{
"$schema": "http://json-schema.org/draft-04/schema#",
"additionalProperties": false,
"description": "VERIS Community Schema 1.4.1.",
"properties": {
"incident_id": {
"type": "string",
"description": "More Info"
},
"security_incident": {
"type": "string",
"description": "Confirmed incident?",
"enum": [
"Confirmed",
"Suspected",
"Near miss",
"False positive"
]
},
"reference": {
"type": "string",
"description": "Reference should be a url, incident number, case ID, or other reference to the document the VERIS incident was based on."
},
"summary": {
"type": "string",
"description": "Give a good descriptive summary of the incident in several sentences. Use natural language instead of VERIS notation, but we should be able to 'VERISize' the incident pretty well from just this description.
**REMINDER: IF THIS IS FOR THE DBIR AND NOT VCDB - DON'T RECORD VICTIM-INDENTIFYING INFO**"
},
"source_id": {
"type": "string",
"description": "Source of the data (eg vcdb, vzir, hr dept)"
},
"campaign_id": {
"type": "string",
"description": "(Way to associate multiple incident w/in one campaign)."
},
"confidence": {
"type": "string",
"enum": [
"High",
"Medium",
"Low",
"None"
]
},
"timeline": {
"additionalProperties": false,
"properties": {
"incident": {
"description": "When did this incident initially occur?",
"additionalProperties": false,
"properties": {
"year": {
"type": "integer",
"maximum": 2050,
"minimum": 1950
},
"month": {
"type": "integer",
"maximum": 12,
"minimum": 1
},
"day": {
"type": "integer",
"maximum": 31,
"minimum": 1
},
"time": {
"description": "Use the format '05:45:00 PM'",
"type": "string",
"pattern": "^0[1-9]|1[0-2]:[0-5][0-9]:[0-5][0-9] [AP]M$"
}
},
"required": [
"year"
],
"type": "object"
},
"compromise": {
"description": "How long from the first action to the first compromise of an attribute?",
"additionalProperties": false,
"properties": {
"unit": {
"type": "string",
"enum": [
"Seconds",
"Minutes",
"Hours",
"Days",
"Weeks",
"Months",
"Years",
"Never",
"NA",
"Unknown"
]
},
"value": {
"type": "number"
}
},
"required": [
"unit"
],
"type": "object"
},
"exfiltration": {
"description": "How long from initial compromise to first known data exfiltration?",
"additionalProperties": false,
"properties": {
"unit": {
"type": "string",
"enum": [
"Seconds",
"Minutes",
"Hours",
"Days",
"Weeks",
"Months",
"Years",
"Never",
"NA",
"Unknown"
]
},
"value": {
"type": "number"
}
},
"required": [
"unit"
],
"type": "object"
},
"discovery": {
"description": "How long from compromise until the incident was discovered by the victim organization?",
"additionalProperties": false,
"properties": {
"unit": {
"type": "string",
"enum": [
"Seconds",
"Minutes",
"Hours",
"Days",
"Weeks",
"Months",
"Years",
"Never",
"NA",
"Unknown"
]
},
"value": {
"type": "number"
}
},
"required": [
"unit"
],
"type": "object"
},
"containment": {
"description": "How long did it take the organization to contain the incident once it was discovered?",
"additionalProperties": false,
"properties": {
"unit": {
"type": "string",
"enum": [
"Seconds",
"Minutes",
"Hours",
"Days",
"Weeks",
"Months",
"Years",
"Never",
"NA",
"Unknown"
]
},
"value": {
"type": "number"
}
},
"required": [
"unit"
],
"type": "object"
}
},
"required": [
"incident"
],
"type": "object"
},
"victim": {
"description": "More Info. **REMINDER - UNLESS THIS IS A VCDB INCIDENT, DON'T RECORD VICTIM-IDENTIFYING INFO IN ANY INCIDENT TO BE SUBMITTED TO THE DBIR**",
"additionalProperties": false,
"properties": {
"victim_id": {
"type": "string"
},
"employee_count": {
"description": "Number of employees. Only use the count of the individual instance of a business (e.g. franchise location vs entire company) if the action vector was explicitly something unique to this individual instance. (i.e. This franchisee used a non-standard POS system that was then compromised.)",
"type": "string",
"enum": [
"Small",
"1 to 10",
"11 to 100",
"101 to 1000",
"Large",
"1001 to 10000",
"10001 to 25000",
"25001 to 50000",
"50001 to 100000",
"Over 100000",
"Unknown"
]
},
"industry": {
"description": "Victim NAICS Code. You can look it up here or here.",
"maxLength": 6,
"minLength": 2,
"pattern": "(00|11|2[1-3]|3[1-3]|4[24589]|5[1-6]|6[1-2]|7[12]|81|92)-?\\d{0,4}",
"type": "string"
},
"government": {
"description": "The level of government if industry starts with 92. Otherwise 'NA'",
"items": {
"type": "string",
"default": "NA",
"enum": [
"Federal",
"Regional",
"Local",
"Unknown",
"Other",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"locations_affected": {
"description": "The number of victim locations, (stores, offices, etc), affected",
"type": "integer"
},
"country": {
"description": "Victim country of operation",
"items": {
"type": "string",
"default": "Unknown",
"enum": [
"Unknown",
"AD",
"AE",
"AF",
"AG",
"AI",
"AL",
"AM",
"AO",
"AQ",
"AR",
"AS",
"AT",
"AU",
"AW",
"AX",
"AZ",
"BA",
"BB",
"BD",
"BE",
"BF",
"BG",
"BH",
"BI",
"BJ",
"BL",
"BM",
"BN",
"BO",
"BQ",
"BR",
"BS",
"BT",
"BV",
"BW",
"BY",
"BZ",
"CA",
"CC",
"CD",
"CF",
"CG",
"CH",
"CI",
"CK",
"CL",
"CM",
"CN",
"CO",
"CR",
"CU",
"CV",
"CW",
"CX",
"CY",
"CZ",
"DE",
"DJ",
"DK",
"DM",
"DO",
"DZ",
"EC",
"EE",
"EG",
"EH",
"ER",
"ES",
"ET",
"FI",
"FJ",
"FK",
"FM",
"FO",
"FR",
"GA",
"GB",
"GD",
"GE",
"GF",
"GG",
"GH",
"GI",
"GL",
"GM",
"GN",
"GP",
"GQ",
"GR",
"GS",
"GT",
"GU",
"GW",
"GY",
"HK",
"HM",
"HN",
"HR",
"HT",
"HU",
"ID",
"IE",
"IL",
"IM",
"IN",
"IO",
"IQ",
"IR",
"IS",
"IT",
"JE",
"JM",
"JO",
"JP",
"KE",
"KG",
"KH",
"KI",
"KM",
"KN",
"KP",
"KR",
"KW",
"KY",
"KZ",
"LA",
"LB",
"LC",
"LI",
"LK",
"LR",
"LS",
"LT",
"LU",
"LV",
"LY",
"MA",
"MC",
"MD",
"ME",
"MF",
"MG",
"MH",
"MK",
"ML",
"MM",
"MN",
"MO",
"MP",
"MQ",
"MR",
"MS",
"MT",
"MU",
"MV",
"MW",
"MX",
"MY",
"MZ",
"NA",
"NC",
"NE",
"NF",
"NG",
"NI",
"NL",
"NO",
"NP",
"NR",
"NU",
"NZ",
"OM",
"PA",
"PE",
"PF",
"PG",
"PH",
"PK",
"PL",
"PM",
"PN",
"PR",
"PS",
"PT",
"PW",
"PY",
"QA",
"RE",
"RO",
"RS",
"RU",
"RW",
"SA",
"SB",
"SC",
"SD",
"SE",
"SG",
"SH",
"SI",
"SJ",
"SK",
"SL",
"SM",
"SN",
"SO",
"SR",
"SS",
"ST",
"SV",
"SX",
"SY",
"SZ",
"TC",
"TD",
"TF",
"TG",
"TH",
"TJ",
"TK",
"TL",
"TM",
"TN",
"TO",
"TR",
"TT",
"TV",
"TW",
"TZ",
"UA",
"UG",
"UM",
"US",
"UY",
"UZ",
"VA",
"VC",
"VE",
"VG",
"VI",
"VN",
"VU",
"WF",
"WS",
"YE",
"YT",
"ZA",
"ZM",
"ZW",
"XK",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"region": {
"description": "The UN M.49 super-region and sub-region joined together. e.g. North America: 019021. South America (Brazil): 019005, Asia: 142000, East Asia (includes China): 142030, West Asia (Middle East): 142145, South Asia (India): 142034, Eastern Europe: 150151, Western Europe: 150155. Use 000000 if you do not know and 000001 for 'other' (includes international waters and outer space). If you only know the super-region, use zero's for the region. (e.g. 019000 for Americas.)",
"items": {
"type": "string",
"maxLength": 6,
"minLength": 6,
"pattern": "\\d{6}"
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"state": {
"description": "ALL CAPS. For US states, you can use the ISO_3166-2 2-character state code, otherwise use the full ISO_3166-2 Country subdivision code",
"type": "string"
},
"notes": {
"description": "**UNLESS THIS IS FOR VCDB, DON'T RECORD VICTIM-INDENTIFYING INFO IF THIS WILL BE SUBMITTED TO THE DBIR**",
"minLength": 1,
"type": "string"
},
"secondary": {
"description": "Secondary victims indicates that the breach being coded is the first part of a supply chain breach.",
"additionalProperties": false,
"minProperties": 1,
"properties": {
"amount": {
"definition": "The number of known secondary victims. Should always be a positive number if victim_id is filled in. May not represent all victims if some are unknown.",
"type": "integer"
},
"notes": {
"minLength": 1,
"type": "string"
},
"victim_id": {
"description": "List any secondary victims here. IF a NAICS is known, list the NAICS code after a semi-colon. For example: `verizon;517911`. If only the NAICS code is known, list it first. `;517911`",
"items": {
"type": "string"
},
"minItems": 1,
"type": "array"
}
},
"type": "object"
},
"revenue": {
"description": "For the DBIR, this is a low priority field and is OK to not fill in.",
"additionalProperties": false,
"minProperties": 1,
"properties": {
"amount": {
"type": "integer"
},
"iso_currency_code": {
"description": "ISO4217 currency code. More Info",
"type": "string",
"enum": [
"AED",
"AFN",
"ALL",
"AMD",
"ANG",
"AOA",
"ARS",
"AUD",
"AWG",
"AZN",
"BAM",
"BBD",
"BDT",
"BGN",
"BHD",
"BIF",
"BMD",
"BND",
"BOB",
"BRL",
"BSD",
"BTN",
"BWP",
"BYR",
"BZD",
"CAD",
"CDF",
"CHF",
"CLP",
"CNY",
"COP",
"CRC",
"CUC",
"CUP",
"CVE",
"CZK",
"DJF",
"DKK",
"DOP",
"DZD",
"EGP",
"ERN",
"ETB",
"EUR",
"FJD",
"FKP",
"GBP",
"GEL",
"GGP",
"GHS",
"GIP",
"GMD",
"GNF",
"GTQ",
"GYD",
"HKD",
"HNL",
"HRK",
"HTG",
"HUF",
"IDR",
"ILS",
"IMP",
"INR",
"IQD",
"IRR",
"ISK",
"JEP",
"JMD",
"JOD",
"JPY",
"KES",
"KGS",
"KHR",
"KMF",
"KPW",
"KRW",
"KWD",
"KYD",
"KZT",
"LAK",
"LBP",
"LKR",
"LRD",
"LSL",
"LTL",
"LVL",
"LYD",
"MAD",
"MDL",
"MGA",
"MKD",
"MMK",
"MNT",
"MOP",
"MRO",
"MUR",
"MVR",
"MWK",
"MXN",
"MYR",
"MZN",
"NAD",
"NGN",
"NIO",
"NOK",
"NPR",
"NZD",
"OMR",
"PAB",
"PEN",
"PGK",
"PHP",
"PKR",
"PLN",
"PYG",
"QAR",
"RON",
"RSD",
"RUB",
"RWF",
"SAR",
"SBD",
"SCR",
"SDG",
"SEK",
"SGD",
"SHP",
"SLL",
"SOS",
"SPL",
"SRD",
"STD",
"SVC",
"SYP",
"SZL",
"THB",
"TJS",
"TMT",
"TND",
"TOP",
"TRY",
"TTD",
"TVD",
"TWD",
"TZS",
"UAH",
"UGX",
"USD",
"UYU",
"UZS",
"VEF",
"VND",
"VUV",
"WST",
"XAF",
"XCD",
"XDR",
"XOF",
"XPF",
"YER",
"ZAR",
"ZMK",
"ZWD",
"XBT",
"BCH",
"Ether",
"Litecoin",
"XMR",
"ZEC"
]
}
},
"type": "object"
}
},
"required": [
"country",
"employee_count",
"industry",
"government"
],
"type": "object"
},
"action": {
"description": "What threat actions were involved? More Info",
"minProperties": 1,
"additionalProperties": false,
"properties": {
"hacking": {
"description": "Think things a person does at a keyboard (rather than by a program). More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Abuse of functionality",
"Backdoor",
"Brute force",
"Buffer overflow",
"Cache poisoning",
"Cryptanalysis",
"CSRF",
"Disable controls",
"DoS",
"Evade Defenses",
"Exploit misconfig",
"Exploit vuln",
"Forced browsing",
"Format string attack",
"Fuzz testing",
"Hijack",
"HTTP request smuggling",
"HTTP request splitting",
"HTTP response smuggling",
"HTTP response splitting",
"Insecure deserialization",
"Integer overflows",
"LDAP injection",
"Mail command injection",
"AitM",
"Null byte injection",
"Offline cracking",
"OS commanding",
"Pass-the-hash",
"Path traversal",
"Profile host",
"Prompt injection",
"Reverse engineering",
"RFI",
"Routing detour",
"Scan network",
"Session fixation",
"Session prediction",
"Session replay",
"Soap array abuse",
"Special element injection",
"SQLi",
"SSI injection",
"URL redirector abuse",
"Use of stolen creds",
"User breakout",
"Virtual machine escape",
"XML attribute blowup",
"XML entity expansion",
"XML external entities",
"XML injection",
"XPath injection",
"XQuery injection",
"XSS",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"vector": {
"items": {
"type": "string",
"enum": [
"3rd party desktop",
"Backdoor",
"Command shell",
"Desktop sharing",
"Desktop sharing software",
"Hypervisor",
"Inter-tenant",
"Other network service",
"Partner",
"Physical access",
"VPN",
"Web application",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string",
"enum": [
"Infiltrate",
"Exfiltrate",
"Elevate",
"Lateral movement",
"Deploy payload",
"Persist",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"cve": {
"description": "CVE(s) exploited through hacking",
"type": "string"
}
},
"required": [
"vector",
"variety"
],
"type": "object"
},
"malware": {
"description": "Think things a program does (rather than a person on a keyboard) More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Adminware",
"Adware",
"Backdoor",
"Backdoor or C2",
"Brute force",
"C2",
"Capture app data",
"Capture stored data",
"Click fraud",
"Click fraud and cryptocurrency mining",
"Client-side attack",
"Cryptocurrency mining",
"Destroy data",
"In-memory",
"AitM",
"Modify data",
"Disable controls",
"DoS",
"Downloader",
"Exploit misconfig",
"Evade Defenses",
"Exploit vuln",
"Export data",
"Packet sniffer",
"Pass-the-hash",
"Password dumper",
"Profile host",
"RAM scraper",
"Ransomware",
"RAT",
"Rootkit",
"Scan network",
"Spam",
"Spyware/Keylogger",
"Trojan",
"Worm",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"vector": {
"items": {
"type": "string",
"enum": [
"C2",
"Direct install",
"Download by malware",
"Email",
"Email attachment",
"Email autoexecute",
"Email link",
"Email unknown",
"Email other",
"Instant messaging",
"Network propagation",
"Partner",
"Remote injection",
"Removable media",
"Software update",
"Web application",
"Web application - download",
"Web application - drive-by",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string",
"enum": [
"Infiltrate",
"Exfiltrate",
"Elevate",
"Lateral movement",
"Deploy payload",
"Persist",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"name": {
"description": "Common name(s) or strain(s) of malware",
"type": "string"
},
"cve": {
"description": "CVE(s) exploited by this malware",
"type": "string"
}
},
"required": [
"vector",
"variety"
],
"type": "object"
},
"social": {
"description": "Actions done to a person. More Info",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varities of social tactics",
"items": {
"type": "string",
"enum": [
"Baiting",
"Bribery",
"Elicitation",
"Evade Defenses",
"Extortion",
"Forgery",
"Influence",
"Phishing",
"Pretexting",
"Prompt bombing",
"Propaganda",
"Scam",
"Spam",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"vector": {
"description": "Vectors of communication",
"items": {
"type": "string",
"enum": [
"Documents",
"Email",
"IM",
"In-person",
"Partner",
"Phone",
"Removable media",
"SMS",
"Social media",
"Software",
"Virtual meeting",
"Web application",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"target": {
"description": "Target of social tactics",
"items": {
"type": "string",
"enum": [
"Auditor",
"Call center",
"Cashier",
"Customer",
"Developer",
"End-user",
"End-user or employee",
"Executive",
"Finance",
"Former employee",
"Guard",
"Helpdesk",
"Human resources",
"Maintenance",
"Manager",
"Other employee",
"Partner",
"System admin",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string",
"enum": [
"Infiltrate",
"Exfiltrate",
"Elevate",
"Lateral movement",
"Deploy payload",
"Persist",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"required": [
"vector",
"variety",
"target"
],
"type": "object"
},
"error": {
"description": "Unintentional actions. More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Capacity shortage",
"Classification error",
"Data entry error",
"Disposal error",
"Gaffe",
"Loss",
"Maintenance error",
"Malfunction",
"Misconfiguration",
"Misdelivery",
"Misinformation",
"Physical accidents",
"Programming error",
"Publishing error",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"vector": {
"description": "Reasons errors occurred",
"items": {
"type": "string",
"enum": [
"Carelessness",
"Inadequate personnel",
"Inadequate processes",
"Inadequate technology",
"Other",
"Random error",
"Web application",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety",
"vector"
],
"type": "object"
},
"misuse": {
"description": "Unapproved use of legitimate access or permissions. More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Data mishandling",
"Email misuse",
"Evade Defenses",
"Illicit content",
"Knowledge abuse",
"Net misuse",
"Password or Session Sharing",
"Possession abuse",
"Privilege abuse",
"Snap picture",
"Unapproved hardware",
"Unapproved software",
"Unapproved workaround",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"vector": {
"description": "Vectors or access methods",
"items": {
"type": "string",
"enum": [
"LAN access",
"Non-corporate",
"Physical access",
"Remote access",
"Web application",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string",
"enum": [
"Infiltrate",
"Exfiltrate",
"Elevate",
"Lateral movement",
"Deploy payload",
"Persist",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"required": [
"vector",
"variety"
],
"type": "object"
},
"physical": {
"description": "Actions involving proximity and physical contact. More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Assault",
"Bypassed controls",
"Connection",
"Destruction",
"Disabled controls",
"Evade Defenses",
"Skimmer",
"Snooping",
"Surveillance",
"Tampering",
"Theft",
"Wiretapping",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"vector": {
"description": "Vector of physical access",
"items": {
"type": "string",
"enum": [
"Partner facility",
"Partner vehicle",
"Personal residence",
"Personal vehicle",
"Public facility",
"Public vehicle",
"Victim grounds",
"Victim public area",
"Victim secure area",
"Victim work area",
"Unknown",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string",
"enum": [
"Infiltrate",
"Exfiltrate",
"Elevate",
"Lateral movement",
"Deploy payload",
"Persist",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"required": [
"vector",
"variety"
],
"type": "object"
},
"environmental": {
"description": "Forces of nature. Cannot include intentional actions. More Info",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of environmental events",
"items": {
"type": "string",
"enum": [
"Deterioration",
"Earthquake",
"EMI",
"ESD",
"Fire",
"Flood",
"Hazmat",
"Humidity",
"Hurricane",
"Ice",
"Landslide",
"Leak",
"Lightning",
"Meteorite",
"Particulates",
"Pathogen",
"Power failure",
"Temperature",
"Tornado",
"Tsunami",
"Vermin",
"Volcano",
"Wind",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"unknown": {
"description": "The action taken was unknown",
"properties": {
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string",
"enum": [
"Infiltrate",
"Exfiltrate",
"Elevate",
"Lateral movement",
"Deploy payload",
"Persist",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"type": "object"
}
},
"type": "object"
},
"actor": {
"description": "What entity did the threat action? More Info",
"additionalProperties": false,
"minProperties": 1,
"properties": {
"external": {
"description": "Unaffiliated with the victim. More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Acquaintance",
"Activist",
"Auditor",
"Competitor",
"Customer",
"Force majeure",
"Former employee",
"Nation-state",
"Organized crime",
"State-affiliated",
"Terrorist",
"Unaffiliated",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"motive": {
"items": {
"type": "string",
"enum": [
"Convenience",
"Espionage",
"Fear",
"Financial",
"Fun",
"Grudge",
"Ideology",
"NA",
"Secondary",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"description": "Misc external actor notes",
"minLength": 1,
"type": "string"
},
"country": {
"items": {
"type": "string",
"enum": [
"Unknown",
"AD",
"AE",
"AF",
"AG",
"AI",
"AL",
"AM",
"AO",
"AQ",
"AR",
"AS",
"AT",
"AU",
"AW",
"AX",
"AZ",
"BA",
"BB",
"BD",
"BE",
"BF",
"BG",
"BH",
"BI",
"BJ",
"BL",
"BM",
"BN",
"BO",
"BQ",
"BR",
"BS",
"BT",
"BV",
"BW",
"BY",
"BZ",
"CA",
"CC",
"CD",
"CF",
"CG",
"CH",
"CI",
"CK",
"CL",
"CM",
"CN",
"CO",
"CR",
"CU",
"CV",
"CW",
"CX",
"CY",
"CZ",
"DE",
"DJ",
"DK",
"DM",
"DO",
"DZ",
"EC",
"EE",
"EG",
"EH",
"ER",
"ES",
"ET",
"FI",
"FJ",
"FK",
"FM",
"FO",
"FR",
"GA",
"GB",
"GD",
"GE",
"GF",
"GG",
"GH",
"GI",
"GL",
"GM",
"GN",
"GP",
"GQ",
"GR",
"GS",
"GT",
"GU",
"GW",
"GY",
"HK",
"HM",
"HN",
"HR",
"HT",
"HU",
"ID",
"IE",
"IL",
"IM",
"IN",
"IO",
"IQ",
"IR",
"IS",
"IT",
"JE",
"JM",
"JO",
"JP",
"KE",
"KG",
"KH",
"KI",
"KM",
"KN",
"KP",
"KR",
"KW",
"KY",
"KZ",
"LA",
"LB",
"LC",
"LI",
"LK",
"LR",
"LS",
"LT",
"LU",
"LV",
"LY",
"MA",
"MC",
"MD",
"ME",
"MF",
"MG",
"MH",
"MK",
"ML",
"MM",
"MN",
"MO",
"MP",
"MQ",
"MR",
"MS",
"MT",
"MU",
"MV",
"MW",
"MX",
"MY",
"MZ",
"NA",
"NC",
"NE",
"NF",
"NG",
"NI",
"NL",
"NO",
"NP",
"NR",
"NU",
"NZ",
"OM",
"PA",
"PE",
"PF",
"PG",
"PH",
"PK",
"PL",
"PM",
"PN",
"PR",
"PS",
"PT",
"PW",
"PY",
"QA",
"RE",
"RO",
"RS",
"RU",
"RW",
"SA",
"SB",
"SC",
"SD",
"SE",
"SG",
"SH",
"SI",
"SJ",
"SK",
"SL",
"SM",
"SN",
"SO",
"SR",
"SS",
"ST",
"SV",
"SX",
"SY",
"SZ",
"TC",
"TD",
"TF",
"TG",
"TH",
"TJ",
"TK",
"TL",
"TM",
"TN",
"TO",
"TR",
"TT",
"TV",
"TW",
"TZ",
"UA",
"UG",
"UM",
"US",
"UY",
"UZ",
"VA",
"VC",
"VE",
"VG",
"VI",
"VN",
"VU",
"WF",
"WS",
"YE",
"YT",
"ZA",
"ZM",
"ZW",
"XK",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"region": {
"description": "The UN M.49 super-region and sub-region joined together. e.g. North America: 019021. South America (Brazil): 019005, Asia: 142000, East Asia (includes China): 142030, West Asia (Middle East): 142145, South Asia (India): 142034, Eastern Europe: 150151, Western Europe: 150155. Use 000000 if you do not know and 000001 for 'other' (includes international waters and outer space). If you only know the super-region, use zero's for the region. (e.g. 019000 for Americas.)",
"items": {
"type": "string",
"maxLength": 6,
"minLength": 6,
"pattern": "\\d{6}"
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"name": {
"description": "Actor name (if known). e.g. 'lizard squad'",
"items": {
"type": "string"
},
"type": "array",
"uniqueItems": true
}
},
"required": [
"variety",
"motive"
],
"type": "object"
},
"internal": {
"description": "The victim or a part thereof (such as an employee). More Info. Unless it is an error or intentional breaking of rules (misuse), the actor MUST be acting maliciously.",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Auditor",
"Call center",
"Cashier",
"Developer",
"End-user",
"Executive",
"Finance",
"Guard",
"Helpdesk",
"Human resources",
"Maintenance",
"Manager",
"System admin",
"Doctor or nurse",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"motive": {
"items": {
"type": "string",
"enum": [
"Convenience",
"Espionage",
"Fear",
"Financial",
"Fun",
"Grudge",
"Ideology",
"Secondary",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"job_change": {
"description": "Recent job change PRIOR to incident? (i.e., not asking if 'let go' afterwards)",
"items": {
"type": "string",
"enum": [
"Demoted",
"Hired",
"Job eval",
"Lateral move",
"Let go",
"Passed over",
"Personal issues",
"Promoted",
"Reprimanded",
"Resigned",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"description": "Misc internal actor notes",
"minLength": 1,
"type": "string"
}
},
"required": [
"motive",
"variety"
],
"type": "object"
},
"partner": {
"description": "An entity with an organizational relationship to the victim, but not the victim (such as a customer or supplier). More Info",
"additionalProperties": false,
"properties": {
"motive": {
"items": {
"type": "string",
"enum": [
"Convenience",
"Espionage",
"Fear",
"Financial",
"Fun",
"Grudge",
"Ideology",
"Secondary",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"description": "Misc partner actor notes",
"minLength": 1,
"type": "string"
},
"industry": {
"maxLength": 6,
"minLength": 2,
"pattern": "\\d{2}-?\\d{0,4}",
"type": "string"
},
"country": {
"items": {
"type": "string",
"enum": [
"Unknown",
"AD",
"AE",
"AF",
"AG",
"AI",
"AL",
"AM",
"AO",
"AQ",
"AR",
"AS",
"AT",
"AU",
"AW",
"AX",
"AZ",
"BA",
"BB",
"BD",
"BE",
"BF",
"BG",
"BH",
"BI",
"BJ",
"BL",
"BM",
"BN",
"BO",
"BQ",
"BR",
"BS",
"BT",
"BV",
"BW",
"BY",
"BZ",
"CA",
"CC",
"CD",
"CF",
"CG",
"CH",
"CI",
"CK",
"CL",
"CM",
"CN",
"CO",
"CR",
"CU",
"CV",
"CW",
"CX",
"CY",
"CZ",
"DE",
"DJ",
"DK",
"DM",
"DO",
"DZ",
"EC",
"EE",
"EG",
"EH",
"ER",
"ES",
"ET",
"FI",
"FJ",
"FK",
"FM",
"FO",
"FR",
"GA",
"GB",
"GD",
"GE",
"GF",
"GG",
"GH",
"GI",
"GL",
"GM",
"GN",
"GP",
"GQ",
"GR",
"GS",
"GT",
"GU",
"GW",
"GY",
"HK",
"HM",
"HN",
"HR",
"HT",
"HU",
"ID",
"IE",
"IL",
"IM",
"IN",
"IO",
"IQ",
"IR",
"IS",
"IT",
"JE",
"JM",
"JO",
"JP",
"KE",
"KG",
"KH",
"KI",
"KM",
"KN",
"KP",
"KR",
"KW",
"KY",
"KZ",
"LA",
"LB",
"LC",
"LI",
"LK",
"LR",
"LS",
"LT",
"LU",
"LV",
"LY",
"MA",
"MC",
"MD",
"ME",
"MF",
"MG",
"MH",
"MK",
"ML",
"MM",
"MN",
"MO",
"MP",
"MQ",
"MR",
"MS",
"MT",
"MU",
"MV",
"MW",
"MX",
"MY",
"MZ",
"NA",
"NC",
"NE",
"NF",
"NG",
"NI",
"NL",
"NO",
"NP",
"NR",
"NU",
"NZ",
"OM",
"PA",
"PE",
"PF",
"PG",
"PH",
"PK",
"PL",
"PM",
"PN",
"PR",
"PS",
"PT",
"PW",
"PY",
"QA",
"RE",
"RO",
"RS",
"RU",
"RW",
"SA",
"SB",
"SC",
"SD",
"SE",
"SG",
"SH",
"SI",
"SJ",
"SK",
"SL",
"SM",
"SN",
"SO",
"SR",
"SS",
"ST",
"SV",
"SX",
"SY",
"SZ",
"TC",
"TD",
"TF",
"TG",
"TH",
"TJ",
"TK",
"TL",
"TM",
"TN",
"TO",
"TR",
"TT",
"TV",
"TW",
"TZ",
"UA",
"UG",
"UM",
"US",
"UY",
"UZ",
"VA",
"VC",
"VE",
"VG",
"VI",
"VN",
"VU",
"WF",
"WS",
"YE",
"YT",
"ZA",
"ZM",
"ZW",
"XK",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"region": {
"description": "The UN M.49 super-region and sub-region joined together. e.g. North America: 019021. South America (Brazil): 019005, Asia: 142000, East Asia (includes China): 142030, West Asia (Middle East): 142145, South Asia (India): 142034, Eastern Europe: 150151, Western Europe: 150155. Use 000000 if you do not know and 000001 for 'other' (includes international waters and outer space). If you only know the super-region, use zero's for the region. (e.g. 019000 for Americas.)",
"items": {
"type": "string",
"maxLength": 6,
"minLength": 6,
"pattern": "\\d{6}"
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"name": {
"items": {
"type": "string"
},
"type": "array",
"uniqueItems": true
}
},
"required": [
"country",
"motive"
],
"type": "object"
},
"unknown": {
"description": "If the actor is unknown, you *must* add a note of some type, otherwise the incident will not validate.",
"properties": {
"notes": {
"minLength": 1,
"type": "string"
}
},
"type": "object"
}
},
"type": "object"
},
"asset": {
"description": "What assets were affected by the incident actions. Data types and record count will be covered in the attributes section. More Info",
"additionalProperties": false,
"minProperties": 1,
"properties": {
"total_amount": {
"type": "number"
},
"assets": {
"items": {
"additionalProperties": false,
"properties": {
"variety": {
"description": "What varieties of assets were compromised?",
"type": "string",
"enum": [
"M - Disk drive",
"M - Disk media",
"M - Documents",
"M - Flash drive",
"M - Payment card",
"M - Smart card",
"M - SIM card",
"M - Tapes",
"M - Other",
"M - Unknown",
"M - Fax",
"N - Access reader",
"N - Broadband",
"N - Camera",
"N - Firewall",
"N - IDS",
"N - LAN",
"N - NAS",
"N - PBX",
"N - PLC",
"N - Private WAN",
"N - Public WAN",
"N - Remote access",
"N - Router or switch",
"N - RTU",
"N - SAN",
"N - Telephone",
"N - VoIP adapter",
"N - WLAN",
"N - Other",
"N - Unknown",
"P - Auditor",
"P - Call center",
"P - Cashier",
"P - Customer",
"P - Developer",
"P - End-user",
"P - End-user or employee",
"P - Executive",
"P - Finance",
"P - Former employee",
"P - Guard",
"P - Helpdesk",
"P - Human resources",
"P - Maintenance",
"P - Manager",
"P - Other employee",
"P - Partner",
"P - System admin",
"P - Other",
"P - Unknown",
"S - Authentication",
"S - Backup",
"S - Configuration or patch management",
"S - Code repository",
"S - Database",
"S - DCS",
"S - DHCP",
"S - Directory",
"S - DNS",
"S - File",
"S - ICS",
"S - LLM application",
"S - Log",
"S - Mail",
"S - Mainframe",
"S - Payment switch",
"S - POS controller",
"S - Print",
"S - Proxy",
"S - Secrets vault",
"S - VM host",
"S - Web application",
"S - Other",
"S - Unknown",
"T - ATM",
"T - Gas terminal",
"T - Kiosk",
"T - PED pad",
"T - Other",
"T - Unknown",
"U - Auth token",
"U - Desktop",
"U - Desktop or laptop",
"U - Laptop",
"U - Media",
"U - Mobile phone",
"U - Peripheral",
"U - POS terminal",
"U - Tablet",
"U - Telephone",
"U - VoIP phone",
"U - Other",
"U - Unknown",
"E - Telemetry",
"E - Telematics",
"E - Other",
"E - Unknown",
"Unknown",
"Other"
]
},
"amount": {
"description": "How many total systems were compromised?",
"type": "integer"
}
},
"required": [
"variety"
],
"type": "object"
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"ownership": {
"description": "Who owns the affected asset? This can allow us to identify employee-owned (BYOD) assets.",
"items": {
"type": "string",
"enum": [
"Customer",
"Employee",
"NA",
"Partner",
"Unknown",
"Victim",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"cloud": {
"description": "Only answer if you know for sure if the asset was hosted in a cloud service.",
"items": {
"type": "string",
"enum": [
"On-Premise Asset(s)",
"External Cloud Asset(s)",
"Other",
"Unknown",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"hosting": {
"description": "Where is the affected asset hosted/located?",
"items": {
"type": "string",
"enum": [
"External - unknown environment",
"External - dedicated environment",
"External - shared environment",
"Internal",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"management": {
"description": "Independent of physical location, who administers and maintains the affected asset?",
"items": {
"type": "string",
"enum": [
"External",
"Internal",
"Co-managed",
"NA",
"Unknown",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"role": {
"description": "Is the asset Information Technology (IT) such as email or the domain controller or Operational Technology (OT) such as rail-switching computers for a railroad or manufacturing robots for a manufacturing company.",
"items": {
"type": "string",
"enum": [
"IT",
"OT",
"Unknown",
"Other",
"NA"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
},
"country": {
"description": "The country hosting the asset.",
"items": {
"type": "string",
"enum": [
"Unknown",
"AD",
"AE",
"AF",
"AG",
"AI",
"AL",
"AM",
"AO",
"AQ",
"AR",
"AS",
"AT",
"AU",
"AW",
"AX",
"AZ",
"BA",
"BB",
"BD",
"BE",
"BF",
"BG",
"BH",
"BI",
"BJ",
"BL",
"BM",
"BN",
"BO",
"BQ",
"BR",
"BS",
"BT",
"BV",
"BW",
"BY",
"BZ",
"CA",
"CC",
"CD",
"CF",
"CG",
"CH",
"CI",
"CK",
"CL",
"CM",
"CN",
"CO",
"CR",
"CU",
"CV",
"CW",
"CX",
"CY",
"CZ",
"DE",
"DJ",
"DK",
"DM",
"DO",
"DZ",
"EC",
"EE",
"EG",
"EH",
"ER",
"ES",
"ET",
"FI",
"FJ",
"FK",
"FM",
"FO",
"FR",
"GA",
"GB",
"GD",
"GE",
"GF",
"GG",
"GH",
"GI",
"GL",
"GM",
"GN",
"GP",
"GQ",
"GR",
"GS",
"GT",
"GU",
"GW",
"GY",
"HK",
"HM",
"HN",
"HR",
"HT",
"HU",
"ID",
"IE",
"IL",
"IM",
"IN",
"IO",
"IQ",
"IR",
"IS",
"IT",
"JE",
"JM",
"JO",
"JP",
"KE",
"KG",
"KH",
"KI",
"KM",
"KN",
"KP",
"KR",
"KW",
"KY",
"KZ",
"LA",
"LB",
"LC",
"LI",
"LK",
"LR",
"LS",
"LT",
"LU",
"LV",
"LY",
"MA",
"MC",
"MD",
"ME",
"MF",
"MG",
"MH",
"MK",
"ML",
"MM",
"MN",
"MO",
"MP",
"MQ",
"MR",
"MS",
"MT",
"MU",
"MV",
"MW",
"MX",
"MY",
"MZ",
"NA",
"NC",
"NE",
"NF",
"NG",
"NI",
"NL",
"NO",
"NP",
"NR",
"NU",
"NZ",
"OM",
"PA",
"PE",
"PF",
"PG",
"PH",
"PK",
"PL",
"PM",
"PN",
"PR",
"PS",
"PT",
"PW",
"PY",
"QA",
"RE",
"RO",
"RS",
"RU",
"RW",
"SA",
"SB",
"SC",
"SD",
"SE",
"SG",
"SH",
"SI",
"SJ",
"SK",
"SL",
"SM",
"SN",
"SO",
"SR",
"SS",
"ST",
"SV",
"SX",
"SY",
"SZ",
"TC",
"TD",
"TF",
"TG",
"TH",
"TJ",
"TK",
"TL",
"TM",
"TN",
"TO",
"TR",
"TT",
"TV",
"TW",
"TZ",
"UA",
"UG",
"UM",
"US",
"UY",
"UZ",
"VA",
"VC",
"VE",
"VG",
"VI",
"VN",
"VU",
"WF",
"WS",
"YE",
"YT",
"ZA",
"ZM",
"ZW",
"XK",
"Other"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"type": "object",
"required": [
"assets",
"cloud"
]
},
"attribute": {
"description": "What attributes were compromised? More Info",
"additionalProperties": false,
"minProperties": 1,
"properties": {
"confidentiality": {
"description": "Was data (potentially) disclosed to an unauthorized party? More Info",
"additionalProperties": false,
"properties": {
"data_disclosure": {
"description": "Was data disclosed? This is the core determiner if this incident is a breach. If this is 'Yes', it will be considered a breach. If it is anything else, it will only be an incident.",
"type": "string",
"enum": [
"No",
"Potentially",
"Yes",
"Unknown"
]
},
"data_total": {
"description": "Total records breached",
"type": "integer"
},
"data_volume": {
"description": "Amount of data breached in volume (GB)",
"type": "integer"
},
"data": {
"description": "Varieties (and amount) of data compromised. Click the red \u2018Add\u2019 button to record multiple data varieties.",
"items": {
"additionalProperties": false,
"properties": {
"amount": {
"type": "integer"
},
"variety": {
"type": "string",
"enum": [
"API key",
"Bank",
"Classified",
"Copyrighted",
"Credentials",
"Digital certificate",
"Internal",
"Medical",
"Multi-factor credential",
"Payment",
"Personal",
"Sensitive Personal",
"Secrets",
"Session key",
"Source code",
"System",
"Virtual currency",
"Other",
"Unknown"
]
}
},
"required": [
"variety"
],
"type": "object"
},
"minItems": 1,
"type": "array"
},
"data_victim": {
"items": {
"type": "string",
"enum": [
"Customer",
"Employee",
"Partner",
"Patient",
"Student",
"Victim organization",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"state": {
"items": {
"type": "string",
"enum": [
"Processed",
"Stored",
"Stored encrypted",
"Stored unencrypted",
"Transmitted",
"Transmitted encrypted",
"Transmitted unencrypted",
"Other",
"Unknown",
"Printed"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"data_disclosure"
],
"type": "object"
},
"integrity": {
"description": "Was a person manipulated or the state of a system changed? More Info",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Alter behavior",
"Created account",
"Defacement",
"Fraudulent transaction",
"Hardware tampering",
"Log tampering",
"Misrepresentation",
"Modify authentication",
"Modify configuration",
"Modify data",
"Modify privileges",
"Register MFA device",
"Repurpose",
"Software installation",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"availability": {
"description": "Was something rendered partially or wholly unavailable? More Info",
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Acceleration",
"Degradation",
"Destruction",
"Interruption",
"Loss",
"Obscuration",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"duration": {
"description": "Specific value of the specific selected unit, (i.e., # of 'days').",
"additionalProperties": false,
"properties": {
"unit": {
"type": "string",
"enum": [
"Seconds",
"Minutes",
"Hours",
"Days",
"Weeks",
"Months",
"Years",
"Never",
"NA",
"Unknown"
]
},
"value": {
"type": "number"
}
},
"required": [
"unit"
],
"type": "object"
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"unknown": {
"properties": {
"notes": {
"minLength": 1,
"type": "string"
},
"result": {
"description": "The result of the action. If there's a difference between action result and actor intent, use the result not intent.",
"items": {
"type": "string"
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"type": "object"
}
},
"type": "object"
},
"targeted": {
"description": "Was this a targeted or opportunistic attack? More Info
N/A: Not an attack (e.g., unintentional actions)
Opportunistic: Victim was NOT pre-selected as a target; they were identified/attacked because they exhibited a weakness the attacker knew how to exploit.
Targeted: The victim is pre-selected as a target; the attacker(s) then determined what weaknesses exist within the target that could be exploited.",
"type": "string",
"enum": [
"Opportunistic",
"Targeted",
"NA",
"Unknown"
]
},
"discovery_method": {
"description": "What discovery method was involved? More Info",
"minProperties": 1,
"additionalProperties": false,
"properties": {
"external": {
"description": "Discovered by an external entity.",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Actor disclosure",
"Audit",
"Customer",
"Emergency response team",
"Found documents",
"Fraud detection",
"Incident response",
"Law enforcement",
"Security researcher",
"Suspicious traffic",
"Unrelated 3rd party",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"required": [
"variety"
],
"type": "object"
},
"internal": {
"description": "Discovered by entity within the victim organization.",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Antivirus",
"Break in discovered",
"Data loss prevention",
"Financial audit",
"Fraud detection",
"Hids",
"Incident response",
"Infrastructure monitoring",
"It review",
"Log review",
"Nids",
"Offboarding",
"Reported by employee",
"Security alarm",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"required": [
"variety"
],
"type": "object"
},
"partner": {
"description": "Discovered by a partner of the victim.",
"additionalProperties": false,
"properties": {
"variety": {
"items": {
"type": "string",
"enum": [
"Antivirus",
"Audit",
"Incident response",
"Monitoring service",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
}
},
"required": [
"variety"
],
"type": "object"
},
"other": {
"type": "boolean"
},
"unknown": {
"type": "boolean"
}
},
"type": "object"
},
"discovery_notes": {
"description": "How was the incident discovered? More Info",
"minLength": 1,
"type": "string"
},
"value_chain": {
"description": "Capabilities and investments an attacker must acquire prior to the actions on target, (either by purchase or investment in creating). May be internal to the actors organization (vertically integrated org), or external (purchased in a criminal market).",
"minProperties": 1,
"additionalProperties": false,
"properties": {
"development": {
"description": "Software that must be developed to accomplish the actions on target.",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of development investments",
"items": {
"type": "string",
"enum": [
"Bot",
"Email",
"Exploit",
"Exploit Kits",
"Payload",
"Persona",
"Physical",
"Ransomware",
"Trojan",
"Website",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"non-distribution services": {
"description": "Services provided and used by malicious actors other than those used for distribution of actor content",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of non-distribution service investments",
"items": {
"type": "string",
"enum": [
"C2",
"Counter AV",
"DNS",
"Escrow",
"Hashcracking",
"Marketplace",
"Proxy",
"VPN",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"targeting": {
"description": "Things that identify exploitable opportunities. These overlap heavily with data varieties that are compromised.",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of targeting investments",
"items": {
"type": "string",
"enum": [
"Default credentials",
"Email addresses",
"Lost or stolen credentials",
"Misconfigurations",
"Partner",
"Personal Information",
"Physical",
"Organizational Information",
"Vulnerabilities",
"Weaknesses",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"distribution": {
"description": "Services used to distribute actor content.",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of distribution investments",
"items": {
"type": "string",
"enum": [
"Botnet",
"Compromised server",
"Direct",
"Email",
"Loader",
"Partner",
"Phone",
"Physical",
"Website",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"cash-out": {
"description": "Methods for converting something (likely the attribute compromised) into currency.",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of cash-out investments",
"items": {
"type": "string",
"enum": [
"Cryptocurrency",
"Direct",
"Fraud",
"Hijacked rewards",
"Provide service",
"Sell stolen goods",
"Purchase stolen goods",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"money laundering": {
"description": "Methods for concealing the origins of illegally obtained money.",
"additionalProperties": false,
"properties": {
"variety": {
"description": "Varieties of money laundering",
"items": {
"type": "string",
"enum": [
"Bank",
"Company",
"Cryptocurrency tumbling",
"Employment",
"Gambling",
"Physical",
"Provide service",
"Re-shipping",
"Smurfing",
"Sell stolen goods",
"NA",
"Other",
"Unknown"
]
},
"minItems": 1,
"type": "array",
"uniqueItems": true
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"variety"
],
"type": "object"
},
"NA": {
"type": "boolean"
}
},
"type": "object"
},
"impact": {
"description": "Impact Info
**REMINDER - UNLESS THIS IS FOR VCDB, DON'T RECORD VICTIM-INDENTIFYING INFO IF SUBMITTING TO THE DBIR**
**Tip: Hold CTRL or COMMAND to select multiple items from a list.",
"additionalProperties": false,
"properties": {
"overall_rating": {
"type": "string",
"enum": [
"Catastrophic",
"Damaging",
"Painful",
"Distracting",
"Insignificant",
"Unknown"
]
},
"iso_currency_code": {
"description": "ISO4217 currency code. More Info",
"type": "string",
"enum": [
"AED",
"AFN",
"ALL",
"AMD",
"ANG",
"AOA",
"ARS",
"AUD",
"AWG",
"AZN",
"BAM",
"BBD",
"BDT",
"BGN",
"BHD",
"BIF",
"BMD",
"BND",
"BOB",
"BRL",
"BSD",
"BTN",
"BWP",
"BYR",
"BZD",
"CAD",
"CDF",
"CHF",
"CLP",
"CNY",
"COP",
"CRC",
"CUC",
"CUP",
"CVE",
"CZK",
"DJF",
"DKK",
"DOP",
"DZD",
"EGP",
"ERN",
"ETB",
"EUR",
"FJD",
"FKP",
"GBP",
"GEL",
"GGP",
"GHS",
"GIP",
"GMD",
"GNF",
"GTQ",
"GYD",
"HKD",
"HNL",
"HRK",
"HTG",
"HUF",
"IDR",
"ILS",
"IMP",
"INR",
"IQD",
"IRR",
"ISK",
"JEP",
"JMD",
"JOD",
"JPY",
"KES",
"KGS",
"KHR",
"KMF",
"KPW",
"KRW",
"KWD",
"KYD",
"KZT",
"LAK",
"LBP",
"LKR",
"LRD",
"LSL",
"LTL",
"LVL",
"LYD",
"MAD",
"MDL",
"MGA",
"MKD",
"MMK",
"MNT",
"MOP",
"MRO",
"MUR",
"MVR",
"MWK",
"MXN",
"MYR",
"MZN",
"NAD",
"NGN",
"NIO",
"NOK",
"NPR",
"NZD",
"OMR",
"PAB",
"PEN",
"PGK",
"PHP",
"PKR",
"PLN",
"PYG",
"QAR",
"RON",
"RSD",
"RUB",
"RWF",
"SAR",
"SBD",
"SCR",
"SDG",
"SEK",
"SGD",
"SHP",
"SLL",
"SOS",
"SPL",
"SRD",
"STD",
"SVC",
"SYP",
"SZL",
"THB",
"TJS",
"TMT",
"TND",
"TOP",
"TRY",
"TTD",
"TVD",
"TWD",
"TZS",
"UAH",
"UGX",
"USD",
"UYU",
"UZS",
"VEF",
"VND",
"VUV",
"WST",
"XAF",
"XCD",
"XDR",
"XOF",
"XPF",
"YER",
"ZAR",
"ZMK",
"ZWD",
"XBT",
"BCH",
"Ether",
"Litecoin",
"XMR",
"ZEC"
]
},
"overall_amount": {
"description": "The total amount lost in the given ISO currency code.",
"type": "number"
},
"overall_min_amount": {
"description": "When 'overall_amount' would be a range, use this field for the minimum of that range. Note: Values here will not appear in searches for 'overall_amount'.",
"type": "number"
},
"overall_max_amount": {
"description": "When 'overall_amount' would be a range, use this field for the maximum of that range. Note: Values here will not appear in searches for 'overall_amount'.",
"type": "number"
},
"loss": {
"description": "Were any losses or costs reported for this incident? (Definitions for loss varieties and ratings are here)",
"items": {
"additionalProperties": false,
"properties": {
"variety": {
"type": "string",
"enum": [
"Asset and fraud",
"Brand damage",
"Business disruption",
"Competitive advantage",
"Legal and regulatory",
"Operating costs",
"Response and recovery",
"Other"
]
},
"rating": {
"type": "string",
"enum": [
"Major",
"Moderate",
"Minor",
"None",
"Unknown"
]
},
"amount": {
"type": "number"
},
"min_amount": {
"type": "number"
},
"max_amount": {
"type": "number"
}
},
"required": [
"variety"
],
"type": "object"
},
"minItems": 1,
"type": "array"
},
"notes": {
"minLength": 1,
"type": "string"
}
},
"required": [
"overall_rating"
],
"type": "object"
},
"notes": {
"minLength": 1,
"type": "string",
"description": "Record notes about the incident."
},
"plus": {
"type": "object",
"description": "Plus is the appropriate place to extend the VERIS schema for your own needs. Add organization-specific enumerations here.",
"properties": {
"master_id": {
"description": "Master_id is a type 4 UUID and is unique for every record (incident).",
"minLength": 1,
"type": "string"
},
"attribute": {
"additionalProperties": false,
"properties": {
"confidentiality": {
"additionalProperties": false,
"properties": {
"data_abuse": {
"description": "The data was used for fraud, used mischievously, used maliciously, or otherwise abused.",
"minLength": 1,
"type": "string",
"enum": [
"Yes",
"Yes - Data ransomed",
"Yes - Identity theft",
"Yes - Financial fraud",
"Yes - Posted on personal forum",
"No",
"Other",
"Unknown"
]
}
},
"type": "object"
}
},
"type": "object"
},
"row_number": {
"type": "number"
}
}
},
"extra": {
"type": "object",
"additionalProperties": false,
"description": "Extra is a reserved name and should not appear in any objects. It should only be used for temporary derived columns during analysis.",
"properties": {}
},
"corrective_action": {
"description": "What corrective action(s) are planned (or recommended) to prevent and/or detect similar incidents in the future?
This can include general recommendations, specific changes to policy, procedures, personnel, and technology, short-term and long-term strategies, etc. Don't simply copy what the investigator said. Tie to the root causes listed above, and focus on practical, effective corrective actions.",
"type": "string"
},
"cost_corrective_action": {
"type": "string",
"enum": [
"Difficult and expensive",
"Something in-between",
"Simple and cheap",
"Unknown"
]
},
"ioc": {
"items": {
"additionalProperties": false,
"properties": {
"comment": {
"type": "string"
},
"indicator": {
"type": "string"
}
},
"required": [
"indicator"
],
"type": "object"
},
"minItems": 1,
"type": "array"
},
"control_failure": {
"description": "What were the root control failures or weaknesses that allowed this incident to occur?
Obviously, there may be a multitude of factors that could be listed here. Include as many as you want, but focus on the issues most pertinent to why the incident occurred.",
"type": "string"
},
"subsets": {
"type": "object",
"properties": {}
},
"schema_version": {
"description": "Schema version in use. This should be 1.4.0 for this schema.",
"type": "string",
"default": "1.4.0"
},
"schema_name": {
"description": "Name of Schema. This can be used to signal to software reading the schema which it is. Common values are 'verisc', 'dbir', and 'vcdb'.",
"type": "string",
"default": "verisc"
}
},
"required": [
"actor",
"action",
"discovery_method",
"schema_version",
"asset",
"timeline",
"incident_id",
"security_incident",
"summary"
],
"type": "object"
}