v2.137.0 Model Updates
The following model updates were made during the v2.137.0 Synapse release.
New Types
it:mitre:attack:matrixAdd a type to capture the enumeration of MITRE ATT&CK matrix values.
New Forms
inet:egressAdd a form to capture a host using a specific network egress client address.
it:prod:softregAdd a form to capture a registry entry is created by a specific software version.
transport:land:vehicleAdd a form to capture an individual vehicle.
transport:land:registrationAdd a form to capture the registration issued to a contact for a land vehicle.
transport:land:licenseAdd a form to capture the license to operate a land vehicle issued to a contact.
New Properties
inet:http:requestThe form had the following property added to it:
refererThe referer URL parsed from the “Referer:” header in the request.
inet:search:queryThe form had the following property added to it:
requestThe HTTP request used to issue the query.
it:mitre:attack:tacticThe form had the following property added to it:
matrixThe ATT&CK matrix which defines the tactic.
it:mitre:attack:techniqueThe form had the following property added to it:
matrixThe ATT&CK matrix which defines the technique.
it:mitre:attack:mitigationThe form had the following property added to it:
matrixThe ATT&CK matrix which defines the mitigation.
it:app:snort:ruleThe form had the following property added to it:
engineThe snort engine ID which can parse and evaluate the rule text.
it:app:yara:ruleThe form had the following properties added to it:
ext:idThe YARA rule ID from an external system.
urlA URL which documents the YARA rule.
ou:campaignThe form had the following property added to it:
tagThe tag used to annotate nodes that are associated with the campaign.
ou:orgThe form had the following properties added to it:
countryThe organization’s country of origin.
country:codeThe 2 digit ISO 3166 country code for the organization’s country of origin.
risk:threatThe form had the following properties added to it:
countryThe reporting organization’s assessed country of origin of the threat cluster.
country:codeThe 2 digit ISO 3166 country code for the threat cluster’s assessed country of origin.
risk:compromiseThe form had the following property added to it:
vectorThe attack assessed to be the initial compromise vector.
Light Edges
detectsWhen used with a
meta:rulenode, the edge indicates the rule was designed to detect instances of the target node.When used with an
it:app:snort:rulenode, the edge indicates the rule was designed to detect instances of the target node.When used with an
it:app:yara:rulenode, the edge indicates the rule was designed to detect instances of the target node.containsWhen used between two
geo:placenodes, the edge indicates the source place completely contains the target place.
Deprecated Properties
geo:placeThe form had the following property marked as deprecated:
parent