.
:fileThe file which was attached.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:base
A file name with no path.
The base type for the form can be found at file:base.
An example of file:base:
woot.exe
- Properties:
name
type
doc
opts
:extThe file extension (if any).
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:bytes
The file bytes type with SHA256 based primary property.
The base type for the form can be found at file:bytes.
- Properties:
name
type
doc
:sizeThe file size in bytes.
:md5The md5 hash of the file.
:sha1The sha1 hash of the file.
:sha256The sha256 hash of the file.
:sha512The sha512 hash of the file.
:ssdeepsThe ssdeep fuzzy hashes of the file.
:nameThe best known base name for the file.
:mimeThe “best” mime type name for the file.
:mime:x509:cnThe Common Name (CN) attribute of the x509 Subject.
:mime:pe:sizeThe size of the executable file according to the PE file header.
:mime:pe:imphashThe PE import hash of the file as calculated by pefile; https://github.com/erocarrera/pefile .
:mime:pe:compiledThe compile time of the file according to the PE header.
:mime:pe:pdbpathThe PDB string according to the PE.
:mime:pe:exports:timeThe export time of the file according to the PE.
:mime:pe:exports:libnameThe export library name according to the PE.
:mime:pe:richhdrThe sha256 hash of the rich header bytes.
:exe:compilerThe software used to compile the file.
:exe:packerThe packer software used to encode the file.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
file:bytes
-(refs)>
it:dev:strThe source file contains the target string.
file:bytes
-(uses)>
math:algorithmThe file uses the algorithm.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
crypto:key
-(decrypts)>
file:bytesThe key is used to decrypt the file.
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:filepath
The fused knowledge of the association of a file:bytes node and a file:path.
The base type for the form can be found at file:filepath.
- Properties:
name
type
doc
opts
:fileThe file seen at a path.
Read Only:
True
:pathThe path a file was seen at.
Read Only:
True
:path:dirThe parent directory.
Read Only:
True
:path:baseThe name of the file.
Read Only:
True
:path:base:extThe extension of the file name.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:ismime
Records one, of potentially multiple, mime types for a given file.
The base type for the form can be found at file:ismime.
- Properties:
name
type
doc
opts
:fileThe file node that is an instance of the named mime type.
Read Only:
True
:mimeThe mime type of the file.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime
A file mime name string.
The base type for the form can be found at file:mime.
An example of file:mime:
text/plain
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:gif
The GUID of a set of mime metadata for a .gif file.
The base type for the form can be found at file:mime:gif.
- Properties:
name
type
doc
:descMIME specific description field extracted from metadata.
:commentMIME specific comment field extracted from metadata.
:createdMIME specific creation timestamp extracted from metadata.
:imageidMIME specific unique identifier extracted from metadata.
:authorMIME specific contact information extracted from metadata.
:latlongMIME specific lat/long information extracted from metadata.
:altitudeMIME specific altitude information extracted from metadata.
:textThe text contained within the image.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:jpg
The GUID of a set of mime metadata for a .jpg file.
The base type for the form can be found at file:mime:jpg.
- Properties:
name
type
doc
:descMIME specific description field extracted from metadata.
:commentMIME specific comment field extracted from metadata.
:createdMIME specific creation timestamp extracted from metadata.
:imageidMIME specific unique identifier extracted from metadata.
:authorMIME specific contact information extracted from metadata.
:latlongMIME specific lat/long information extracted from metadata.
:altitudeMIME specific altitude information extracted from metadata.
:textThe text contained within the image.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:lnk
The GUID of the metadata pulled from a Windows shortcut or LNK file.
The base type for the form can be found at file:mime:lnk.
- Properties:
name
type
doc
opts
:flagsThe flags specified by the LNK header that control the structure of the LNK file.
:entry:primaryThe primary file path contained within the FileEntry structure of the LNK file.
:entry:secondaryThe secondary file path contained within the FileEntry structure of the LNK file.
:entry:extendedThe extended file path contained within the extended FileEntry structure of the LNK file.
:entry:localizedThe localized file path reconstructed from references within the extended FileEntry structure of the LNK file.
:entry:iconThe icon file path contained within the StringData structure of the LNK file.
:environment:pathThe target file path contained within the EnvironmentVariableDataBlock structure of the LNK file.
:environment:iconThe icon file path contained within the IconEnvironmentDataBlock structure of the LNK file.
:iconindexA resource index for an icon within an icon location.
:workingThe working directory used when activating the link target.
:relative strip:TrueThe relative target path string contained within the StringData structure of the LNK file.
:argumentsThe command line arguments passed to the target file when the LNK file is activated.
:descThe description of the LNK file contained within the StringData section of the LNK file.
Display:
{'hint': 'text'}
:target:attrsThe attributes of the target file according to the LNK header.
:target:sizeThe size of the target file according to the LNK header. The LNK format specifies that this is only the lower 32 bits of the target file size.
:target:createdThe creation time of the target file according to the LNK header.
:target:accessedThe access time of the target file according to the LNK header.
:target:writtenThe write time of the target file according to the LNK header.
:driveserialThe drive serial number of the volume the link target is stored on.
:machineidThe NetBIOS name of the machine where the link target was last located.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:macho:loadcmd
A generic load command pulled from the Mach-O headers.
The base type for the form can be found at file:mime:macho:loadcmd.
- Properties:
name
type
doc
:fileThe Mach-O file containing the load command.
:type enums:((1, 'segment'), (2, 'symbol table'), (3, 'gdb symbol table'), (4, 'thread'), (5, 'unix thread'), (6, 'fixed VM shared library'), (7, 'fixed VM shared library identification'), (8, 'object identification'), (9, 'fixed VM file inclusion'), (10, 'prepage'), (11, 'dynamic link-edit symbol table'), (12, 'load dynamically linked shared library'), (13, 'dynamically linked shared library identifier'), (14, 'load dynamic linker'), (15, 'dynamic linker identification'), (16, 'prebound dynamically linked shared library'), (17, 'image routines'), (18, 'sub framework'), (19, 'sub umbrella'), (20, 'sub client'), (21, 'sub library'), (22, 'two level namespace lookup hints'), (23, 'prebind checksum'), (24, 'weak import dynamically linked shared library'), (25, '64bit segment'), (26, '64bit image routines'), (27, 'uuid'), (28, 'runpath additions'), (29, 'code signature'), (30, 'split segment info'), (31, 'load and re-export dynamic library'), (32, 'delay load of dynamic library'), (33, 'encrypted segment information'), (34, 'compressed dynamic library information'), (35, 'load upward dylib'), (36, 'minimum osx version'), (37, 'minimum ios version'), (38, 'compressed table of function start addresses'), (39, 'environment variable string for dynamic library'), (40, 'unix thread replacement'), (41, 'table of non-instructions in __text'), (42, 'source version used to build binary'), (43, 'Code signing DRs copied from linked dynamic libraries'))The type of the load command.
:sizeThe size of the load command structure in bytes.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:macho:section
A section inside a Mach-O binary denoting a named region of bytes inside a segment.
The base type for the form can be found at file:mime:macho:section.
- Properties:
name
type
doc
:segmentThe Mach-O segment that contains this section.
:nameName of the section.
:sizeSize of the section in bytes.
:type enums:((0, 'regular'), (1, 'zero fill on demand'), (2, 'only literal C strings'), (3, 'only 4 byte literals'), (4, 'only 8 byte literals'), (5, 'only pointers to literals'), (6, 'only non-lazy symbol pointers'), (7, 'only lazy symbol pointers'), (8, 'only symbol stubs'), (9, 'only function pointers for init'), (10, 'only function pointers for fini'), (11, 'contains symbols to be coalesced'), (12, 'zero fill on deman (greater than 4gb)'), (13, 'only pairs of function pointers for interposing'), (14, 'only 16 byte literals'), (15, 'dtrace object format'), (16, 'only lazy symbols pointers to lazy dynamic libraries'))The type of the section.
:sha256The sha256 hash of the bytes of the Mach-O section.
:offsetThe file offset to the beginning of the section.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:macho:segment
A named region of bytes inside a Mach-O binary.
The base type for the form can be found at file:mime:macho:segment.
- Properties:
name
type
doc
:nameThe name of the Mach-O segment.
:memsizeThe size of the segment in bytes, when resident in memory, according to the load command structure.
:disksizeThe size of the segment in bytes, when on disk, according to the load command structure.
:sha256The sha256 hash of the bytes of the segment.
:offsetThe file offset to the beginning of the segment.
:fileThe Mach-O file containing the load command.
:type enums:((1, 'segment'), (2, 'symbol table'), (3, 'gdb symbol table'), (4, 'thread'), (5, 'unix thread'), (6, 'fixed VM shared library'), (7, 'fixed VM shared library identification'), (8, 'object identification'), (9, 'fixed VM file inclusion'), (10, 'prepage'), (11, 'dynamic link-edit symbol table'), (12, 'load dynamically linked shared library'), (13, 'dynamically linked shared library identifier'), (14, 'load dynamic linker'), (15, 'dynamic linker identification'), (16, 'prebound dynamically linked shared library'), (17, 'image routines'), (18, 'sub framework'), (19, 'sub umbrella'), (20, 'sub client'), (21, 'sub library'), (22, 'two level namespace lookup hints'), (23, 'prebind checksum'), (24, 'weak import dynamically linked shared library'), (25, '64bit segment'), (26, '64bit image routines'), (27, 'uuid'), (28, 'runpath additions'), (29, 'code signature'), (30, 'split segment info'), (31, 'load and re-export dynamic library'), (32, 'delay load of dynamic library'), (33, 'encrypted segment information'), (34, 'compressed dynamic library information'), (35, 'load upward dylib'), (36, 'minimum osx version'), (37, 'minimum ios version'), (38, 'compressed table of function start addresses'), (39, 'environment variable string for dynamic library'), (40, 'unix thread replacement'), (41, 'table of non-instructions in __text'), (42, 'source version used to build binary'), (43, 'Code signing DRs copied from linked dynamic libraries'))The type of the load command.
:sizeThe size of the load command structure in bytes.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:macho:uuid
A specific load command denoting a UUID used to uniquely identify the Mach-O binary.
The base type for the form can be found at file:mime:macho:uuid.
- Properties:
name
type
doc
:uuidThe UUID of the Mach-O application (as defined in an LC_UUID load command).
:fileThe Mach-O file containing the load command.
:type enums:((1, 'segment'), (2, 'symbol table'), (3, 'gdb symbol table'), (4, 'thread'), (5, 'unix thread'), (6, 'fixed VM shared library'), (7, 'fixed VM shared library identification'), (8, 'object identification'), (9, 'fixed VM file inclusion'), (10, 'prepage'), (11, 'dynamic link-edit symbol table'), (12, 'load dynamically linked shared library'), (13, 'dynamically linked shared library identifier'), (14, 'load dynamic linker'), (15, 'dynamic linker identification'), (16, 'prebound dynamically linked shared library'), (17, 'image routines'), (18, 'sub framework'), (19, 'sub umbrella'), (20, 'sub client'), (21, 'sub library'), (22, 'two level namespace lookup hints'), (23, 'prebind checksum'), (24, 'weak import dynamically linked shared library'), (25, '64bit segment'), (26, '64bit image routines'), (27, 'uuid'), (28, 'runpath additions'), (29, 'code signature'), (30, 'split segment info'), (31, 'load and re-export dynamic library'), (32, 'delay load of dynamic library'), (33, 'encrypted segment information'), (34, 'compressed dynamic library information'), (35, 'load upward dylib'), (36, 'minimum osx version'), (37, 'minimum ios version'), (38, 'compressed table of function start addresses'), (39, 'environment variable string for dynamic library'), (40, 'unix thread replacement'), (41, 'table of non-instructions in __text'), (42, 'source version used to build binary'), (43, 'Code signing DRs copied from linked dynamic libraries'))The type of the load command.
:sizeThe size of the load command structure in bytes.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:macho:version
A specific load command used to denote the version of the source used to build the Mach-O binary.
The base type for the form can be found at file:mime:macho:version.
- Properties:
name
type
doc
:versionThe version of the Mach-O file encoded in an LC_VERSION load command.
:fileThe Mach-O file containing the load command.
:type enums:((1, 'segment'), (2, 'symbol table'), (3, 'gdb symbol table'), (4, 'thread'), (5, 'unix thread'), (6, 'fixed VM shared library'), (7, 'fixed VM shared library identification'), (8, 'object identification'), (9, 'fixed VM file inclusion'), (10, 'prepage'), (11, 'dynamic link-edit symbol table'), (12, 'load dynamically linked shared library'), (13, 'dynamically linked shared library identifier'), (14, 'load dynamic linker'), (15, 'dynamic linker identification'), (16, 'prebound dynamically linked shared library'), (17, 'image routines'), (18, 'sub framework'), (19, 'sub umbrella'), (20, 'sub client'), (21, 'sub library'), (22, 'two level namespace lookup hints'), (23, 'prebind checksum'), (24, 'weak import dynamically linked shared library'), (25, '64bit segment'), (26, '64bit image routines'), (27, 'uuid'), (28, 'runpath additions'), (29, 'code signature'), (30, 'split segment info'), (31, 'load and re-export dynamic library'), (32, 'delay load of dynamic library'), (33, 'encrypted segment information'), (34, 'compressed dynamic library information'), (35, 'load upward dylib'), (36, 'minimum osx version'), (37, 'minimum ios version'), (38, 'compressed table of function start addresses'), (39, 'environment variable string for dynamic library'), (40, 'unix thread replacement'), (41, 'table of non-instructions in __text'), (42, 'source version used to build binary'), (43, 'Code signing DRs copied from linked dynamic libraries'))The type of the load command.
:sizeThe size of the load command structure in bytes.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:msdoc
The GUID of a set of mime metadata for a Microsoft Word file.
The base type for the form can be found at file:mime:msdoc.
- Properties:
name
type
doc
:titleThe title extracted from Microsoft Office metadata.
:authorThe author extracted from Microsoft Office metadata.
:subjectThe subject extracted from Microsoft Office metadata.
:applicationThe creating_application extracted from Microsoft Office metadata.
:createdThe create_time extracted from Microsoft Office metadata.
:lastsavedThe last_saved_time extracted from Microsoft Office metadata.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:msppt
The GUID of a set of mime metadata for a Microsoft Powerpoint file.
The base type for the form can be found at file:mime:msppt.
- Properties:
name
type
doc
:titleThe title extracted from Microsoft Office metadata.
:authorThe author extracted from Microsoft Office metadata.
:subjectThe subject extracted from Microsoft Office metadata.
:applicationThe creating_application extracted from Microsoft Office metadata.
:createdThe create_time extracted from Microsoft Office metadata.
:lastsavedThe last_saved_time extracted from Microsoft Office metadata.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:msxls
The GUID of a set of mime metadata for a Microsoft Excel file.
The base type for the form can be found at file:mime:msxls.
- Properties:
name
type
doc
:titleThe title extracted from Microsoft Office metadata.
:authorThe author extracted from Microsoft Office metadata.
:subjectThe subject extracted from Microsoft Office metadata.
:applicationThe creating_application extracted from Microsoft Office metadata.
:createdThe create_time extracted from Microsoft Office metadata.
:lastsavedThe last_saved_time extracted from Microsoft Office metadata.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:pdf
Metadata extracted from a Portable Document Format (PDF) file.
The base type for the form can be found at file:mime:pdf.
- Properties:
name
type
doc
:id strip:TrueThe “DocumentID” field extracted from PDF metadata.
:titleThe “Title” field extracted from PDF metadata.
:author:nameThe “Author” field extracted from PDF metadata.
:language:nameThe “Language” field extracted from PDF metadata.
:createdThe “CreatedDate” field extracted from PDF metadata.
:updatedThe “ModifyDate” field extracted from PDF metadata.
:producer:nameThe “Producer” field extracted from PDF metadata.
:tool:nameThe “CreatorTool” field extracted from PDF metadata.
:subjectThe “Subject” field extracted from PDF metadata.
:keywordsThe “Keywords” field extracted from PDF metadata.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:pe:export
The fused knowledge of a file:bytes node containing a pe named export.
The base type for the form can be found at file:mime:pe:export.
- Properties:
name
type
doc
opts
:fileThe file containing the export.
Read Only:
True
:nameThe name of the export in the file.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:pe:resource
The fused knowledge of a file:bytes node containing a pe resource.
The base type for the form can be found at file:mime:pe:resource.
- Properties:
name
type
doc
opts
:fileThe file containing the resource.
Read Only:
True
:typeThe typecode for the resource.
Read Only:
True
:langidThe language code for the resource.
Read Only:
True
:resourceThe sha256 hash of the resource bytes.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:pe:section
The fused knowledge a file:bytes node containing a pe section.
The base type for the form can be found at file:mime:pe:section.
- Properties:
name
type
doc
opts
:fileThe file containing the section.
Read Only:
True
:nameThe textual name of the section.
Read Only:
True
:sha256The sha256 hash of the section. Relocations must be zeroed before hashing.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:pe:vsvers:info
knowledge of a file:bytes node containing vsvers info.
The base type for the form can be found at file:mime:pe:vsvers:info.
- Properties:
name
type
doc
opts
:fileThe file containing the vsversion keyval pair.
Read Only:
True
:keyvalThe vsversion info keyval in this file:bytes node.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:pe:vsvers:keyval
A key value pair found in a PE vsversion info structure.
The base type for the form can be found at file:mime:pe:vsvers:keyval.
- Properties:
name
type
doc
opts
:nameThe key for the vsversion keyval pair.
Read Only:
True
:valueThe value for the vsversion keyval pair.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:png
The GUID of a set of mime metadata for a .png file.
The base type for the form can be found at file:mime:png.
- Properties:
name
type
doc
:descMIME specific description field extracted from metadata.
:commentMIME specific comment field extracted from metadata.
:createdMIME specific creation timestamp extracted from metadata.
:imageidMIME specific unique identifier extracted from metadata.
:authorMIME specific contact information extracted from metadata.
:latlongMIME specific lat/long information extracted from metadata.
:altitudeMIME specific altitude information extracted from metadata.
:textThe text contained within the image.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:rtf
The GUID of a set of mime metadata for a .rtf file.
The base type for the form can be found at file:mime:rtf.
- Properties:
name
type
doc
:guidThe parsed GUID embedded in the .rtf file.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:mime:tif
The GUID of a set of mime metadata for a .tif file.
The base type for the form can be found at file:mime:tif.
- Properties:
name
type
doc
:descMIME specific description field extracted from metadata.
:commentMIME specific comment field extracted from metadata.
:createdMIME specific creation timestamp extracted from metadata.
:imageidMIME specific unique identifier extracted from metadata.
:authorMIME specific contact information extracted from metadata.
:latlongMIME specific lat/long information extracted from metadata.
:altitudeMIME specific altitude information extracted from metadata.
:textThe text contained within the image.
:fileThe file that the mime info was parsed from.
:file:offsThe optional offset where the mime info was parsed from.
:file:dataA mime specific arbitrary data structure for non-indexed data.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:path
A normalized file path.
The base type for the form can be found at file:path.
An example of file:path:
c:/windows/system32/calc.exe
- Properties:
name
type
doc
opts
:dirThe parent directory.
Read Only:
True
:baseThe file base name.
Read Only:
True
:base:extThe file extension.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:string
Deprecated. Please use the edge -(refs)> it:dev:str.
The base type for the form can be found at file:string.
- Properties:
name
type
doc
opts
:fileThe file containing the string.
Read Only:
True
:stringThe string contained in this file:bytes node.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
file:subfile
A parent file that fully contains the specified child file.
The base type for the form can be found at file:subfile.
- Properties:
name
type
doc
opts
:parentThe parent file containing the child file.
Read Only:
True
:childThe child file contained in the parent file.
Read Only:
True
:nameDeprecated, please use the :path property.
Deprecated:
True
:pathThe path that the parent uses to refer to the child file.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
geo:name
An unstructured place name or address.
The base type for the form can be found at geo:name.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
geo:nloc
Records a node latitude/longitude in space-time.
The base type for the form can be found at geo:nloc.
- Properties:
name
type
doc
opts
:ndefThe node with location in geospace and time.
Read Only:
True
:ndef:formThe form of node referenced by the ndef.
Read Only:
True
:latlongThe latitude/longitude the node was observed.
Read Only:
True
:timeThe time the node was observed at location.
Read Only:
True
:placeThe place corresponding to the latlong property.
:locThe geo-political location string for the node.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
geo:place
A GUID for a geographic place.
The base type for the form can be found at geo:place.
- Properties:
name
type
doc
opts
:id strip:TrueA type specific identifier such as an airport ID.
:nameThe name of the place.
alts:
('names',)
:typeThe type of place.
:namesAn array of alternative place names.
:parentDeprecated. Please use a -(contains)> edge.
Deprecated:
True
:descA long form description of the place.
:locThe geo-political location string for the node.
:addressThe street/mailing address for the place.
:geojsonA GeoJSON representation of the place.
:latlongThe lat/long position for the place.
:bboxA bounding box which encompasses the place.
:radiusAn approximate radius to use for bounding box calculation.
:photoThe image file to use as the primary image of the place.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
geo:place
-(contains)>
geo:placeThe source place completely contains the target place.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
geo:place
-(contains)>
geo:placeNone
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
geo:place:taxonomy
A taxonomy of place types.
The base type for the form can be found at geo:place:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
geo:telem
The geospatial position and physical characteristics of a node at a given time.
The base type for the form can be found at geo:telem.
- Properties:
name
type
doc
opts
:timeThe time that the telemetry measurements were taken.
:descA description of the telemetry sample.
:latlongDeprecated. Please use :place:latlong.
Deprecated:
True
:accuracyDeprecated. Please use :place:latlong:accuracy.
Deprecated:
True
:nodeThe node that was observed at the associated time and place.
:phys:massThe mass of the object.
:phys:volumeThe cubed volume of the object.
:phys:lengthThe length of the object.
:phys:widthThe width of the object.
:phys:heightThe height of the object.
:placeThe place where the object was located.
:place:locThe geopolitical location of the object.
:place:nameThe name of the place where the object was located.
:place:addressThe postal address of the place where the object was located.
:place:latlongThe latlong where the object was located.
:place:latlong:accuracyThe accuracy of the latlong where the object was located.
:place:countryThe country where the object was located.
:place:country:codeThe country code where the object was located.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
gov:cn:icp
A Chinese Internet Content Provider ID.
The base type for the form can be found at gov:cn:icp.
- Properties:
name
type
doc
:orgThe org with the Internet Content Provider ID.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
gov:cn:mucd
A Chinese PLA MUCD.
The base type for the form can be found at gov:cn:mucd.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
gov:us:cage
A Commercial and Government Entity (CAGE) code.
The base type for the form can be found at gov:us:cage.
- Properties:
name
type
doc
:name0The name of the organization.
:name1 lower:TrueName Part 1.
:street lower:TrueThe base string type.
:city lower:TrueThe base string type.
:state lower:TrueThe base string type.
:zipA US Postal Zip Code.
:ccThe 2 digit ISO 3166 country code.
:country lower:TrueThe base string type.
:phone0A phone number.
:phone1A phone number.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
gov:us:ssn
A US Social Security Number (SSN).
The base type for the form can be found at gov:us:ssn.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
gov:us:zip
A US Postal Zip Code.
The base type for the form can be found at gov:us:zip.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
graph:cluster
A generic node, used in conjunction with Edge types, to cluster arbitrary nodes to a single node in the model.
The base type for the form can be found at graph:cluster.
- Properties:
name
type
doc
:name lower:TrueA human friendly name for the cluster.
:desc lower:TrueA human friendly long form description for the cluster.
:type lower:TrueAn optional type field used to group clusters.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
graph:edge
A generic digraph edge to show relationships outside the model.
The base type for the form can be found at graph:edge.
- Properties:
name
type
doc
opts
:n1The node definition type for a (form,valu) compound field.
Read Only:
True
:n1:formThe base string type.
Read Only:
True
:n2The node definition type for a (form,valu) compound field.
Read Only:
True
:n2:formThe base string type.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
graph:event
A generic event node to represent events outside the model.
The base type for the form can be found at graph:event.
- Properties:
name
type
doc
:timeThe time of the event.
:typeA arbitrary type string for the event.
:nameA name for the event.
:dataArbitrary non-indexed msgpack data attached to the event.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
graph:node
A generic node used to represent objects outside the model.
The base type for the form can be found at graph:node.
- Properties:
name
type
doc
:typeThe type name for the non-model node.
:nameA human readable name for this record.
:dataArbitrary non-indexed msgpack data attached to the node.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
graph:timeedge
A generic digraph time edge to show relationships outside the model.
The base type for the form can be found at graph:timeedge.
- Properties:
name
type
doc
opts
:timeA date/time value.
Read Only:
True
:n1The node definition type for a (form,valu) compound field.
Read Only:
True
:n1:formThe base string type.
Read Only:
True
:n2The node definition type for a (form,valu) compound field.
Read Only:
True
:n2:formThe base string type.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
hash:md5
A hex encoded MD5 hash.
The base type for the form can be found at hash:md5.
An example of hash:md5:
d41d8cd98f00b204e9800998ecf8427e
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
hash:sha1
A hex encoded SHA1 hash.
The base type for the form can be found at hash:sha1.
An example of hash:sha1:
da39a3ee5e6b4b0d3255bfef95601890afd80709
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
hash:sha256
A hex encoded SHA256 hash.
The base type for the form can be found at hash:sha256.
An example of hash:sha256:
ad9f4fe922b61e674a09530831759843b1880381de686a43460a76864ca0340c
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
hash:sha384
A hex encoded SHA384 hash.
The base type for the form can be found at hash:sha384.
An example of hash:sha384:
d425f1394e418ce01ed1579069a8bfaa1da8f32cf823982113ccbef531fa36bda9987f389c5af05b5e28035242efab6c
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
hash:sha512
A hex encoded SHA512 hash.
The base type for the form can be found at hash:sha512.
An example of hash:sha512:
ca74fe2ff2d03b29339ad7d08ba21d192077fece1715291c7b43c20c9136cd132788239189f3441a87eb23ce2660aa243f334295902c904b5520f6e80ab91f11
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
hash:ssdeep
A fuzzy hash of a file in ssdeep format.
The base type for the form can be found at hash:ssdeep.
An example of hash:ssdeep:
98304:PYZdVAWWlLuKn4messQdqSqkxbpYlXLL:iglLlsHSfxVYVL
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:asn
An Autonomous System Number (ASN).
The base type for the form can be found at inet:asn.
- Properties:
name
type
doc
:name lower:TrueThe name of the organization currently responsible for the ASN.
:ownerThe guid of the organization currently responsible for the ASN.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:asnet4
An Autonomous System Number (ASN) and its associated IPv4 address range.
The base type for the form can be found at inet:asnet4.
An example of inet:asnet4:
(54959, (1.2.3.4, 1.2.3.20))
- Properties:
name
type
doc
opts
:asnThe Autonomous System Number (ASN) of the netblock.
Read Only:
True
:net4The IPv4 address range assigned to the ASN.
Read Only:
True
:net4:minThe first IPv4 in the range assigned to the ASN.
Read Only:
True
:net4:maxThe last IPv4 in the range assigned to the ASN.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:asnet6
An Autonomous System Number (ASN) and its associated IPv6 address range.
The base type for the form can be found at inet:asnet6.
An example of inet:asnet6:
(54959, (ff::00, ff::02))
- Properties:
name
type
doc
opts
:asnThe Autonomous System Number (ASN) of the netblock.
Read Only:
True
:net6The IPv6 address range assigned to the ASN.
Read Only:
True
:net6:minThe first IPv6 in the range assigned to the ASN.
Read Only:
True
:net6:maxThe last IPv6 in the range assigned to the ASN.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:cidr4
An IPv4 address block in Classless Inter-Domain Routing (CIDR) notation.
The base type for the form can be found at inet:cidr4.
An example of inet:cidr4:
1.2.3.0/24
- Properties:
name
type
doc
opts
:broadcastThe broadcast IP address from the CIDR notation.
Read Only:
True
:maskThe mask from the CIDR notation.
Read Only:
True
:networkThe network IP address from the CIDR notation.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:cidr6
An IPv6 address block in Classless Inter-Domain Routing (CIDR) notation.
The base type for the form can be found at inet:cidr6.
An example of inet:cidr6:
2001:db8::/101
- Properties:
name
type
doc
opts
:broadcastThe broadcast IP address from the CIDR notation.
Read Only:
True
:maskThe mask from the CIDR notation.
Read Only:
True
:networkThe network IP address from the CIDR notation.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:client
A network client address.
The base type for the form can be found at inet:client.
An example of inet:client:
tcp://1.2.3.4:80
- Properties:
name
type
doc
opts
:proto lower:TrueThe network protocol of the client.
Read Only:
True
:ipv4The IPv4 of the client.
Read Only:
True
:ipv6The IPv6 of the client.
Read Only:
True
:hostThe it:host node for the client.
Read Only:
True
:portThe client tcp/udp port.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:a
The result of a DNS A record lookup.
The base type for the form can be found at inet:dns:a.
An example of inet:dns:a:
(vertex.link,1.2.3.4)
- Properties:
name
type
doc
opts
:fqdnThe domain queried for its DNS A record.
Read Only:
True
:ipv4The IPv4 address returned in the A record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:aaaa
The result of a DNS AAAA record lookup.
The base type for the form can be found at inet:dns:aaaa.
An example of inet:dns:aaaa:
(vertex.link,2607:f8b0:4004:809::200e)
- Properties:
name
type
doc
opts
:fqdnThe domain queried for its DNS AAAA record.
Read Only:
True
:ipv6The IPv6 address returned in the AAAA record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:answer
A single answer from within a DNS reply.
The base type for the form can be found at inet:dns:answer.
- Properties:
name
type
doc
:ttlThe base 64 bit signed integer type.
:requestA single instance of a DNS resolver request and optional reply info.
:aThe DNS A record returned by the lookup.
:nsThe DNS NS record returned by the lookup.
:revThe DNS PTR record returned by the lookup.
:aaaaThe DNS AAAA record returned by the lookup.
:rev6The DNS PTR record returned by the lookup of an IPv6 address.
:cnameThe DNS CNAME record returned by the lookup.
:mxThe DNS MX record returned by the lookup.
:mx:priorityThe DNS MX record priority.
:soaThe domain queried for its SOA record.
:txtThe DNS TXT record returned by the lookup.
:timeThe time that the DNS response was transmitted.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:cname
The result of a DNS CNAME record lookup.
The base type for the form can be found at inet:dns:cname.
An example of inet:dns:cname:
(foo.vertex.link,vertex.link)
- Properties:
name
type
doc
opts
:fqdnThe domain queried for its CNAME record.
Read Only:
True
:cnameThe domain returned in the CNAME record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:dynreg
A dynamic DNS registration.
The base type for the form can be found at inet:dns:dynreg.
- Properties:
name
type
doc
:fqdnThe FQDN registered within a dynamic DNS provider.
:providerThe organization which provides the dynamic DNS FQDN.
:provider:nameThe name of the organization which provides the dynamic DNS FQDN.
:provider:fqdnThe FQDN of the organization which provides the dynamic DNS FQDN.
:contactThe contact information of the registrant.
:createdThe time that the dynamic DNS registration was first created.
:clientThe network client address used to register the dynamic FQDN.
:client:ipv4The client IPv4 address used to register the dynamic FQDN.
:client:ipv6The client IPv6 address used to register the dynamic FQDN.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:mx
The result of a DNS MX record lookup.
The base type for the form can be found at inet:dns:mx.
An example of inet:dns:mx:
(vertex.link,mail.vertex.link)
- Properties:
name
type
doc
opts
:fqdnThe domain queried for its MX record.
Read Only:
True
:mxThe domain returned in the MX record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:ns
The result of a DNS NS record lookup.
The base type for the form can be found at inet:dns:ns.
An example of inet:dns:ns:
(vertex.link,ns.dnshost.com)
- Properties:
name
type
doc
opts
:zoneThe domain queried for its DNS NS record.
Read Only:
True
:nsThe domain returned in the NS record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:query
A DNS query unique to a given client.
The base type for the form can be found at inet:dns:query.
An example of inet:dns:query:
(1.2.3.4, woot.com, 1)
- Properties:
name
type
doc
opts
:clientA network client address.
Read Only:
True
:nameA DNS query name string. Likely an FQDN but not always.
Read Only:
True
:name:ipv4An IPv4 address.
:name:ipv6An IPv6 address.
:name:fqdnA Fully Qualified Domain Name (FQDN).
:typeThe base 64 bit signed integer type.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:request
A single instance of a DNS resolver request and optional reply info.
The base type for the form can be found at inet:dns:request.
- Properties:
name
type
doc
:timeA date/time value.
:queryA DNS query unique to a given client.
:query:nameA DNS query name string. Likely an FQDN but not always.
:query:name:ipv4An IPv4 address.
:query:name:ipv6An IPv6 address.
:query:name:fqdnA Fully Qualified Domain Name (FQDN).
:query:typeThe base 64 bit signed integer type.
:serverA network server address.
:reply:code enums:((0, 'NOERROR'), (1, 'FORMERR'), (2, 'SERVFAIL'), (3, 'NXDOMAIN'), (4, 'NOTIMP'), (5, 'REFUSED'), (6, 'YXDOMAIN'), (7, 'YXRRSET'), (8, 'NXRRSET'), (9, 'NOTAUTH'), (10, 'NOTZONE'), (11, 'DSOTYPENI'), (16, 'BADSIG'), (17, 'BADKEY'), (18, 'BADTIME'), (19, 'BADMODE'), (20, 'BADNAME'), (21, 'BADALG'), (22, 'BADTRUNC'), (23, 'BADCOOKIE'))enums:strict:FalseThe DNS server response code.
:exeThe file containing the code that attempted the DNS lookup.
:procThe process that attempted the DNS lookup.
:hostThe host that attempted the DNS lookup.
:sandbox:fileThe initial sample given to a sandbox environment to analyze.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:rev
The transformed result of a DNS PTR record lookup.
The base type for the form can be found at inet:dns:rev.
An example of inet:dns:rev:
(1.2.3.4,vertex.link)
- Properties:
name
type
doc
opts
:ipv4The IPv4 address queried for its DNS PTR record.
Read Only:
True
:fqdnThe domain returned in the PTR record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:rev6
The transformed result of a DNS PTR record for an IPv6 address.
The base type for the form can be found at inet:dns:rev6.
An example of inet:dns:rev6:
(2607:f8b0:4004:809::200e,vertex.link)
- Properties:
name
type
doc
opts
:ipv6The IPv6 address queried for its DNS PTR record.
Read Only:
True
:fqdnThe domain returned in the PTR record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:soa
The result of a DNS SOA record lookup.
The base type for the form can be found at inet:dns:soa.
- Properties:
name
type
doc
:fqdnThe domain queried for its SOA record.
:nsThe domain (MNAME) returned in the SOA record.
The email address (RNAME) returned in the SOA record.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:txt
The result of a DNS TXT record lookup.
The base type for the form can be found at inet:dns:txt.
An example of inet:dns:txt:
(hehe.vertex.link,"fancy TXT record")
- Properties:
name
type
doc
opts
:fqdnThe domain queried for its TXT record.
Read Only:
True
:txtThe string returned in the TXT record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:wild:a
A DNS A wild card record and the IPv4 it resolves to.
The base type for the form can be found at inet:dns:wild:a.
- Properties:
name
type
doc
opts
:fqdnThe domain containing a wild card record.
Read Only:
True
:ipv4The IPv4 address returned by wild card resolutions.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:dns:wild:aaaa
A DNS AAAA wild card record and the IPv6 it resolves to.
The base type for the form can be found at inet:dns:wild:aaaa.
- Properties:
name
type
doc
opts
:fqdnThe domain containing a wild card record.
Read Only:
True
:ipv6The IPv6 address returned by wild card resolutions.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:download
An instance of a file downloaded from a server.
The base type for the form can be found at inet:download.
- Properties:
name
type
doc
:timeThe time the file was downloaded.
:fqdnThe FQDN used to resolve the server.
:fileThe file that was downloaded.
:serverThe inet:addr of the server.
:server:hostThe it:host node for the server.
:server:ipv4The IPv4 of the server.
:server:ipv6The IPv6 of the server.
:server:portThe server tcp/udp port.
:server:proto lower:TrueThe server network layer protocol.
:clientThe inet:addr of the client.
:client:hostThe it:host node for the client.
:client:ipv4The IPv4 of the client.
:client:ipv6The IPv6 of the client.
:client:portThe client tcp/udp port.
:client:proto lower:TrueThe client network layer protocol.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:egress
A host using a specific network egress client address.
The base type for the form can be found at inet:egress.
- Properties:
name
type
doc
:hostThe host that used the network egress.
:host:ifaceThe interface which the host used to connect out via the egress.
:accountThe service account which used the client address to egress.
:clientThe client address the host used as a network egress.
:client:ipv4The client IPv4 address the host used as a network egress.
:client:ipv6The client IPv6 address the host used as a network egress.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:email
An e-mail address.
The base type for the form can be found at inet:email.
- Properties:
name
type
doc
opts
:userThe username of the email address.
Read Only:
True
:fqdnThe domain of the email address.
Read Only:
True
:plusThe optional email address “tag”.
Read Only:
True
:baseThe base email address which is populated if the email address contains a user with a +<tag>.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:email:header
A unique email message header.
The base type for the form can be found at inet:email:header.
- Properties:
name
type
doc
opts
:nameThe name of the email header.
Read Only:
True
:valueThe value of the email header.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:email:message
An individual email message delivered to an inbox.
The base type for the form can be found at inet:email:message.
- Properties:
name
type
doc
opts
:id strip:TrueThe ID parsed from the “message-id” header.
:toThe email address of the recipient.
:fromThe email address of the sender.
:replytoThe email address parsed from the “reply-to” header.
:ccEmail addresses parsed from the “cc” header.
:subjectThe email message subject parsed from the “subject” header.
:bodyThe body of the email message.
Display:
{'hint': 'text'}
:dateThe time the email message was delivered.
:bytesThe file bytes which contain the email message.
:headers type: inet:email:headerAn array of email headers from the message.
:received:from:ipv4The sending SMTP server IPv4, potentially from the Received: header.
:received:from:ipv6The sending SMTP server IPv6, potentially from the Received: header.
:received:from:fqdnThe sending server FQDN, potentially from the Received: header.
:flowThe inet:flow which delivered the message.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:email:message:attachment
A file which was attached to an email message.
The base type for the form can be found at inet:email:message:attachment.
- Properties:
name
type
doc
opts
:messageThe message containing the attached file.
Read Only:
True
:fileThe attached file.
Read Only:
True
:nameThe name of the attached file.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:email:message:link
A url/link embedded in an email message.
The base type for the form can be found at inet:email:message:link.
- Properties:
name
type
doc
opts
:messageThe message containing the embedded link.
Read Only:
True
:urlThe url contained within the email message.
Read Only:
True
:textThe displayed hyperlink text if it was not the raw URL.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:flow
An individual network connection between a given source and destination.
The base type for the form can be found at inet:flow.
- Properties:
name
type
doc
opts
:timeThe time the network connection was initiated.
:durationThe duration of the flow in seconds.
:fromThe ingest source file/iden. Used for reparsing.
:dstThe destination address / port for a connection.
:dst:ipv4The destination IPv4 address.
:dst:ipv6The destination IPv6 address.
:dst:portThe destination port.
:dst:proto lower:TrueThe destination protocol.
:dst:hostThe guid of the destination host.
:dst:procThe guid of the destination process.
:dst:exeThe file (executable) that received the connection.
:dst:txfilesAn array of files sent by the destination host.
:dst:txcountThe number of packets sent by the destination host.
:dst:txbytesThe number of bytes sent by the destination host.
:dst:handshakeA text representation of the initial handshake sent by the server.
Display:
{'hint': 'text'}
:srcThe source address / port for a connection.
:src:ipv4The source IPv4 address.
:src:ipv6The source IPv6 address.
:src:portThe source port.
:src:proto lower:TrueThe source protocol.
:src:hostThe guid of the source host.
:src:procThe guid of the source process.
:src:exeThe file (executable) that created the connection.
:src:txfilesAn array of files sent by the source host.
:src:txcountThe number of packets sent by the source host.
:src:txbytesThe number of bytes sent by the source host.
:tot:txcountThe number of packets sent in both directions.
:tot:txbytesThe number of bytes sent in both directions.
:src:handshakeA text representation of the initial handshake sent by the client.
Display:
{'hint': 'text'}
:dst:cpesAn array of NIST CPEs identified on the destination host.
:dst:softnamesAn array of software names identified on the destination host.
:src:cpesAn array of NIST CPEs identified on the source host.
:src:softnamesAn array of software names identified on the source host.
:ip:protoThe IP protocol number of the flow.
:ip:tcp:flagsAn aggregation of observed TCP flags commonly provided by flow APIs.
:sandbox:fileThe initial sample given to a sandbox environment to analyze.
:src:ssl:certThe x509 certificate sent by the client as part of an SSL/TLS negotiation.
:dst:ssl:certThe x509 certificate sent by the server as part of an SSL/TLS negotiation.
:src:rdp:hostnameThe hostname sent by the client as part of an RDP session setup.
:src:rdp:keyboard:layoutThe keyboard layout sent by the client as part of an RDP session setup.
:src:ssh:keyThe key sent by the client as part of an SSH session setup.
:dst:ssh:keyThe key sent by the server as part of an SSH session setup.
:capture:hostThe host which captured the flow.
:rawA raw record used to create the flow which may contain additional protocol details.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:fqdn
A Fully Qualified Domain Name (FQDN).
The base type for the form can be found at inet:fqdn.
An example of inet:fqdn:
vertex.link
- Properties:
name
type
doc
opts
:domainThe parent domain for the FQDN.
Read Only:
True
:host lower:TrueThe host part of the FQDN.
Read Only:
True
:issuffixTrue if the FQDN is considered a suffix.
:iszoneTrue if the FQDN is considered a zone.
:zoneThe zone level parent for this FQDN.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:group
A group name string.
The base type for the form can be found at inet:group.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:http:param
An HTTP request path query parameter.
The base type for the form can be found at inet:http:param.
- Properties:
name
type
doc
opts
:name lower:TrueThe name of the HTTP query parameter.
Read Only:
True
:valueThe value of the HTTP query parameter.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:http:request
A single HTTP request.
The base type for the form can be found at inet:http:request.
- Properties:
name
type
doc
opts
:methodThe HTTP request method string.
:pathThe requested HTTP path (without query parameters).
:urlThe reconstructed URL for the request if known.
:queryThe HTTP query string which optionally follows the path.
:headersAn array of HTTP headers from the request.
:header:hostThe FQDN parsed from the “Host:” header in the request.
:header:refererThe referer URL parsed from the “Referer:” header in the request.
:bodyThe body of the HTTP request.
:refererDeprecated. Please use :header:referer.
Deprecated:
True
:cookiesAn array of HTTP cookie values parsed from the “Cookies:” header in the request.
:response:timeA date/time value.
:response:codeThe base 64 bit signed integer type.
:response:reasonThe base string type.
:response:headersAn array of HTTP headers from the response.
:response:bodyThe file bytes type with SHA256 based primary property.
:sessionThe HTTP session this request was part of.
:flowThe raw inet:flow containing the request.
:clientThe inet:addr of the client.
:client:ipv4The server IPv4 address that the request was sent from.
:client:ipv6The server IPv6 address that the request was sent from.
:client:hostThe host that the request was sent from.
:serverThe inet:addr of the server.
:server:ipv4The server IPv4 address that the request was sent to.
:server:ipv6The server IPv6 address that the request was sent to.
:server:portThe server port that the request was sent to.
:server:hostThe host that the request was sent to.
:exeThe executable file which caused the activity.
:procThe host process which caused the activity.
:threadThe host thread which caused the activity.
:hostThe host on which the activity occurred.
:timeThe time that the activity started.
:sandbox:fileThe initial sample given to a sandbox environment to analyze.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:http:request:header
An HTTP request header.
The base type for the form can be found at inet:http:request:header.
- Properties:
name
type
doc
opts
:nameThe name of the HTTP request header.
Read Only:
True
:valueThe value of the HTTP request header.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:http:response:header
An HTTP response header.
The base type for the form can be found at inet:http:response:header.
- Properties:
name
type
doc
opts
:nameThe name of the HTTP response header.
Read Only:
True
:valueThe value of the HTTP response header.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:http:session
An HTTP session.
The base type for the form can be found at inet:http:session.
- Properties:
name
type
doc
:contactThe ps:contact which owns the session.
:cookiesAn array of cookies used to identify this specific session.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:iface
A network interface with a set of associated protocol addresses.
The base type for the form can be found at inet:iface.
- Properties:
name
type
doc
opts
:hostThe guid of the host the interface is associated with.
:name strip:TrueThe interface name.
Example:
eth0
:networkThe guid of the it:network the interface connected to.
:type lower:TrueThe free-form interface type.
:macThe ethernet (MAC) address of the interface.
:ipv4The IPv4 address of the interface.
:ipv6The IPv6 address of the interface.
:phoneThe telephone number of the interface.
:wifi:ssidThe wifi SSID of the interface.
:wifi:bssidThe wifi BSSID of the interface.
:adidAn advertising ID associated with the interface.
:mob:imeiThe IMEI of the interface.
:mob:imsiThe IMSI of the interface.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:ipv4
An IPv4 address.
The base type for the form can be found at inet:ipv4.
An example of inet:ipv4:
1.2.3.4
- Properties:
name
type
doc
:asnThe ASN to which the IPv4 address is currently assigned.
:latlongThe best known latitude/longitude for the node.
:locThe geo-political location string for the IPv4.
:placeThe geo:place associated with the latlong property.
:typeThe type of IP address (e.g., private, multicast, etc.).
:dns:revThe most current DNS reverse lookup for the IPv4.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
inet:whois:iprec
-(ipwhois)>
inet:ipv4The source IP whois record describes the target IPv4 address.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:ipv6
An IPv6 address.
The base type for the form can be found at inet:ipv6.
An example of inet:ipv6:
2607:f8b0:4004:809::200e
- Properties:
name
type
doc
:asnThe ASN to which the IPv6 address is currently assigned.
:ipv4The mapped ipv4.
:latlongThe last known latitude/longitude for the node.
:placeThe geo:place associated with the latlong property.
:dns:revThe most current DNS reverse lookup for the IPv6.
:locThe geo-political location string for the IPv6.
:typeThe type of IP address (e.g., private, multicast, etc.).
:scope enums:reserved,interface-local,link-local,realm-local,admin-local,site-local,organization-local,global,unassignedThe IPv6 scope of the address (e.g., global, link-local, etc.).
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
inet:whois:iprec
-(ipwhois)>
inet:ipv6The source IP whois record describes the target IPv6 address.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:mac
A 48-bit Media Access Control (MAC) address.
The base type for the form can be found at inet:mac.
An example of inet:mac:
aa:bb:cc:dd:ee:ff
- Properties:
name
type
doc
:vendorThe vendor associated with the 24-bit prefix of a MAC address.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:passwd
A password string.
The base type for the form can be found at inet:passwd.
- Properties:
name
type
doc
opts
:md5The MD5 hash of the password.
Read Only:
True
:sha1The SHA1 hash of the password.
Read Only:
True
:sha256The SHA256 hash of the password.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:proto
A network protocol name.
The base type for the form can be found at inet:proto.
- Properties:
name
type
doc
:portThe default port this protocol typically uses if applicable.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:rfc2822:addr
An RFC 2822 Address field.
The base type for the form can be found at inet:rfc2822:addr.
An example of inet:rfc2822:addr:
"Visi Kenshoto" <visi@vertex.link>
- Properties:
name
type
doc
opts
:nameThe name field parsed from an RFC 2822 address string.
Read Only:
True
The email field parsed from an RFC 2822 address string.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:search:query
An instance of a search query issued to a search engine.
The base type for the form can be found at inet:search:query.
- Properties:
name
type
doc
opts
:textThe search query text.
Display:
{'hint': 'text'}
:timeThe time the web search was issued.
:acctThe account that the query was issued as.
:hostThe host that issued the query.
:engine lower:TrueA simple name for the search engine used.
Example:
:requestThe HTTP request used to issue the query.
:appDeprecated. Please use :agent / inet:service:agent.
Deprecated:
True
:agentThe service agent which performed the action potentially on behalf of an account.
:accountThe account which initiated the action.
:successSet to true if the action was successful.
:ruleThe rule which allowed or denied the action.
:error:code strip:TrueThe platform specific error code if the action was unsuccessful.
:error:reason strip:TrueThe platform specific friendly error reason if the action was unsuccessful.
:platformThe platform where the action was initiated.
:instanceThe platform instance where the action was initiated.
:sessionThe session which initiated the action.
:clientThe network address of the client which initiated the action.
:client:hostThe client host which initiated the action.
:client:softwareThe client software used to initiate the action.
:client:appDeprecated. Please use :client:software.
Deprecated:
True
:serverThe network address of the server which handled the action.
:server:hostThe server host which handled the action.
:id strip:TrueA platform specific ID which identifies the node.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:search:result
A single result from a web search.
The base type for the form can be found at inet:search:result.
- Properties:
name
type
doc
:queryThe search query that produced the result.
:title lower:TrueThe title of the matching web page.
:rankThe rank/order of the query result.
:urlThe URL hosting the matching content.
:text lower:TrueExtracted/matched text from the matched content.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:server
A network server address.
The base type for the form can be found at inet:server.
An example of inet:server:
tcp://1.2.3.4:80
- Properties:
name
type
doc
opts
:proto lower:TrueThe network protocol of the server.
Read Only:
True
:ipv4The IPv4 of the server.
Read Only:
True
:ipv6The IPv6 of the server.
Read Only:
True
:hostThe it:host node for the server.
Read Only:
True
:portThe server tcp/udp port.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:servfile
A file hosted on a server for access over a network protocol.
The base type for the form can be found at inet:servfile.
- Properties:
name
type
doc
opts
:fileThe file hosted by the server.
Read Only:
True
:serverThe inet:addr of the server.
Read Only:
True
:server:proto lower:TrueThe network protocol of the server.
Read Only:
True
:server:ipv4The IPv4 of the server.
Read Only:
True
:server:ipv6The IPv6 of the server.
Read Only:
True
:server:hostThe it:host node for the server.
Read Only:
True
:server:portThe server tcp/udp port.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:access
Represents a user access request to a service resource.
The base type for the form can be found at inet:service:access.
- Properties:
name
type
doc
opts
:actionThe platform specific action which this access records.
:resourceThe resource which the account attempted to access.
:type enums:((10, 'create'), (30, 'read'), (40, 'update'), (50, 'delete'), (60, 'list'), (70, 'execute'))The type of access requested.
:appDeprecated. Please use :agent / inet:service:agent.
Deprecated:
True
:agentThe service agent which performed the action potentially on behalf of an account.
:timeThe time that the account initiated the action.
:accountThe account which initiated the action.
:successSet to true if the action was successful.
:ruleThe rule which allowed or denied the action.
:error:code strip:TrueThe platform specific error code if the action was unsuccessful.
:error:reason strip:TrueThe platform specific friendly error reason if the action was unsuccessful.
:platformThe platform where the action was initiated.
:instanceThe platform instance where the action was initiated.
:sessionThe session which initiated the action.
:clientThe network address of the client which initiated the action.
:client:hostThe client host which initiated the action.
:client:softwareThe client software used to initiate the action.
:client:appDeprecated. Please use :client:software.
Deprecated:
True
:serverThe network address of the server which handled the action.
:server:hostThe server host which handled the action.
:id strip:TrueA platform specific ID which identifies the node.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:account
An account within a service platform. Accounts may be instance specific.
The base type for the form can be found at inet:service:account.
- Properties:
name
type
doc
opts
:userThe current user name of the account.
alts:
('users',)
:usersAn array of alternate user names for this account.
:parentA parent account which owns this account.
The current email address associated with the account.
:tenantThe tenant which contains the account.
:profileThe primary contact information for the account.
:urlThe primary URL associated with the account.
:statusThe status of the account.
:periodThe period when the account existed.
:creatorThe service account which created the account.
:removerThe service account which removed or decommissioned the account.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the account.
:platformThe platform which defines the account.
:instanceThe platform instance which defines the account.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:agent
An instance of a deployed agent or software integration which is part of the service architecture.
The base type for the form can be found at inet:service:agent.
- Properties:
name
type
doc
opts
:nameThe name of the service agent instance.
alts:
('names',)
:namesAn array of alternate names for the service agent instance.
:descA description of the deployed service agent instance.
Display:
{'hint': 'text'}
:softwareThe latest known software version running on the service agent instance.
:urlThe primary URL associated with the agent.
:statusThe status of the agent.
:periodThe period when the agent existed.
:creatorThe service account which created the agent.
:removerThe service account which removed or decommissioned the agent.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the agent.
:platformThe platform which defines the agent.
:instanceThe platform instance which defines the agent.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:app
Deprecated. Please use inet:service:agent for autonomous agents.
The base type for the form can be found at inet:service:app.
- Properties:
name
type
doc
opts
:nameThe name of the platform specific application.
alts:
('names',)
:namesAn array of alternate names for the application.
:descA description of the platform specific application.
Display:
{'hint': 'text'}
:providerThe organization which provides the application.
:provider:nameThe name of the organization which provides the application.
:urlThe primary URL associated with the application.
:statusThe status of the application.
:periodThe period when the application existed.
:creatorThe service account which created the application.
:removerThe service account which removed or decommissioned the application.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the application.
:platformThe platform which defines the application.
:instanceThe platform instance which defines the application.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:threat
-(uses)>
inet:service:appDeprecated. Please use the inet:service:platform form instead.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:bucket
A file/blob storage object within a service architecture.
The base type for the form can be found at inet:service:bucket.
- Properties:
name
type
doc
opts
:nameThe name of the service resource.
:urlThe primary URL associated with the bucket.
:statusThe status of the bucket.
:periodThe period when the bucket existed.
:creatorThe service account which created the bucket.
:removerThe service account which removed or decommissioned the bucket.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the bucket.
:platformThe platform which defines the bucket.
:instanceThe platform instance which defines the bucket.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:bucket:item
An individual file stored within a bucket.
The base type for the form can be found at inet:service:bucket:item.
- Properties:
name
type
doc
opts
:bucketThe bucket which contains the item.
:fileThe bytes stored within the bucket item.
:file:nameThe name of the file stored in the bucket item.
:urlThe primary URL associated with the bucket item.
:statusThe status of the bucket item.
:periodThe period when the bucket item existed.
:creatorThe service account which created the bucket item.
:removerThe service account which removed or decommissioned the bucket item.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the bucket item.
:platformThe platform which defines the bucket item.
:instanceThe platform instance which defines the bucket item.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:channel
A channel used to distribute messages.
The base type for the form can be found at inet:service:channel.
- Properties:
name
type
doc
opts
:nameThe name of the channel.
:periodThe time period where the channel was available.
:topicThe visible topic of the channel.
:urlThe primary URL associated with the channel.
:statusThe status of the channel.
:creatorThe service account which created the channel.
:removerThe service account which removed or decommissioned the channel.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the channel.
:platformThe platform which defines the channel.
:instanceThe platform instance which defines the channel.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:channel:member
Represents a service account being a member of a channel.
The base type for the form can be found at inet:service:channel:member.
- Properties:
name
type
doc
opts
:channelThe channel that the account was a member of.
:accountThe account that was a member of the channel.
:periodThe time period where the account was a member of the channel.
:urlThe primary URL associated with the channel membership.
:statusThe status of the channel membership.
:creatorThe service account which created the channel membership.
:removerThe service account which removed or decommissioned the channel membership.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the channel membership.
:platformThe platform which defines the channel membership.
:instanceThe platform instance which defines the channel membership.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:emote
An emote or reaction by an account.
The base type for the form can be found at inet:service:emote.
- Properties:
name
type
doc
opts
:aboutThe node that the emote is about.
:text strip:TrueThe unicode or emote text of the reaction.
Example:
:partyparrot:
:urlThe primary URL associated with the emote.
:statusThe status of the emote.
:periodThe period when the emote existed.
:creatorThe service account which created the emote.
:removerThe service account which removed or decommissioned the emote.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the emote.
:platformThe platform which defines the emote.
:instanceThe platform instance which defines the emote.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:group
A group or role which contains member accounts.
The base type for the form can be found at inet:service:group.
- Properties:
name
type
doc
opts
:nameThe name of the group on this platform.
:profileCurrent detailed contact information for this group.
:urlThe primary URL associated with the group.
:statusThe status of the group.
:periodThe period when the group existed.
:creatorThe service account which created the group.
:removerThe service account which removed or decommissioned the group.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the group.
:platformThe platform which defines the group.
:instanceThe platform instance which defines the group.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:group:member
Represents a service account being a member of a group.
The base type for the form can be found at inet:service:group:member.
- Properties:
name
type
doc
opts
:accountThe account that is a member of the group.
:groupThe group that the account is a member of.
:periodThe time period when the account was a member of the group.
:urlThe primary URL associated with the group membership.
:statusThe status of the group membership.
:creatorThe service account which created the group membership.
:removerThe service account which removed or decommissioned the group membership.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the group membership.
:platformThe platform which defines the group membership.
:instanceThe platform instance which defines the group membership.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:instance
An instance of the platform such as Slack or Discord instances.
The base type for the form can be found at inet:service:instance.
- Properties:
name
type
doc
opts
:id strip:TrueA platform specific ID to identify the service instance.
Example:
B8ZS2
:platformThe platform which defines the service instance.
:urlThe primary URL which identifies the service instance.
Example:
https://v.vtx.lk/slack
:nameThe name of the service instance.
Example:
synapse users slack
:descA description of the service instance.
Display:
{'hint': 'text'}
:periodThe time period where the instance existed.
:statusThe status of this instance.
:creatorThe service account which created the instance.
:ownerThe service account which owns the instance.
:tenantThe tenant which contains the instance.
:appDeprecated. Instances are no longer scoped to applications.
Deprecated:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:login
A login event for a service account.
The base type for the form can be found at inet:service:login.
- Properties:
name
type
doc
opts
:urlThe URL of the login endpoint used for this login attempt.
:methodThe type of authentication used for the login. For example “password” or “multifactor.sms”.
:appDeprecated. Please use :agent / inet:service:agent.
Deprecated:
True
:agentThe service agent which performed the action potentially on behalf of an account.
:timeThe time that the account initiated the action.
:accountThe account which initiated the action.
:successSet to true if the action was successful.
:ruleThe rule which allowed or denied the action.
:error:code strip:TrueThe platform specific error code if the action was unsuccessful.
:error:reason strip:TrueThe platform specific friendly error reason if the action was unsuccessful.
:platformThe platform where the action was initiated.
:instanceThe platform instance where the action was initiated.
:sessionThe session which initiated the action.
:clientThe network address of the client which initiated the action.
:client:hostThe client host which initiated the action.
:client:softwareThe client software used to initiate the action.
:client:appDeprecated. Please use :client:software.
Deprecated:
True
:serverThe network address of the server which handled the action.
:server:hostThe server host which handled the action.
:id strip:TrueA platform specific ID which identifies the node.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:message
A message or post created by an account.
The base type for the form can be found at inet:service:message.
- Properties:
name
type
doc
opts
:accountThe account which sent the message.
:toThe destination account. Used for direct messages.
:urlThe URL where the message may be viewed.
:groupThe group that the message was sent to.
:channelThe channel that the message was sent to.
:threadThe thread which contains the message.
:publicSet to true if the message is publicly visible.
:titleThe message title.
:textThe text body of the message.
Display:
{'hint': 'text'}
:statusThe message status.
:replytoThe message that this message was sent in reply to. Used for message threading.
:repostThe original message reposted by this message.
:linksAn array of links contained within the message.
:attachmentsAn array of files attached to the message.
:hashtagsAn array of hashtags mentioned within the message.
:placeThe place that the message was sent from.
:place:nameThe name of the place that the message was sent from.
:client:addressDeprecated. Please use :client.
Deprecated:
True
:client:softwareThe client software version used to send the message.
:client:software:nameThe name of the client software used to send the message.
:fileThe raw file that the message was extracted from.
:typeThe type of message.
:mentionsContactable entities mentioned within the message.
:appDeprecated. Please use :agent / inet:service:agent.
Deprecated:
True
:agentThe service agent which performed the action potentially on behalf of an account.
:timeThe time that the account initiated the action.
:successSet to true if the action was successful.
:ruleThe rule which allowed or denied the action.
:error:code strip:TrueThe platform specific error code if the action was unsuccessful.
:error:reason strip:TrueThe platform specific friendly error reason if the action was unsuccessful.
:platformThe platform where the action was initiated.
:instanceThe platform instance where the action was initiated.
:sessionThe session which initiated the action.
:clientThe network address of the client which initiated the action.
:client:hostThe client host which initiated the action.
:client:appDeprecated. Please use :client:software.
Deprecated:
True
:serverThe network address of the server which handled the action.
:server:hostThe server host which handled the action.
:id strip:TrueA platform specific ID which identifies the node.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:message:attachment
A file attachment included within a message.
The base type for the form can be found at inet:service:message:attachment.
- Properties:
name
type
doc
:nameThe name of the attached file.
:textAny text associated with the file such as alt-text for images.
:fileThe file which was attached to the message.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:message:link
A URL link included within a message.
The base type for the form can be found at inet:service:message:link.
- Properties:
name
type
doc
:title strip:TrueThe title text for the link.
:urlThe URL which was attached to the message.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:message:type:taxonomy
A message type taxonomy.
The base type for the form can be found at inet:service:message:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:permission
A permission which may be granted to a service account or role.
The base type for the form can be found at inet:service:permission.
- Properties:
name
type
doc
opts
:nameThe name of the permission.
:typeThe type of permission.
:urlThe primary URL associated with the permission.
:statusThe status of the permission.
:periodThe period when the permission existed.
:creatorThe service account which created the permission.
:removerThe service account which removed or decommissioned the permission.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the permission.
:platformThe platform which defines the permission.
:instanceThe platform instance which defines the permission.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:permission:type:taxonomy
A permission type taxonomy.
The base type for the form can be found at inet:service:permission:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:platform
A network platform which provides services.
The base type for the form can be found at inet:service:platform.
- Properties:
name
type
doc
opts
:id strip:TrueAn ID which identifies the platform.
:urlThe primary URL of the platform.
Example:https://twitter.comalts:('urls',)
:urlsAn array of alternate URLs for the platform.
:zoneThe primary zone for the platform.
alts:
('zones',)
:zonesAn array of alternate zones for the platform.
:nameA friendly name for the platform.
Example:alts:('names',)
:namesAn array of alternate names for the platform.
:descA description of the service platform.
Display:
{'hint': 'text'}
:typeThe type of service platform.
:familyA family designation for use with instanced platforms such as Slack, Discord, or Mastodon.
:parentA parent platform which owns this platform.
:statusThe status of the platform.
:periodThe period when the platform existed.
:creatorThe service account which created the platform.
:removerThe service account which removed or decommissioned the platform.
:providerThe organization which operates the platform.
:provider:nameThe name of the organization which operates the platform.
:softwareThe latest known software version that the platform is running.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:threat
-(uses)>
inet:service:platformThe threat cluster uses the service platform.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:platform:type:taxonomy
A service platform type taxonomy.
The base type for the form can be found at inet:service:platform:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:relationship
A relationship between two service objects.
The base type for the form can be found at inet:service:relationship.
- Properties:
name
type
doc
opts
:sourceThe source object.
:targetThe target object.
:typeThe type of relationship between the source and the target.
Example:
follows
:urlThe primary URL associated with the relationship.
:statusThe status of the relationship.
:periodThe period when the relationship existed.
:creatorThe service account which created the relationship.
:removerThe service account which removed or decommissioned the relationship.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the relationship.
:platformThe platform which defines the relationship.
:instanceThe platform instance which defines the relationship.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:relationship:type:taxonomy
A service object relationship type taxonomy.
The base type for the form can be found at inet:service:relationship:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:resource
A generic resource provided by the service architecture.
The base type for the form can be found at inet:service:resource.
- Properties:
name
type
doc
opts
:nameThe name of the service resource.
:descA description of the service resource.
Display:
{'hint': 'text'}
:urlThe primary URL where the resource is available from the service.
:typeThe resource type. For example “rpc.endpoint”.
:statusThe status of the resource.
:periodThe period when the resource existed.
:creatorThe service account which created the resource.
:removerThe service account which removed or decommissioned the resource.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the resource.
:platformThe platform which defines the resource.
:instanceThe platform instance which defines the resource.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:resource:type:taxonomy
A taxonomy of inet service resource types.
The base type for the form can be found at inet:service:resource:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:rule
A rule which grants or denies a permission to a service account or role.
The base type for the form can be found at inet:service:rule.
- Properties:
name
type
doc
opts
:permissionThe permission which is granted.
:deniedSet to (true) to denote that the rule is an explicit deny.
:object interface:inet:service:objectThe object that the permission controls access to.
:grantee forms:('inet:service:account', 'inet:service:group')The user or role which is granted the permission.
:urlThe primary URL associated with the rule.
:statusThe status of the rule.
:periodThe period when the rule existed.
:creatorThe service account which created the rule.
:removerThe service account which removed or decommissioned the rule.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the rule.
:platformThe platform which defines the rule.
:instanceThe platform instance which defines the rule.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:ruleset
-(has)>
inet:service:ruleThe meta:ruleset includes the inet:service:rule.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:mitigation
-(uses)>
inet:service:ruleThe mitigation uses the service rule.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:session
An authenticated session.
The base type for the form can be found at inet:service:session.
- Properties:
name
type
doc
opts
:creatorThe account which authenticated to create the session.
:periodThe period where the session was valid.
:http:sessionThe HTTP session associated with the service session.
:urlThe primary URL associated with the session.
:statusThe status of the session.
:removerThe service account which removed or decommissioned the session.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the session.
:platformThe platform which defines the session.
:instanceThe platform instance which defines the session.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:subscription
A subscription to a service platform or instance.
The base type for the form can be found at inet:service:subscription.
- Properties:
name
type
doc
opts
:levelA platform specific subscription level.
:pay:instrumentThe primary payment instrument used to pay for the subscription.
:subscriberThe subscriber who owns the subscription.
:urlThe primary URL associated with the subscription.
:statusThe status of the subscription.
:periodThe period when the subscription existed.
:creatorThe service account which created the subscription.
:removerThe service account which removed or decommissioned the subscription.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the subscription.
:platformThe platform which defines the subscription.
:instanceThe platform instance which defines the subscription.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:subscription:level:taxonomy
A taxonomy of platform specific subscription levels.
The base type for the form can be found at inet:service:subscription:level:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:tenant
A tenant which groups accounts and instances.
The base type for the form can be found at inet:service:tenant.
- Properties:
name
type
doc
opts
:profileThe primary contact information for the tenant.
:urlThe primary URL associated with the tenant.
:statusThe status of the tenant.
:periodThe period when the tenant existed.
:creatorThe service account which created the tenant.
:removerThe service account which removed or decommissioned the tenant.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the tenant.
:platformThe platform which defines the tenant.
:instanceThe platform instance which defines the tenant.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:service:thread
A message thread.
The base type for the form can be found at inet:service:thread.
- Properties:
name
type
doc
opts
:titleThe title of the thread.
:channelThe channel that contains the thread.
:messageThe message which initiated the thread.
:urlThe primary URL associated with the thread.
:statusThe status of the thread.
:periodThe period when the thread existed.
:creatorThe service account which created the thread.
:removerThe service account which removed or decommissioned the thread.
:appDeprecated. Objects are no longer scoped to an application or agent.
Deprecated:
True
:id strip:TrueA platform specific ID which identifies the thread.
:platformThe platform which defines the thread.
:instanceThe platform instance which defines the thread.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:ssl:cert
Deprecated. Please use inet:tls:servercert or inet:tls:clientcert.
The base type for the form can be found at inet:ssl:cert.
- Properties:
name
type
doc
opts
:fileThe file bytes for the SSL certificate.
Read Only:
True
:serverThe server that presented the SSL certificate.
Read Only:
True
:server:ipv4The SSL server IPv4 address.
Read Only:
True
:server:ipv6The SSL server IPv6 address.
Read Only:
True
:server:portThe SSL server listening port.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:ssl:jarmhash
A TLS JARM fingerprint hash.
The base type for the form can be found at inet:ssl:jarmhash.
- Properties:
name
type
doc
opts
:ciphersThe encoded cipher and TLS version of the server.
Read Only:
True
:extensionsThe truncated SHA256 of the TLS server extensions.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:ssl:jarmsample
A JARM hash sample taken from a server.
The base type for the form can be found at inet:ssl:jarmsample.
- Properties:
name
type
doc
opts
:jarmhashThe JARM hash computed from the server responses.
Read Only:
True
:serverThe server that was sampled to compute the JARM hash.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:clientcert
An x509 certificate sent by a client for TLS.
The base type for the form can be found at inet:tls:clientcert.
An example of inet:tls:clientcert:
(1.2.3.4:443, 3fdf364e081c14997b291852d1f23868)
- Properties:
name
type
doc
opts
:clientThe client associated with the x509 certificate.
Read Only:
True
:certThe x509 certificate sent by the client.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:handshake
An instance of a TLS handshake between a server and client.
The base type for the form can be found at inet:tls:handshake.
- Properties:
name
type
doc
opts
:timeThe time the handshake was initiated.
:flowThe raw inet:flow associated with the handshake.
:serverThe TLS server during the handshake.
:server:certThe x509 certificate sent by the server during the handshake.
:server:ja3sThe JA3S fingerprint of the server response.
:server:ja4sThe JA4S fingerprint of the server response.
:clientThe TLS client during the handshake.
:client:certThe x509 certificate sent by the client during the handshake.
:client:ja3The JA3 fingerprint of the client request.
:client:ja4The JA4 fingerprint of the client request.
:client:fingerprint:ja3Deprecated. Please use :client:ja3.
Deprecated:
True
:server:fingerprint:ja3Deprecated. Please use :server:ja3s.
Deprecated:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:ja3:sample
A JA3 sample taken from a client.
The base type for the form can be found at inet:tls:ja3:sample.
- Properties:
name
type
doc
opts
:clientThe client that was sampled to produce the JA3 hash.
Read Only:
True
:ja3The JA3 hash computed from the client’s TLS hello packet.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:ja3s:sample
A JA3 sample taken from a server.
The base type for the form can be found at inet:tls:ja3s:sample.
- Properties:
name
type
doc
opts
:serverThe server that was sampled to produce the JA3S hash.
Read Only:
True
:ja3sThe JA3S hash computed from the server’s TLS hello packet.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:ja4
A JA4 TLS client fingerprint.
The base type for the form can be found at inet:tls:ja4.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:ja4:sample
A JA4 TLS client fingerprint used by a client.
The base type for the form can be found at inet:tls:ja4:sample.
- Properties:
name
type
doc
opts
:ja4The JA4 TLS client fingerprint.
Read Only:
True
:clientThe client which initiated the TLS handshake with a JA4 fingerprint.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:ja4s
A JA4S TLS server fingerprint.
The base type for the form can be found at inet:tls:ja4s.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:ja4s:sample
A JA4S TLS server fingerprint used by a server.
The base type for the form can be found at inet:tls:ja4s:sample.
- Properties:
name
type
doc
opts
:ja4sThe JA4S TLS server fingerprint.
Read Only:
True
:serverThe server which responded to the TLS handshake with a JA4S fingerprint.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tls:servercert
An x509 certificate sent by a server for TLS.
The base type for the form can be found at inet:tls:servercert.
An example of inet:tls:servercert:
(1.2.3.4:443, c7437790af01ae1bb2f8f3b684c70bf8)
- Properties:
name
type
doc
opts
:serverThe server associated with the x509 certificate.
Read Only:
True
:certThe x509 certificate sent by the server.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tunnel
A specific sequence of hosts forwarding connections such as a VPN or proxy.
The base type for the form can be found at inet:tunnel.
- Properties:
name
type
doc
:anonIndicates that this tunnel provides anonymization.
:typeThe type of tunnel such as vpn or proxy.
:ingressThe server where client traffic enters the tunnel.
:egressThe server where client traffic leaves the tunnel.
:operatorThe contact information for the tunnel operator.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:tunnel:type:taxonomy
A taxonomy of network tunnel types.
The base type for the form can be found at inet:tunnel:type:taxonomy.
- Properties:
name
type
doc
opts
:titleA brief title of the definition.
:summaryDeprecated. Please use title/desc.
Deprecated:TrueDisplay:{'hint': 'text'}
:descA definition of the taxonomy entry.
Display:
{'hint': 'text'}
:sortA display sort order for siblings.
:baseThe base taxon.
Read Only:
True
:depthThe depth indexed from 0.
Read Only:
True
:parentThe taxonomy parent.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:url
A Universal Resource Locator (URL).
The base type for the form can be found at inet:url.
An example of inet:url:
http://www.woot.com/files/index.html
- Properties:
name
type
doc
opts
:fqdnThe fqdn used in the URL (e.g., http://www.woot.com/page.html).
Read Only:
True
:ipv4The IPv4 address used in the URL (e.g., http://1.2.3.4/page.html).
Read Only:
True
:ipv6The IPv6 address used in the URL.
Read Only:
True
:passwdThe optional password used to access the URL.
Read Only:
True
:baseThe base scheme, user/pass, fqdn, port and path w/o parameters.
Read Only:
True
:pathThe path in the URL w/o parameters.
Read Only:
True
:paramsThe URL parameter string.
Read Only:
True
:portThe port of the URL. URLs prefixed with http will be set to port 80 and URLs prefixed with https will be set to port 443 unless otherwise specified.
Read Only:
True
:proto lower:TrueThe protocol in the URL.
Read Only:
True
:userThe optional username used to access the URL.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:dev:repo
-(has)>
inet:urlThe repo has content hosted at the URL.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:url:mirror
A URL mirror site.
The base type for the form can be found at inet:url:mirror.
- Properties:
name
type
doc
opts
:ofThe URL being mirrored.
Read Only:
True
:atThe URL of the mirror.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:urlfile
A file hosted at a specific Universal Resource Locator (URL).
The base type for the form can be found at inet:urlfile.
- Properties:
name
type
doc
opts
:urlThe URL where the file was hosted.
Read Only:
True
:fileThe file that was hosted at the URL.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:urlredir
A URL that redirects to another URL, such as via a URL shortening service or an HTTP 302 response.
The base type for the form can be found at inet:urlredir.
An example of inet:urlredir:
(http://foo.com/,http://bar.com/)
- Properties:
name
type
doc
opts
:srcThe original/source URL before redirect.
Read Only:
True
:src:fqdnThe FQDN within the src URL (if present).
Read Only:
True
:dstThe redirected/destination URL.
Read Only:
True
:dst:fqdnThe FQDN within the dst URL (if present).
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:user
A username string.
The base type for the form can be found at inet:user.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:acct
An account with a given Internet-based site or service.
The base type for the form can be found at inet:web:acct.
An example of inet:web:acct:
twitter.com/invisig0th
- Properties:
name
type
doc
opts
:avatarThe file representing the avatar (e.g., profile picture) for the account.
:bannerThe file representing the banner for the account.
:dobA self-declared date of birth for the account (if the account belongs to a person).
The email address associated with the account.
:linked:acctsLinked accounts specified in the account profile.
:latlongThe last known latitude/longitude for the node.
:placeThe geo:place associated with the latlong property.
:locA self-declared location for the account.
:nameThe localized name associated with the account (may be different from the account identifier, e.g., a display name).
:name:enThe English version of the name associated with the (may be different from the account identifier, e.g., a display name).
Deprecated:
True
:aliasesAn array of alternate names for the user.
:occupation lower:TrueA self-declared occupation for the account.
:passwdThe current password for the account.
:phoneThe phone number associated with the account.
:realnameThe localized version of the real name of the account owner / registrant.
:realname:enThe English version of the real name of the account owner / registrant.
Deprecated:
True
:signupThe date and time the account was registered.
:signup:clientThe client address used to sign up for the account.
:signup:client:ipv4The IPv4 address used to sign up for the account.
:signup:client:ipv6The IPv6 address used to sign up for the account.
:siteThe site or service associated with the account.
Read Only:
True
:taglineThe text of the account status or tag line.
:urlThe service provider URL where the account is hosted.
:userThe unique identifier for the account (may be different from the common name or display name).
Read Only:
True
:webpageA related URL specified by the account (e.g., a personal or company web page, blog, etc.).
:recovery:emailAn email address registered as a recovery email address for the account.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:action
An instance of an account performing an action at an Internet-based site or service.
The base type for the form can be found at inet:web:action.
- Properties:
name
type
doc
:actThe action performed by the account.
:acctThe web account associated with the action.
:acct:siteThe site or service associated with the account.
:acct:userThe unique identifier for the account.
:timeThe date and time the account performed the action.
:clientThe source client address of the action.
:client:ipv4The source IPv4 address of the action.
:client:ipv6The source IPv6 address of the action.
:locThe location of the user executing the web action.
:latlongThe latlong of the user when executing the web action.
:placeThe geo:place of the user when executing the web action.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:attachment
An instance of a file being sent to a web service by an account.
The base type for the form can be found at inet:web:attachment.
- Properties:
name
type
doc
opts
:acctThe account that uploaded the file.
:postThe optional web post that the file was attached to.
:mesgThe optional web message that the file was attached to.
:protoThe protocol used to transmit the file to the web service.
Example:
https
:interactiveSet to true if the upload was interactive. False if automated.
:fileThe file that was sent.
:nameThe name of the file at the time it was sent.
:timeThe time the file was sent.
:clientThe client address which initiated the upload.
:client:ipv4The IPv4 address of the client that initiated the upload.
:client:ipv6The IPv6 address of the client that initiated the upload.
:placeThe place the file was sent from.
:place:locThe geopolitical location that the file was sent from.
:place:nameThe reported name of the place that the file was sent from.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:channel
A channel within a web service or instance such as slack or discord.
The base type for the form can be found at inet:web:channel.
- Properties:
name
type
doc
opts
:urlThe primary URL used to identify the channel.
Example:
https://app.slack.com/client/T2XK1223Y/C2XHHNDS7
:id strip:TrueThe operator specified ID of this channel.
Example:
C2XHHNDS7
:instanceThe instance which contains the channel.
:name strip:TrueThe visible name of the channel.
Example:
general
:topic strip:TrueThe visible topic of the channel.
Example:
Synapse Discussion - Feel free to invite others!
:createdThe time the channel was created.
:creatorThe account which created the channel.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:chprofile
A change to a web account. Used to capture historical properties associated with an account, as opposed to current data in the inet:web:acct node.
The base type for the form can be found at inet:web:chprofile.
- Properties:
name
type
doc
:acctThe web account associated with the change.
:acct:siteThe site or service associated with the account.
:acct:userThe unique identifier for the account.
:clientThe source address used to make the account change.
:client:ipv4The source IPv4 address used to make the account change.
:client:ipv6The source IPv6 address used to make the account change.
:timeThe date and time when the account change occurred.
:pvThe prop=valu of the account property that was changed. Valu should be the old / original value, while the new value should be updated on the inet:web:acct form.
:pv:propThe property that was changed.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:file
A file posted by a web account.
The base type for the form can be found at inet:web:file.
- Properties:
name
type
doc
opts
:acctThe account that owns or is associated with the file.
Read Only:
True
:acct:siteThe site or service associated with the account.
Read Only:
True
:acct:userThe unique identifier for the account.
Read Only:
True
:fileThe file owned by or associated with the account.
Read Only:
True
:nameThe name of the file owned by or associated with the account.
:postedDeprecated. Instance data belongs on inet:web:attachment.
Deprecated:
True
:clientDeprecated. Instance data belongs on inet:web:attachment.
Deprecated:
True
:client:ipv4Deprecated. Instance data belongs on inet:web:attachment.
Deprecated:
True
:client:ipv6Deprecated. Instance data belongs on inet:web:attachment.
Deprecated:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:follows
A web account follows or is connected to another web account.
The base type for the form can be found at inet:web:follows.
- Properties:
name
type
doc
opts
:followerThe account following an account.
Read Only:
True
:followeeThe account followed by an account.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:group
A group hosted within or registered with a given Internet-based site or service.
The base type for the form can be found at inet:web:group.
An example of inet:web:group:
somesite.com/mycoolgroup
- Properties:
name
type
doc
opts
:siteThe site or service associated with the group.
Read Only:
True
:idThe site-specific unique identifier for the group (may be different from the common name or display name).
Read Only:
True
:nameThe localized name associated with the group (may be different from the account identifier, e.g., a display name).
:aliasesAn array of alternate names for the group.
:name:enThe English version of the name associated with the group (may be different from the localized name).
Deprecated:
True
:urlThe service provider URL where the group is hosted.
:avatarThe file representing the avatar (e.g., profile picture) for the group.
:descThe text of the description of the group.
:webpageA related URL specified by the group (e.g., primary web site, etc.).
:loc lower:TrueA self-declared location for the group.
:latlongThe last known latitude/longitude for the node.
:placeThe geo:place associated with the latlong property.
:signupThe date and time the group was created on the site.
:signup:clientThe client address used to create the group.
:signup:client:ipv4The IPv4 address used to create the group.
:signup:client:ipv6The IPv6 address used to create the group.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:hashtag
A hashtag used in a web post.
The base type for the form can be found at inet:web:hashtag.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:instance
An instance of a web service such as slack or discord.
The base type for the form can be found at inet:web:instance.
- Properties:
name
type
doc
opts
:urlThe primary URL used to identify the instance.
Example:
https://app.slack.com/client/T2XK1223Y
:id strip:TrueThe operator specified ID of this instance.
Example:
T2XK1223Y
:name strip:TrueThe visible name of the instance.
Example:
vertex synapse
:createdThe time the instance was created.
:creatorThe account which created the instance.
:ownerThe organization which created the instance.
:owner:fqdnThe FQDN of the organization which created the instance. Used for entity resolution.
Example:
vertex.link
:owner:nameThe name of the organization which created the instance. Used for entity resolution.
Example:
the vertex project, llc.
:operatorThe organization which operates the instance.
:operator:nameThe name of the organization which operates the instance. Used for entity resolution.
Example:
slack
:operator:fqdnThe FQDN of the organization which operates the instance. Used for entity resolution.
Example:
slack.com- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:logon
An instance of an account authenticating to an Internet-based site or service.
The base type for the form can be found at inet:web:logon.
- Properties:
name
type
doc
:acctThe web account associated with the logon event.
:acct:siteThe site or service associated with the account.
:acct:userThe unique identifier for the account.
:timeThe date and time the account logged into the service.
:clientThe source address of the logon.
:client:ipv4The source IPv4 address of the logon.
:client:ipv6The source IPv6 address of the logon.
:logoutThe date and time the account logged out of the service.
:locThe location of the user executing the logon.
:latlongThe latlong of the user executing the logon.
:placeThe geo:place of the user executing the logon.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:memb
Deprecated. Please use inet:web:member.
The base type for the form can be found at inet:web:memb.
- Properties:
name
type
doc
opts
:acctThe account that is a member of the group.
Read Only:
True
:groupThe group that the account is a member of.
Read Only:
True
:title lower:TrueThe title or status of the member (e.g., admin, new member, etc.).
:joinedThe date / time the account joined the group.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:member
Represents a web account membership in a channel or group.
The base type for the form can be found at inet:web:member.
- Properties:
name
type
doc
:acctThe account that is a member of the group or channel.
:groupThe group that the account is a member of.
:channelThe channel that the account is a member of.
:addedThe date / time the account was added to the group or channel.
:removedThe date / time the account was removed from the group or channel.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:mesg
A message sent from one web account to another web account or channel.
The base type for the form can be found at inet:web:mesg.
An example of inet:web:mesg:
((twitter.com, invisig0th), (twitter.com, gobbles), 20041012130220)
- Properties:
name
type
doc
opts
:fromThe web account that sent the message.
Read Only:
True
:toThe web account that received the message.
Read Only:
True
:clientThe source address of the message.
:client:ipv4The source IPv4 address of the message.
:client:ipv6The source IPv6 address of the message.
:timeThe date and time at which the message was sent.
Read Only:
True
:urlThe URL where the message is posted / visible.
:textThe text of the message.
Display:
{'hint': 'text'}
:deletedThe message was deleted.
:fileThe file attached to or sent with the message.
:placeThe place that the message was reportedly sent from.
:place:nameThe name of the place that the message was reportedly sent from. Used for entity resolution.
:instanceThe instance where the message was sent.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:post
A post made by a web account.
The base type for the form can be found at inet:web:post.
- Properties:
name
type
doc
opts
:acctThe web account that made the post.
:acct:siteThe site or service associated with the account.
:clientThe source address of the post.
:client:ipv4The source IPv4 address of the post.
:client:ipv6The source IPv6 address of the post.
:acct:userThe unique identifier for the account.
:textThe text of the post.
Display:
{'hint': 'text'}
:timeThe date and time that the post was made.
:deletedThe message was deleted by the poster.
:urlThe URL where the post is published / visible.
:fileThe file that was attached to the post.
:replytoThe post that this post is in reply to.
:repostThe original post that this is a repost of.
:hashtagsHashtags mentioned within the post.
:mentions:usersAccounts mentioned within the post.
:mentions:groupsGroups mentioned within the post.
:locThe location that the post was reportedly sent from.
:placeThe place that the post was reportedly sent from.
:place:nameThe name of the place that the post was reportedly sent from. Used for entity resolution.
:latlongThe place that the post was reportedly sent from.
:channelThe channel where the post was made.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:web:post:link
A link contained within post text.
The base type for the form can be found at inet:web:post:link.
- Properties:
name
type
doc
:postThe post containing the embedded link.
:urlThe url that the link forwards to.
:textThe displayed hyperlink text if it was not the raw URL.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:contact
An individual contact from a domain whois record.
The base type for the form can be found at inet:whois:contact.
- Properties:
name
type
doc
opts
:recThe whois record containing the contact data.
Read Only:
True
:rec:fqdnThe domain associated with the whois record.
Read Only:
True
:rec:asofThe date of the whois record.
Read Only:
True
:type lower:TrueThe contact type (e.g., registrar, registrant, admin, billing, tech, etc.).
Read Only:
True
:id lower:TrueThe ID associated with the contact.
:name lower:TrueThe name of the contact.
The email address of the contact.
:orgnameThe name of the contact organization.
:address lower:TrueThe content of the street address field(s) of the contact.
:city lower:TrueThe content of the city field of the contact.
:state lower:TrueThe content of the state field of the contact.
:country lower:TrueThe two-letter country code of the contact.
:phoneThe content of the phone field of the contact.
:faxThe content of the fax field of the contact.
:urlThe URL specified for the contact.
:whois:fqdnThe whois server FQDN for the given contact (most likely a registrar).
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:email
An email address associated with an FQDN via whois registration text.
The base type for the form can be found at inet:whois:email.
- Properties:
name
type
doc
opts
:fqdnThe domain with a whois record containing the email address.
Read Only:
True
The email address associated with the domain whois record.
Read Only:
True- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:ipcontact
An individual contact from an IP block record.
The base type for the form can be found at inet:whois:ipcontact.
- Properties:
name
type
doc
:contactContact information associated with a registration.
:asofThe date of the record.
:createdThe “created” time from the record.
:updatedThe “last updated” time from the record.
:role lower:TrueThe primary role for the contact.
:rolesAdditional roles assigned to the contact.
:asnThe associated Autonomous System Number (ASN).
:idThe registry unique identifier (e.g. NET-74-0-0-0-1).
:linksURLs provided with the record.
:status lower:TrueThe state of the registered contact (e.g. validated, obscured).
:contactsAdditional contacts referenced by this contact.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:ipquery
Query details used to retrieve an IP record.
The base type for the form can be found at inet:whois:ipquery.
- Properties:
name
type
doc
:timeThe time the request was made.
:urlThe query URL when using the HTTP RDAP Protocol.
:fqdnThe FQDN of the host server when using the legacy WHOIS Protocol.
:ipv4The IPv4 address queried.
:ipv6The IPv6 address queried.
:successWhether the host returned a valid response for the query.
:recThe resulting record from the query.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:iprec
An IPv4/IPv6 block registration record.
The base type for the form can be found at inet:whois:iprec.
- Properties:
name
type
doc
opts
:net4The IPv4 address range assigned.
:net4:minThe first IPv4 in the range assigned.
:net4:maxThe last IPv4 in the range assigned.
:net6The IPv6 address range assigned.
:net6:minThe first IPv6 in the range assigned.
:net6:maxThe last IPv6 in the range assigned.
:asofThe date of the record.
:createdThe “created” time from the record.
:updatedThe “last updated” time from the record.
:text lower:TrueThe full text of the record.
Display:
{'hint': 'text'}
:desc lower:TrueNotes concerning the record.
Display:
{'hint': 'text'}
:asnThe associated Autonomous System Number (ASN).
:idThe registry unique identifier (e.g. NET-74-0-0-0-1).
:nameThe name assigned to the network by the registrant.
:parentidThe registry unique identifier of the parent whois record (e.g. NET-74-0-0-0-0).
:registrantDeprecated. Add the registrant inet:whois:ipcontact to the :contacts array.
Deprecated:
True
:contactsAdditional contacts from the record.
:countryThe two-letter ISO 3166 country code.
:status lower:TrueThe state of the registered network.
:type lower:TrueThe classification of the registered network (e.g. direct allocation).
:linksURLs provided with the record.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
inet:whois:iprec
-(ipwhois)>
inet:ipv4The source IP whois record describes the target IPv4 address.
inet:whois:iprec
-(ipwhois)>
inet:ipv6The source IP whois record describes the target IPv6 address.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:rar
A domain registrar.
The base type for the form can be found at inet:whois:rar.
An example of inet:whois:rar:
godaddy, inc.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node was stolen or copied as a result of the compromise.
risk:extortion
-(leveraged)>
*The extortion event was based on attacker access to the target node.
risk:leak
-(leaked)>
*The leak included the disclosure of the target node.
risk:outage
-(impacted)>
*The outage event impacted the availability of the target node.
risk:threat
-(targets)>
*The threat cluster targeted the target node.
risk:threat
-(uses)>
*The threat cluster uses the target node.
risk:tool:software
-(uses)>
*The tool uses the target node.
sci:evidence
-(has)>
*The evidence includes observations from the target nodes.
sci:experiment
-(uses)>
*The experiment used the target nodes when it was run.
sci:observation
-(has)>
*The observations are summarized from the target nodes.
inet:whois:rec
A domain whois record.
The base type for the form can be found at inet:whois:rec.
- Properties:
name
type
doc
opts
:fqdnThe domain associated with the whois record.
Read Only:
True
:asofThe date of the whois record.
Read Only:
True
:text lower:TrueThe full text of the whois record.
Display:
{'hint': 'text'}
:createdThe “created” time from the whois record.
:updatedThe “last updated” time from the whois record.
:expiresThe “expires” time from the whois record.
:registrarThe registrar name from the whois record.
:registrantThe registrant name from the whois record.
- Source Edges:
source
verb
target
doc
*
-(linked)>
*The source node is linked to the target node.
*
-(meets)>
ou:requirementThe requirement is met by the source node.
*
-(refs)>
*The source node contains a reference to the target node.
*
-(seenat)>
geo:telemDeprecated. Please use geo:telem:node.
- Target Edges:
source
verb
target
doc
*
-(linked)>
*None
*
-(refs)>
*None
econ:purchase
-(acquired)>
*The purchase was used to acquire the target node.
it:app:snort:rule
-(detects)>
*The snort rule is intended for use in detecting the target node.
it:app:yara:rule
-(detects)>
*The YARA rule is intended for use in detecting the target node.
it:exec:query
-(found)>
*The target node was returned as a result of running the query.
it:log:event
-(about)>
*The it:log:event is about the target node.
math:algorithm
-(generates)>
*The target node was generated by the algorithm.
meta:feed
-(found)>
*The meta:feed produced the target node.
meta:note
-(about)>
*The meta:note is about the target node.
meta:rule
-(detects)>
*The meta:rule is designed to detect instances of the target node.
meta:rule
-(matches)>
*The meta:rule has matched on target node.
meta:source
-(seen)>
*The meta:source observed the target node.
ou:campaign
-(targets)>
*The campaign targeted the target nodes.
ou:campaign
-(uses)>
*The campaign made use of the target node.
ou:contribution
-(includes)>
*The contribution includes the specific node.
ou:org
-(has)>
*The organization is or was in possession of the target node.
ou:org
-(owns)>
*The organization owns or owned the target node.
ou:org
-(targets)>
*The organization targets the target node.
ou:org
-(uses)>
*The ou:org makes use of the target node.
plan:procedure:step
-(uses)>
*The step in the procedure makes use of the target node.
ps:contact
-(has)>
*The contact is or was in possession of the target node.
ps:contact
-(owns)>
*The contact owns or owned the target node.
ps:person
-(has)>
*The person is or was in possession of the target node.
ps:person
-(owns)>
*The person owns or owned the target node.
risk:alert
-(about)>
*The alert is about the target node.
risk:attack
-(targets)>
*The attack targeted the target node.
risk:attack
-(uses)>
*The attack used the target node to facilitate the attack.
risk:compromise
-(stole)>
*The target node w