{ "namespace": "cccs", "description": "CCCS Custom Taxonomy", "version": 12, "predicates": [ { "value": "analytics", "expanded": "Analytics", "description": "The analytics classification contains names for analytic processes that are generating events with data.", "uuid": "d403ef22-34ab-4f77-ab68-b0fa5623451a" }, { "value": "malware_classification", "expanded": "Malware Classification", "description": "Malware classification taxonomy.", "uuid": "374ba84e-b165-41f2-8a8f-89a7d0b34efc" }, { "value": "incident_classification", "expanded": "Incident Classification", "description": "Incident classification used by CCCS.", "uuid": "ecb320a5-65dc-445c-b32f-183e77824dc1" }, { "value": "confidence", "expanded": "Confidence Classification", "description": "The confidence classification specify the trust level of the information.", "uuid": "28e4f6e4-f271-4486-97d0-2d99514cf9bc" }, { "value": "context", "expanded": "Context Classification", "description": "The context classification is used internally by CCCS to indicate if the attribute contains an indicator of compromise or a threat intelligence information.", "uuid": "43adfff4-bb9c-433f-be5c-f0b4ca3ad70a" }, { "value": "event", "expanded": "Event Classification", "description": "The event classification contains tags related to special events we want to track (EX: COVID, Olympic, etc..).", "uuid": "0bb78ec3-bd91-45a4-8689-dbd3685da32a" }, { "value": "platform", "expanded": "Platform Classification", "description": "The platform classification specify the target platform.", "uuid": "2b7dd0b6-5f03-412d-bdb2-a5a9dab29566" }, { "value": "source", "expanded": "Source Classification", "description": "The source classification specify where the information came from.", "uuid": "c3ad8f45-1bd0-4fdd-9fdd-dc2be777d6e7" }, { "value": "product", "expanded": "CCCS Products Classification", "description": "The CCCS product classification is for all CCCS products: Advisory, Alert, CyberFlash, etc...", "uuid": "88c250d4-78a0-4f72-aff7-5d67a40fc0f5" }, { "value": "report", "expanded": "Report Classification", "description": "The report classification is used internally by CCCS to indicate in what report the MISP event will be inserted.", "uuid": "055a20c8-f613-4d36-8091-4d3cf40c29e4" }, { "value": "tar_submission", "expanded": "Technical Analysis Request Classification.", "description": "The TAR submission indicate what type of file was submitted to CCCS to analyze.", "uuid": "77566f5f-539d-4cc3-a5e8-00a3743167f2" }, { "value": "sector", "expanded": "The Affected Sector Classification.", "description": "The sector classification indicate the affected sector.", "uuid": "cc96139b-e23a-4021-89cc-a641fde61916" }, { "value": "mitigation", "expanded": "The Mitigation Classification", "description": "The mitigation classification indicate the action that was taken by CCCS regarding the MISP event.", "uuid": "da925828-9646-4c77-8482-bc56fb1beca4" }, { "value": "acceptable-usage", "expanded": "The Acceptable Usage Classification", "description": "The acceptable usage classification specify on how information can be use. It typically complements a TLP level.", "uuid": "3042ea43-a6d2-49a0-80e8-0f5e233d70ca" } ], "values": [ { "predicate": "analytics", "entry": [ { "colour": "#0a358a", "value": "icecube", "expanded": "This represents an event generated by the IceCube analytic.", "uuid": "b19ecb5d-4e3c-43ab-96bb-5b58afeed1f9" }, { "colour": "#0a358a", "value": "ironclaw", "expanded": "This represents an event generated by the IronClaw analytic.", "uuid": "dd1d8f48-071b-4f5a-8df7-ce833e7e14da" }, { "colour": "#0a358a", "value": "phishhook", "expanded": "This represents an event generated by the PhishHook analytic.", "uuid": "32bab4d5-3d26-4ae3-bb95-649bdab8ff70" }, { "colour": "#0a358a", "value": "puppetmaster", "expanded": "This represents an event generated by the PuppetMaster analytic.", "uuid": "bf0fd031-4f2f-43ec-afd4-d34e4147a0b2" } ] }, { "predicate": "malware_classification", "entry": [ { "value": "adware", "expanded": "An adware malware is a type of software that shows you extra promotions that you cannot control as you use your PC. You wouldn't see the extra ads if you didn't have adware installed.", "colour": "#4c3011", "uuid": "9dfbf717-97c3-4902-989d-8d0fa41c3ba2" }, { "value": "apt", "expanded": "A apt malware is related to an Advanced Persistent Threat group.", "colour": "#4c3011", "uuid": "0801e06b-e717-417f-96dc-9c786ef570e4" }, { "value": "backdoor", "expanded": "A backdoor malware gives malicious users remote control over the infected computer. They enable the author to do anything they wish on the infected computer including sending, receiving, launching and deleting files, displaying data and rebooting the computer. Backdoor Trojans are often used to unite a group of victim computers to form a botnet or zombie network that can be used for criminal purposes.", "colour": "#4c3011", "uuid": "cab1c444-94d0-460d-826f-4d73f1bfaf38" }, { "value": "banker", "expanded": "A banker malware is designed to steal your account data for online banking systems, e-payment systems and credit or debit cards.", "colour": "#4c3011", "uuid": "fa5e2e63-80e2-4e23-b963-fb6fb6df6341" }, { "value": "bootkit", "expanded": "A bootkit malware modifies the boot sectors of a hard drive, including the Master Boot Record (MBR) and/or the Volume Boot Record (VBR).", "colour": "#4c3011", "uuid": "d4514ca4-6fb1-4fd9-a1a2-663d09f41c01" }, { "value": "bot", "expanded": "A bot malware is designed to infect a host and connect back to one or more control servers (C2) for an entire network of compromised devices, or botnet.", "colour": "#4c3011", "uuid": "26317c31-28da-474f-93e4-77c0721efddd" }, { "value": "browser-hijacker", "expanded": "A browser hijacker malware modifies the web browser's settings without the user's permission. The result is the placement of unwanted advertising into the browser, and possibly the replacement of an existing home page or search page with the hijacker page.", "colour": "#4c3011", "uuid": "81b0d7c8-0f74-4743-9a18-1baa646ac8d6" }, { "value": "bruteforcer", "expanded": "A bruteforcer malware tries to brute force a website/server/service in order to achieve something else (EX: Discovering websites using default credentials).", "colour": "#4c3011", "uuid": "8c7f7bfb-e5a3-4bed-9b3e-4614952c1bbe" }, { "value": "clickfraud", "expanded": "A clickfraud malware can uses an infected machine to click on websites or applications. This type of malware is usually used to make money for a malicious hacker by clicking on online advertisements and making it look like the website gets more traffic than it does. They can also be used to skew online polls, install programs on your PC, or make unwanted software appear more popular than it is.", "colour": "#4c3011", "uuid": "3596b5a4-67ad-4f0e-9158-49db23e36cd5" }, { "value": "cryptominer", "expanded": "A cryptominer malware uses a computer's resources without the owner explicit permission to perform crypto mining calculation.", "colour": "#4c3011", "uuid": "4b0d350b-8ea4-4425-bacb-bb795328c20d" }, { "value": "ddos", "expanded": "A ddos malware conducts a distributed denial of service attack against a targeted web address. By sending multiple requests from the infected machine and several others, the malware can overwhelm the target machine leading to a denial of service.", "colour": "#4c3011", "uuid": "07f2acf8-8f8e-470a-8f05-63342f900aa4" }, { "value": "downloader", "expanded": "A downloader malware downloads/installs additional malware or/and new versions of malicious programs in the target system.", "colour": "#4c3011", "uuid": "05b5ee68-ca88-4a91-b914-92915e01b7b4" }, { "value": "dropper", "expanded": "A dropper malware is used to install a embedded encrypted/compressed payload in the infected system. They are commonly named installer.", "colour": "#4c3011", "uuid": "a6433842-e6bc-4d01-88b4-11943bc26bb9" }, { "value": "exploit", "expanded": "An exploit is a program that takes advantage of a vulnerability in an application or system to perform malicious activity, such as: arbitrary code execution, privilege escalation, denial of service, data exfiltration, etc...", "colour": "#4c3011", "uuid": "ab1fca9b-8b15-4d76-83db-17b73e6b5e29" }, { "value": "exploitkit", "expanded": "A exploit kit malware contain data or code that takes advantage of a vulnerability within an application that is running in the target system.", "colour": "#4c3011", "uuid": "026549a0-e220-4413-8449-940d60e93624" }, { "value": "fakeav", "expanded": "A fake antivirus malware simulate the activity of a real antivirus software. They are designed to extort money in return for the detection and removal of threat, even though the threats that they report are actually non-existent.", "colour": "#4c3011", "uuid": "8924da4f-dd9a-4fbe-a8ab-26e1b9f625ed" }, { "value": "hacktool", "expanded": "A hack tool is a type of software that can be used to allow and maintain unauthorized access to your PC.", "colour": "#4c3011", "uuid": "0102da95-f6c0-4ab2-94b0-9c14652afc70" }, { "value": "infostealer", "expanded": "An infostealer malware, also known as spyware, collects the user’s personal information, such as the browsing history and saved credentials and uses it without adequate consent.", "colour": "#4c3011", "uuid": "b7fd54ed-907a-46fd-921d-f5ebba9b7394" }, { "value": "keylogger", "expanded": "A keylogger malware monitors and logs every keystroke it can identify. Once installed, the malware either keeps track of all the keys and stores the information locally, after which the hacker needs physical access to the computer to retrieve the information, or the logs are sent over the internet back to the hacker.", "colour": "#4c3011", "uuid": "386fe7b2-0feb-4f8c-848e-4e214cfd17a9" }, { "value": "loader", "expanded": "A loader malware is loading another application from the filesystem or directly into the memory.", "colour": "#4c3011", "uuid": "5daaa689-c1c0-4913-a337-eb42235a4e5b" }, { "value": "obfuscator", "expanded": "An obfuscator malware hides its code and purpose to make it more difficult for security software to detect or remove it.", "colour": "#4c3011", "uuid": "4965d066-ccd2-43db-a65f-71c518a850c1" }, { "value": "pos", "expanded": "A point-of-sale malware is used by cybercriminals to target point of sale (POS) and payment terminals with the intent to obtain credit card and debit card information.", "colour": "#4c3011", "uuid": "b458b57d-8be2-4d82-8e0b-9f6b6c4ad019" }, { "value": "proxy", "expanded": "A proxy malware allows unauthorized parties to use the infected computer as a proxy server to access the Internet anonymously.", "colour": "#4c3011", "uuid": "d620d917-14a1-4a16-b73a-4309402d2873" }, { "value": "rat", "expanded": "A rat malware is used by a remote hacker to gain access and control of an infected machine.", "colour": "#4c3011", "uuid": "8335286a-00e0-40fb-a182-a2961cd193da" }, { "value": "ransomware", "expanded": "A ransomware malware can modify data in the target computer so the operating system will stop running correctly or the data is no longer accessible. The criminal will only restore the computer state or data after a ransom is paid to them (mostly using cryptocurrency).", "colour": "#4c3011", "uuid": "02763a54-c2ec-4809-8bec-d184f297b410" }, { "value": "reverse-proxy", "expanded": "A reverse proxy malware is a server that receives requests from the internet and forwards them to a small set of servers.", "colour": "#4c3011", "uuid": "8c5a2d63-019e-4f0d-8f15-cfa8c0dac61e" }, { "value": "rootkit", "expanded": "A rootkit malware is designed to conceal certain objects or activities in the system. Often their main purpose is to prevent malicious programs being detected in order to extend the period in which programs can run on an infected computer.", "colour": "#4c3011", "uuid": "81d6236e-b834-4eee-9e77-c5b1da114c47" }, { "value": "scanner", "expanded": "A scanner malware scan the internet / network(s) / system(s) / service(s) to collect information. That information could be used later to perpetuate a cyber attack.", "colour": "#4c3011", "uuid": "613489fc-3d60-4048-86ef-d988438c3a63" }, { "value": "scareware", "expanded": "A scareware malware is using social engineering to cause shock, anxiety, or the perception of a threat in order to manipulate users into buying unwanted software.", "colour": "#4c3011", "uuid": "467355ba-cc3f-4c3b-8bc7-1b01b8b6fd00" }, { "value": "spammer", "expanded": "A spammer malware is a type of malware that is sending spam email from the infected machine using a malicious or compromised email address.", "colour": "#4c3011", "uuid": "7e81920d-de5e-4aa0-bd59-9827be727332" }, { "value": "trojan", "expanded": "A generic term used for malware of unknown classification.", "colour": "#4c3011", "uuid": "25cfe5cf-5af3-43bf-8bc7-0f556bb96091" }, { "value": "wiper", "expanded": "A wiper malware destroy the data from the infected machine. It normally disable any mechanism that would restore the data (EX: backup, system restore points).", "colour": "#4c3011", "uuid": "5a80994e-dad6-4f59-acd8-f78f1e33e7d1" }, { "value": "webshell", "expanded": "A web shell malware is a script that can be uploaded to a web server to enable remote administration of the machine.", "colour": "#4c3011", "uuid": "f6503d8d-9788-4f1a-a058-5389c358263c" }, { "value": "worm", "expanded": "A worm malware is a type of malware that replicates itself in order to spread to other computers. It often uses a computer network to spread itself to other machines (EX: malspam email).", "colour": "#4c3011", "uuid": "f46b59ad-f900-4a06-bbed-5a40476664b2" } ] }, { "predicate": "incident_classification", "entry": [ { "value": "brute-force", "expanded": "Brute force attack.", "colour": "#a6d31d", "uuid": "25f64fd7-d17d-42fa-83bb-42d035bc54cd" }, { "value": "compromise-account", "expanded": "A compromise account.", "colour": "#a6d31d", "uuid": "94743960-c5eb-4296-945e-4ef0db9b89bc" }, { "value": "compromise-malicious-code", "expanded": "A compromise server with malicious code.", "colour": "#a6d31d", "uuid": "56c7443c-af08-4815-8c69-a62f7a5c1366" }, { "value": "credential-theft", "expanded": "Credential theft.", "colour": "#a6d31d", "uuid": "933b9540-1f20-4ccf-8ffc-bfddc83b6da6" }, { "value": "c&c", "expanded": "Command and control (EX: Pannel).", "colour": "#a6d31d", "uuid": "8692740b-2f47-4361-b35d-17a7fa8d7d2a" }, { "value": "defacement", "expanded": "Defaced website", "colour": "#a6d31d", "uuid": "aa99afbf-84f8-48d0-bae4-cf2abbdb8e40" }, { "value": "doppelganger", "expanded": "Doppelganger.", "colour": "#a6d31d", "uuid": "16e5b742-8a9d-453c-af81-c03b74e1a833" }, { "value": "dos-ddos", "expanded": "Denial of service.", "colour": "#a6d31d", "uuid": "599a9f32-2a0b-4342-9656-07905d66ade9" }, { "value": "illegal-activity", "expanded": "Illegal Activity (EX: copyright, juvenille porn, fraud, criminal activities, etc..)", "colour": "#a6d31d", "uuid": "addb3335-7adb-4b72-9cc2-eb5816a444bd" }, { "value": "infection", "expanded": "Malware infection.", "colour": "#a6d31d", "uuid": "54a47cf4-8cb0-459f-b4d4-608f7555bd50" }, { "value": "information-leak", "expanded": "Information Leak.", "colour": "#a6d31d", "uuid": "26ab883d-7861-43ec-97f9-179eee3ce2af" }, { "value": "impersonation", "expanded": "Impersonation.", "colour": "#a6d31d", "uuid": "607061aa-ff44-4320-b271-28caf96dec40" }, { "value": "malspam", "expanded": "Spam email email with malicious code.", "colour": "#a6d31d", "uuid": "8014e1b3-2840-4d3d-878e-92faf16f11bb" }, { "value": "misconfig", "expanded": "Misconfig (improper usage)", "colour": "#a6d31d", "uuid": "5fcd7e5f-7d7f-4818-90c5-30ef665077de" }, { "value": "phishing", "expanded": "Phishing incident", "colour": "#a6d31d", "uuid": "8ad11b56-04cc-42e2-a832-43556c5da581" }, { "value": "scan-probes-attempted_access", "expanded": "Scan", "colour": "#a6d31d", "uuid": "a98c9409-af4a-43d8-b9e3-70ff5b469f41" }, { "value": "session-hijacking", "expanded": "Session Hijacking and Man-in-the-Middle Attacks", "colour": "#a6d31d", "uuid": "f0a05686-8036-409f-9e22-afd659c50df7" }, { "value": "smishing", "expanded": "Phishing using a SMS message. (SMS Phishing)", "colour": "#a6d31d", "uuid": "77278b30-4097-45eb-8f99-d52fd7d2d90d" }, { "value": "spam", "expanded": "Spam email", "colour": "#a6d31d", "uuid": "a466d97f-b54b-4187-8696-c61f9b139cd8" }, { "value": "spear-phishing", "expanded": "Spear Phishing", "colour": "#a6d31d", "uuid": "9ab33553-1571-4ab3-bf5f-785848fee323" }, { "value": "sql-injection", "expanded": "SQL injection attack", "colour": "#a6d31d", "uuid": "90444b3c-14bc-4fa6-b0ef-9bee39c063a1" }, { "value": "unauthorized-access", "expanded": "Unauthorized Access", "colour": "#a6d31d", "uuid": "4a128a97-eb32-4a55-8a19-e39ab4f26d02" }, { "value": "vulnerability", "expanded": "Vulnerability", "colour": "#a6d31d", "uuid": "5e912c0f-7148-46e4-a581-b7733d28d358" }, { "value": "wire-transfer-fraud", "expanded": "Wire transfer fraud", "colour": "#a6d31d", "uuid": "ecbd6e64-ebd2-4813-b25e-1be6ea46265f" }, { "value": "xss", "expanded": "Cross site scription", "colour": "#a6d31d", "uuid": "e1860edc-2f3c-48f4-a751-8dbac2a1fa21" } ] }, { "predicate": "confidence", "entry": [ { "colour": "#ff0000", "value": "low", "expanded": "Low Confidence Level", "uuid": "4f6f7879-65bf-43ae-86f2-be73d4326d54" }, { "colour": "#ebff00", "value": "medium", "expanded": "Medium Confidence Level", "uuid": "2bc508b9-0382-4580-8b4f-be94851b15cd" }, { "colour": "#00ff19", "value": "high", "expanded": "High Confidence Level", "uuid": "183a97ca-7fcc-4db0-ae53-6ef667176b53" } ] }, { "predicate": "context", "entry": [ { "colour": "#4f008c", "value": "indicator", "expanded": "This attribute is an indicator of compromise.", "uuid": "78cc5c26-9e75-4fbc-bf09-782ed5e02b77" }, { "colour": "#4f008c", "value": "observable", "expanded": "This attribute is an observable information.", "uuid": "6c063c32-39ba-4783-9c77-e576fdba2beb" } ] }, { "predicate": "event", "entry": [ { "colour": "#24e320", "value": "covid19", "expanded": "This tag is related to the Conoravirus (COVID-19) pandemy that strike the world in 2019/2020.", "uuid": "7b22cfbf-ba42-47a7-aeac-f690e92beaeb" } ] }, { "predicate": "platform", "entry": [ { "colour": "#8e15c1", "value": "windows", "expanded": "Microsoft Windows Operating System", "uuid": "a793bad0-cdff-449d-9d2f-ea3fc1e44809" }, { "colour": "#8e15c1", "value": "macos", "expanded": "Apple Operating System", "uuid": "7790364f-13e4-4d3e-b751-f2bcb4362c26" }, { "colour": "#8e15c1", "value": "linux", "expanded": "Linux Operating System", "uuid": "4e2b2847-2dc2-4c78-be37-b51f68100605" }, { "colour": "#8e15c1", "value": "android", "expanded": "Android Operating System", "uuid": "5b15ed66-33e1-40e1-83a9-8ea67bdec050" }, { "colour": "#8e15c1", "value": "ios", "expanded": "Iphone Operating System", "uuid": "d0fa6f4b-21bb-4c8e-9a45-d795d1112292" }, { "colour": "#8e15c1", "value": "solaris", "expanded": "Oracle Solaris Operating System", "uuid": "092a0c0e-c7ed-435a-802e-1b6351a13689" }, { "colour": "#8e15c1", "value": "cross-platform", "expanded": "Run on mutiple operating system", "uuid": "a3c7e522-cbce-4e92-a34b-d5e82d2a1096" }, { "colour": "#8e15c1", "value": "IoT", "expanded": "Embedded IoT operating system", "uuid": "9133935d-0747-4b50-b6da-eee2e54f24ff" }, { "colour": "#8e15c1", "value": "arm", "expanded": "Arm (Advanced RISC Machine)", "uuid": "59ec332b-bcb8-4b8b-b81a-dcdbbb8314eb" }, { "colour": "#8e15c1", "value": "mips", "expanded": "MIPS (Reduced RISC Machine)", "uuid": "c30b6dd2-32ad-4a9e-91a6-b2d39ecb689e" } ] }, { "predicate": "source", "entry": [ { "value": "trusted-partner", "expanded": "Report came from a CCCS trusted partner.", "colour": "#595456", "uuid": "ff2c4827-1137-4541-a896-1d471862dbab" }, { "value": "international-partner", "expanded": "Report came from a CCCS international partner.", "colour": "#595456", "uuid": "6040684e-4ccc-4d8e-b2b7-f6bbab4dbe82" }, { "value": "trusted-source", "expanded": "Report came from a CCCS trusted source.", "colour": "#595456", "uuid": "c7d1d99a-70a0-4c3d-b1c8-15f5bc8fb42d" }, { "value": "cccs-research", "expanded": "Report came from CCCS research.", "colour": "#595456", "uuid": "8a5e83f7-a372-42ee-a350-200cf6d3894b" }, { "value": "internal", "expanded": "Report came from an sibling team.", "colour": "#595456", "uuid": "23727a90-8bdb-4b58-9887-c6bfb77b019d" }, { "value": "federal-partner", "expanded": "Report came from an federal partner", "colour": "#595456", "uuid": "dc1079f0-3ab1-44fa-9505-a6847173efa1" }, { "value": "open-source", "expanded": "open source report.", "colour": "#595456", "uuid": "9ee167e5-e479-4237-8dfb-146787d0eabd" } ] }, { "predicate": "product", "entry": [ { "value": "advisory", "expanded": "Advisory", "colour": "#bf11a2", "uuid": "a0a5c377-611c-4b84-b21f-bfaf4a914dad" }, { "value": "alert", "expanded": "Alert", "colour": "#bf11a2", "uuid": "d94e8531-68df-4d67-ac2e-92b2d943efd4" }, { "value": "cyber-flash", "expanded": "Cyber Flash", "colour": "#bf11a2", "uuid": "01fac139-61e0-4b67-861b-a2288cd6e314" }, { "value": "information-note", "expanded": "Information note", "colour": "#bf11a2", "uuid": "f3363588-6516-4f6a-8b3a-3f4273d168bb" } ] }, { "predicate": "report", "entry": [ { "value": "executive-summary", "expanded": "The MISP event will generate the executive summary.", "colour": "#135606", "uuid": "477e5b07-5449-4822-862d-fcdc7e91a322" }, { "value": "operational", "expanded": "The MISP event will be generated in the operation report.", "colour": "#135606", "uuid": "5e9e2f0d-ff93-49ca-8064-4aedda7f41e1" }, { "value": "technical", "expanded": "The MISP event will be generated in the technical report.", "colour": "#135606", "uuid": "de64cb7f-e9d8-41f1-b837-ee323275a35a" }, { "value": "ioc-harvesting", "expanded": "The MISP event title will be displayed above the technical section.", "colour": "#135606", "uuid": "5d0d8c4b-3edd-483e-9886-27df6df63aa5" } ] }, { "predicate": "tar_submission", "entry": [ { "value": "archive", "expanded": "An archive with files.", "colour": "#0d09e0", "uuid": "f18608be-b4d6-4602-b552-f35d257a23ef" }, { "value": "browser-extension", "expanded": "A browser extension / plugin.", "colour": "#0d09e0", "uuid": "0ef21cad-b33b-41cc-8dba-463a6fa6a108" }, { "value": "data", "expanded": "A data file.", "colour": "#0d09e0", "uuid": "1f95c0a3-7506-4d01-a53d-3e62497f38ed" }, { "value": "driver", "expanded": "A driver file (EX: driver.sys, lib.ko).", "colour": "#0d09e0", "uuid": "81ce6a40-65e5-417b-9df1-69feec5f2f67" }, { "value": "disk-image", "expanded": "A disk image (EX: mem.raw).", "colour": "#0d09e0", "uuid": "4cb7e9df-974a-4e3b-8e99-ce74b43108dc" }, { "value": "executable", "expanded": "An executable file (EX: PE32, ELF).", "colour": "#0d09e0", "uuid": "5ae69472-5307-4938-a751-e4a0a12818bf" }, { "value": "exploit-kit", "expanded": "An exploit kit.", "colour": "#0d09e0", "uuid": "afe70d02-77ca-49a2-903b-2e8392d143ab" }, { "value": "infected-device", "expanded": "An infected device.", "colour": "#0d09e0", "uuid": "efa454d3-ffb0-46de-8acd-4f3034f21869" }, { "value": "image", "expanded": "An image containing another payload or malicious properties (EX: Stegano)", "colour": "#0d09e0", "uuid": "3c54b814-095e-4242-8417-2e6b2caccf80" }, { "value": "firmware", "expanded": "A firmware.", "colour": "#1713f0", "uuid": "8ae3880c-c72b-4ec4-af62-fc0f0d78b934" }, { "value": "hash", "expanded": "A hash value.", "colour": "#1713f0", "uuid": "9d1b879a-0d28-47d3-8fb7-85e516508797" }, { "value": "library", "expanded": "A library (EX: DLL, SO).", "colour": "#0d09e0", "uuid": "c02cd39f-f40c-4dce-aba8-4a82c3904649" }, { "value": "log", "expanded": "A log file (EX: WebServer Log).", "colour": "#0d09e0", "uuid": "8b94f0c9-e8dc-4957-b4e5-95bc2356cf28" }, { "value": "maldoc", "expanded": "A malicious Microsoft Word document.", "colour": "#0d09e0", "uuid": "5a346522-3dd4-4358-bf78-ef8565e18cd3" }, { "value": "malspam", "expanded": "A malspam email.", "colour": "#0d09e0", "uuid": "b7677873-e3a2-4aae-a2cf-9fa4a4937a68" }, { "value": "malicious-link", "expanded": "A malicious link.", "colour": "#0d09e0", "uuid": "8775f7b8-66b4-4bbe-a040-c92d3a1652e8" }, { "value": "malicious-script", "expanded": "A malicious script.", "colour": "#0d09e0", "uuid": "20407518-7611-4df4-bb3b-dbeed8a8f6f3" }, { "value": "memory-dump", "expanded": "A memory dump.", "colour": "#0d09e0", "uuid": "60923a27-8b8e-4a54-83d8-5aa5130ccfa0" }, { "value": "pcap", "expanded": "A network traffic capture file.", "colour": "#0d09e0", "uuid": "693ce018-3b5c-4538-9f99-23eda4393e25" }, { "value": "pdf", "expanded": "A malicious PDF document.", "colour": "#0d09e0", "uuid": "8b2ef398-64d7-416a-80fe-1ca12c507500" }, { "value": "phishing-kit", "expanded": "A phishing kit.", "colour": "#0d09e0", "uuid": "5b9a6f0e-f661-4f6d-8ebc-a6aa9a501fc5" }, { "value": "quarantine", "expanded": "A quarantine file", "colour": "#0d09e0", "uuid": "5816ea16-875a-40ac-a554-c8389d790fc4" }, { "value": "ransomnote", "expanded": "A note left by an ransomware.", "colour": "#0d09e0", "uuid": "e9b93da6-6ad4-4243-85e6-647d1f7fef59" }, { "value": "registry-key", "expanded": "A registry key and value.", "colour": "#0d09e0", "uuid": "f0f054c2-4119-4476-bb6d-3a155ed66fe3" }, { "value": "spam", "expanded": "A malicious email.", "colour": "#0d09e0", "uuid": "d1b47796-1c5c-4ccc-89f6-c3f668e52e5e" }, { "value": "webpage", "expanded": "A web page (EX: HTML, CFML)", "colour": "#0d09e0", "uuid": "566bb90c-646f-4fb8-b6b5-01559fc2b458" } ] }, { "predicate": "sector", "entry": [ { "value": "federal", "expanded": "Federal Government of Canada.", "colour": "#20d6cb", "uuid": "181b6a97-d30c-4e31-a086-4b67060e981b" }, { "value": "municipal", "expanded": "Municipal", "colour": "#20d6cb", "uuid": "e73fa556-9e79-45aa-8184-8af60831a62f" }, { "value": "provincial-territorial", "expanded": "Provincial and Territorial", "colour": "#20d6cb", "uuid": "3e5c9baa-ab46-4d02-9902-4cbfc68f8a34" }, { "value": "ict", "expanded": "Information Communication Technology", "colour": "#20d6cb", "uuid": "6ce46a2f-75dd-4861-990d-2a3ab984b3f8" }, { "value": "finance", "expanded": "finance", "colour": "#20d6cb", "uuid": "4c179f48-f6b5-459a-aca5-977167bf7580" }, { "value": "energy-utils-electricity", "expanded": "Electricity", "colour": "#20d6cb", "uuid": "8a3278e8-e543-4a3e-99f6-03aa30d147d3" }, { "value": "energy-utils-oil-gas", "expanded": "Oil and Gas", "colour": "#20d6cb", "uuid": "fb2ebd27-37dc-4a26-9c8a-f9fa51320cda" }, { "value": "energy-utils-nuclear", "expanded": "Nuclear", "colour": "#20d6cb", "uuid": "f695a0c3-a6f1-4298-901b-3154487c089c" }, { "value": "energy-utils-mines", "expanded": "Mines", "colour": "#20d6cb", "uuid": "e1608bab-e542-4207-af87-31f79f69dd94" }, { "value": "transportation-air", "expanded": "Air", "colour": "#20d6cb", "uuid": "d77e7be7-9442-499d-bceb-49555557c5e2" }, { "value": "transportation-marine", "expanded": "Marine", "colour": "#20d6cb", "uuid": "ba12373a-3c51-4fdc-903d-dc47a445dbb9" }, { "value": "transportation-rail", "expanded": "Rail", "colour": "#20d6cb", "uuid": "cb215ca2-7b57-4676-8784-d89d8a7e6073" }, { "value": "transportation-road", "expanded": "Road", "colour": "#20d6cb", "uuid": "080561b8-2c5c-4ab0-8fb0-b2a169db3c7e" }, { "value": "manufacturing", "expanded": "Manufacturing", "colour": "#20d6cb", "uuid": "fe4c86f7-a42c-4482-bb83-c722160eccca" }, { "value": "health", "expanded": "Health", "colour": "#20d6cb", "uuid": "19d9e643-8662-46cd-b349-b5e423ad902e" }, { "value": "food", "expanded": "Food", "colour": "#20d6cb", "uuid": "7aa2a0dc-198a-4dc4-87e2-c25d0fbd4192" }, { "value": "water", "expanded": "Water", "colour": "#20d6cb", "uuid": "a4253ec5-22b7-44f6-a223-b8b22675ca36" }, { "value": "safety-police", "expanded": "Police", "colour": "#20d6cb", "uuid": "138101f8-6bfd-4056-bbf9-764a91534934" }, { "value": "safety-ambulance", "expanded": "Ambulance", "colour": "#20d6cb", "uuid": "fe8ec43f-a2bc-4d29-b470-097c42eeb0d8" }, { "value": "safety-fire", "expanded": "Fire", "colour": "#20d6cb", "uuid": "1dad9ce2-ceec-4adb-9e15-ec44409d2bf2" }, { "value": "safety-military", "expanded": "Military", "colour": "#20d6cb", "uuid": "3b23bfec-338c-473b-82c1-6a8f3216e794" }, { "value": "scada", "expanded": "Scada", "colour": "#20d6cb", "uuid": "67d8b390-9b11-4ef3-9dd5-a6aea6d80316" }, { "value": "international", "expanded": "International", "colour": "#20d6cb", "uuid": "76e175e2-b2e3-4c12-bb90-b5dae78eff4f" }, { "value": "academia", "expanded": "Academia", "colour": "#20d6cb", "uuid": "98e90ce5-65b4-458a-8541-aaa7121d6bca" }, { "value": "non-critical", "expanded": "Non Critical", "colour": "#20d6cb", "uuid": "2f798ac6-2cfc-41a5-8073-31e676c2976a" }, { "value": "non-government", "expanded": "Non Governement", "colour": "#20d6cb", "uuid": "703dfe81-35bb-48c9-9bcf-6b77d557146c" }, { "value": "all", "expanded": "All", "colour": "#20d6cb", "uuid": "dc66e57f-4e4b-46bf-acd8-95b97dfc11db" } ] }, { "predicate": "mitigation", "entry": [ { "value": "advice-org", "expanded": "Advice the affected organization.", "colour": "#f7880a", "uuid": "1e7d4a68-9755-4963-bf8c-75469ad5b2b6" }, { "value": "apwg", "expanded": "Anti-phishing working group", "colour": "#f7880a", "uuid": "fec83fce-3f75-4c21-bc7d-fca428269349" }, { "value": "code-removal-request", "expanded": "Code Removal Request (CRR)", "colour": "#f7880a", "uuid": "0e9a33dc-cd71-423b-89b0-4865227919fc" }, { "value": "crtc", "expanded": "Canadian Radio-television and Telecommunications Commission (CRTC)", "colour": "#f7880a", "uuid": "810acf53-40af-4571-9098-59ec7347441c" }, { "value": "deregister-domain", "expanded": "Deregister Domain (DRR)", "colour": "#f7880a", "uuid": "60b4271f-f5ca-4f2e-a0ee-c100f98d2d00" }, { "value": "netcraft", "expanded": "Netcraft (malicious url takedown service)", "colour": "#f7880a", "uuid": "56ed3b2d-d227-4abd-899f-5df4cea80451" }, { "value": "notification-org-victim", "expanded": "Notification - victims/affected Org", "colour": "#f7880a", "uuid": "0f8919ce-ad5d-4f43-95de-784b3edca3cf" }, { "value": "null-route-ip", "expanded": "Null Route IP", "colour": "#f7880a", "uuid": "182413d1-f23a-4349-9911-3e675435b534" }, { "value": "phishlabs", "expanded": "Phishlabs by HelpSystems (digital risk protection service)", "colour": "#f7880a", "uuid": "d09c02dd-dc53-46d0-9399-a57192e75335" }, { "value": "sinkhole-domain", "expanded": "Sinkhole Domain (DRR)", "colour": "#f7880a", "uuid": "5e949ab7-5d23-4c70-bdee-fe4a0c21f8a0" } ] }, { "predicate": "acceptable-usage", "entry": [ { "value": "no monetization", "expanded": "Information should not be monetized", "colour": "#66ffcc", "uuid": "1a065b3f-4542-4628-accd-23317589ec4e" } ] } ], "uuid": "8639287e-2a00-4753-904b-2e23a72e7a29" }