{ "namespace": "cycat", "expanded": " Universal Cybersecurity Resource Catalogue", "description": "Taxonomy used by CyCAT, the Universal Cybersecurity Resource Catalogue, to categorize the namespaces it supports and uses.", "version": 1, "refs": [ "https://www.cycat.org/" ], "values": [ { "predicate": "type", "entry": [ { "value": "tool", "expanded": "Tool", "description": "Open source or proprietary tool used in cybersecurity.", "uuid": "dcab6726-083d-5c5a-9f9e-aa547ab54f58" }, { "value": "playbook", "expanded": "Playbook", "description": "Playbook, such as a defined set of rules with one or more actions triggered by different events to respond to, orchestrate or automate cybersecurity related actions.", "uuid": "4f0e6308-fc6d-59ff-bbd9-77904eca9eee" }, { "value": "taxonomy", "expanded": "Taxonomy", "description": "Cybersecurity taxonomy is a set of labels used to classify (in both terms - arrange in classes or/and design to national classification) cybersecurity related information.", "uuid": "284be36b-b773-577f-b5d9-9c71fbe8f3a4" }, { "value": "rule", "expanded": "Rule", "description": "Detection rule or set of detection rules used in the cybersecurity field. Rulesets can be in different formats for (N/L)IDS/SIEM (such as Snort, Suricata, Zeek, SIGMA or YARA) or any other tool capable of parsing them.", "uuid": "1b84f22e-a0f5-5f32-b60d-6f3be814065b" }, { "value": "notebook", "expanded": "Notebook", "description": "Interactive document to code, experiment, train or visualize cybersecurity-related information. A notebook can be transcribed in a format such as Jupyter Notebooks, Apache Zeppelin, Pluton or Google Colab.", "uuid": "d6060b53-85b4-5bfe-9c48-1cb101334582" }, { "value": "vulnerability", "expanded": "Vulnerability", "description": "Public or non-public information about a security vulnerability in a specific software, hardware or service.", "uuid": "84984736-440e-5bf4-a074-d222a4fd9a6e" }, { "value": "proof-of-concept", "expanded": "Proof-of-concept", "description": "Code to validate a known vulnerability.", "uuid": "6f837823-9fb2-5d11-b56f-3ff66cb198c3" }, { "value": "fingerprint", "expanded": "Fingerprint", "description": "Code to uniquely identify specific cybersecurity-relevant patterns. Fingerprints can be expressed in different formats such as ja3, ja3s, hassh, jarm or favicon-mmh3.", "uuid": "af45eb9f-b749-50c7-b10a-d53e331e239b" }, { "value": "mitigation", "expanded": "Mitigation", "description": "Mitigating control to prevent unwanted activity from happening, like a specific configuration of the operating system/tools or an implementation policy.", "uuid": "ea180f1d-c4c2-594a-8e4e-693048073a60" }, { "value": "dataset", "expanded": "Dataset", "description": "Dataset for validation of detections and tool stacks,", "uuid": "107134a3-daee-5ba0-86ba-9e56d40f5ef4" } ] }, { "predicate": "scope", "entry": [ { "value": "identify", "expanded": "Identify", "uuid": "b48e3036-d837-512b-ad7c-58a8d8bd4598" }, { "value": "protect", "expanded": "Protect", "uuid": "d8e70b67-3788-506b-874a-ea7d9c5fddde" }, { "value": "detect", "expanded": "Detect", "uuid": "c6ed4bef-2bb6-5b73-893a-8ce41334393b" }, { "value": "respond", "expanded": "Respond", "uuid": "a302d8ac-1bba-539c-8818-9ef83dd4e411" }, { "value": "recover", "expanded": "Recover", "uuid": "bfd6bcea-ffca-537a-a136-ba943ce8011a" }, { "value": "exploit", "expanded": "Exploit", "uuid": "a943de57-eb70-5b6a-99fb-201b9a44718c" }, { "value": "investigate", "expanded": "Investigate", "uuid": "fae742a8-e4c1-536b-91eb-6cf2bf652171" }, { "value": "train", "expanded": "Train", "uuid": "54e3fcd3-b5be-5352-8057-50eacd6d0d3a" }, { "value": "test", "expanded": "Test", "uuid": "64f31800-47aa-5732-b1d8-d58a970fead4" } ] } ], "predicates": [ { "value": "type", "expanded": "Type", "description": "Type of entry in the catalogue.", "uuid": "e0358f1b-d177-5ff5-baa0-ff962ca3ef3d" }, { "value": "scope", "expanded": "Scope", "description": "Scope of usage for the entry in the catalogue.", "uuid": "2aaff7c4-1b93-582f-ac37-94168503f048" } ], "uuid": "0a4ed543-b2b9-5748-8418-7cf2a6796e38" }