{ "values": [ { "entry": [ { "description": "Malware detected in a system.", "expanded": "Infection", "value": "infection", "uuid": "57db167a-5564-5882-8ce8-7923626311d2" }, { "description": "Malware attached to a message or email message containing link to malicious URL or IP.", "expanded": "Distribution", "value": "distribution", "uuid": "6584ab61-d902-5666-96e1-1c500813fd80" }, { "description": "System used as a command-and-control point by a botnet. Also included in this field are systems serving as a point for gathering information stolen by botnets.", "expanded": "Command & Control (C&C)", "value": "command-and-control", "uuid": "39ca2aed-16eb-5895-a6fa-8ea9c67a207a" }, { "description": "System attempting to gain access to a port normally linked to a specific type of malware / System attempting to gain access to an IP address or URL normally linked to a specific type of malware, e.g. C&C or a distribution page for components linked to a specific botnet.", "expanded": "Malicious connection", "value": "malicious-connection", "uuid": "0180fbe6-cf12-5467-9127-de2e777716e6" } ], "predicate": "malware" }, { "entry": [ { "description": "Single source using specially designed software to affect the normal functioning of a specific service, by exploiting vulnerability / Mass mailing of requests (network packets, emails, etc.) from one single source to a specific service, aimed at affecting its normal functioning.", "expanded": "Denial of Service (DoS) / Distributed Denial of Service (DDoS)", "value": "dos-ddos", "uuid": "970fa580-8967-5325-b63e-9c59d1999b95" }, { "description": "Logical and physical activities which – although they are not aimed at causing damage to information or at preventing its transmission among systems – have this effect.", "expanded": "Sabotage", "value": "sabotage", "uuid": "fed3d2c7-bca6-5059-b95a-160d1132dde7" } ], "predicate": "availability" }, { "entry": [ { "description": "Single system scan searching for open ports or services using these ports for responding / Scanning a network aimed at identifying systems which are active in the same network / Transfer of a specific DNS zone.", "expanded": "Scanning", "value": "scanning", "uuid": "4bf87ccd-a9e5-585d-8533-dc2a5032502f" }, { "description": "Logical or physical interception of communications.", "expanded": "Sniffing", "value": "sniffing", "uuid": "391e5c4b-7cf9-5824-b3d6-677f34716908" }, { "description": "Mass emailing aimed at collecting data for phishing purposes with regard to the victims / Hosting web sites for phishing purposes.", "expanded": "Phishing", "value": "phishing", "uuid": "b35bc79b-19c3-5ab4-a4e8-5e9ded9f1233" } ], "predicate": "information-gathering" }, { "entry": [ { "description": "Unsuccessful use of a tool exploiting a specific vulnerability of the system / Unsuccessful attempt to manipulate or read the information of a database by using the SQL injection technique / Unsuccessful attempts to perform attacks by using cross-site scripting techniques / Unsuccessful attempt to include files in the system under attack by using file inclusion techniques / Unauthorised access to a system or component by bypassing an access control system in place.", "expanded": "Exploitation of vulnerability attempt", "value": "vulnerability-exploitation-attempt", "uuid": "a1425fe2-f7cf-511c-80ec-2624472d2a2b" }, { "description": "Unsuccessful login by using sequential credentials for gaining access to the system / Unsuccessful acquisition of access credentials by breaking the protective cryptographic keys / Unsuccessful login by using system access credentials previously loaded into a dictionary.", "expanded": "Login attempt", "value": "login-attempt", "uuid": "442a4ba4-6505-5028-9394-c4269da4fbe5" } ], "predicate": "intrusion-attempt" }, { "entry": [ { "description": "Unauthorised use of a tool exploiting a specific vulnerability of the system / Unauthorised manipulation or reading of information contained in a database by using the SQL injection technique / Attack performed with the use of cross-site scripting techniques / Unauthorised inclusion of files into a system under attack with the use of file inclusion techniques / Unauthorised access to a system or component by bypassing an access control system in place.", "expanded": "(Successful) Exploitation of vulnerability", "value": "vulnerability-exploitation", "uuid": "257398f2-0210-5a81-b2f0-c7382aac274b" }, { "description": "Unauthorised access to a system or component by using stolen access credentials.", "expanded": "Compromising an account", "value": "account-compromise", "uuid": "b4ce6ffe-90ad-5b0a-b6fe-e391527072ec" } ], "predicate": "intrusion" }, { "entry": [ { "description": "Unauthorised access to a system or component / Unauthorised access to a set of information / Unauthorised access to and sharing of a specific set of information.", "expanded": "Unauthorised access", "value": "unauthorised-access", "uuid": "5dca2acf-0629-58d7-8104-052716bb28b4" }, { "description": "Unauthorised changes to a specific set of information / Unauthorised deleting of a specific set of information.", "expanded": "Unauthorised modification / deletion", "value": "unauthorised-modification-or-deletion", "uuid": "d5e59bc5-3acc-5b22-af06-ddeb1965be36" } ], "predicate": "information-security" }, { "entry": [ { "description": "Use of institutional resources for purposes other than those intended.", "expanded": "Misuse or unauthorised use of resources", "value": "resources-misuse", "uuid": "283d65f3-db80-5504-9a85-3fa2163aaf71" }, { "description": "Unauthorised use of the name of an institution.", "expanded": "False representation", "value": "false-representation", "uuid": "d79a8b32-bd75-502f-b3c7-785c65d08848" } ], "predicate": "fraud" }, { "entry": [ { "description": "Sending an unusually large quantity of email messages / Unsolicited or unwanted email message sent to the recipient.", "expanded": "SPAM", "value": "spam", "uuid": "d84b7238-765f-5ba2-a5e5-a4408ea50d9e" }, { "description": "Unauthorised distribution or sharing of content protected by Copyright and related rights.", "expanded": "Copyright", "value": "copyright", "uuid": "e8e23ba9-6dcc-5997-9145-302b40ab4fbf" }, { "description": "Distribution or sharing of illegal content such as child sexual exploitation material, racism, xenophobia, etc.", "expanded": "Child Sexual Exploitation, racism or incitement to violence", "value": "cse-racism-violence-incitement", "uuid": "f9681b8d-5ebd-5b2e-ab15-4ffd6f15802c" } ], "predicate": "abusive-content" }, { "entry": [ { "description": "Incidents which do not fit the existing classification, acting as an indicator for the classification’s update.", "expanded": "Unclassified incident", "value": "unclassified-incident", "uuid": "f2035f9c-4745-525b-95c4-f905d47d30c2" }, { "description": "Unprocessed incidents which have remained undetermined from the beginning.", "expanded": "Undetermined incident", "value": "undetermined-incident", "uuid": "4d5306e9-a356-5286-9bda-94c169db35a6" } ], "predicate": "other" } ], "predicates": [ { "description": "Infection of one or various systems with a specific type of malware / Connection performed by/from/to (a) suspicious system(s)", "expanded": "Malicious software/code", "value": "malware", "uuid": "c5804b0d-d487-5f0e-a902-43342e7e1c68" }, { "description": "Disruption of the processing and response capacity of systems and networks in order to render them inoperative / Premeditated action to damage a system, interrupt a process, change or delete information, etc.", "expanded": "Availability", "value": "availability", "uuid": "965d7dfa-69d8-5133-948a-4981b87eb686" }, { "description": "Active and passive gathering of information on systems or networks / Unauthorised monitoring and reading of network traffic / Attempt to gather information on a user or a system through phishing methods.", "expanded": "Information Gathering", "value": "information-gathering", "uuid": "9f6c7132-1c40-5a2e-a6e8-0fcc5d630f6a" }, { "description": "Attempt to intrude by exploiting vulnerability in a system, component or network / Attempt to log in to services or authentication/access control mechanisms.", "expanded": "Intrusion Attempt", "value": "intrusion-attempt", "uuid": "0ef6bc26-d6fa-5c0f-b341-cb3e25288bee" }, { "description": "Actual intrusion by exploiting vulnerability in the system, component or network / Actual intrusion in a system, component or network by compromising a user or administrator account.", "expanded": "Intrusion", "value": "intrusion", "uuid": "b5ad3990-f0c8-58a6-8e1b-0e00651a62c0" }, { "description": "Unauthorised access to a particular set of information / Unauthorised change or elimination of a particular set of information.", "expanded": "Information Security", "value": "information-security", "uuid": "99d78380-c384-5594-9794-70131828bebd" }, { "description": "Loss of property caused with fraudulent or dishonest intent of procuring, without right, an economic benefit for oneself or for another person.", "expanded": "Fraud", "value": "fraud", "uuid": "af6fce59-7d6d-583a-be71-32d1cdadf9b4" }, { "description": "Sending SPAM messages / Distribution and sharing of copyright protected content / Dissemination of content forbidden by law.", "expanded": "Abusive Content", "value": "abusive-content", "uuid": "d70c6dca-0fcc-5f75-bc66-96e6fe6ab152" }, { "description": "Incidents not classified in the existing classification.", "expanded": "Other", "value": "other", "uuid": "574941f1-089a-5d6d-b3ae-0cd79575b661" } ], "version": 3, "description": "Common Taxonomy for Law enforcement and CSIRTs", "refs": [ "https://www.europol.europa.eu/publications-documents/common-taxonomy-for-law-enforcement-and-csirts", "https://www.enisa.europa.eu/publications/tools-and-methodologies-to-support-cooperation-between-csirts-and-law-enforcement" ], "namespace": "common-taxonomy", "uuid": "2b701288-6e91-5366-bc3e-f86c57dd233b" }