Commit graph

2847 commits

Author SHA1 Message Date
Mathieu4141
40dc998b9b [threat-actors] Add RaHDit 2024-09-09 08:18:23 -07:00
Mathieu4141
af9d183371 [threat-actors] Add IRLeaks 2024-09-09 08:18:23 -07:00
Mathieu4141
4fc5c37d08 [threat-actors] Add UAC-0154 2024-09-09 08:18:23 -07:00
Mathieu4141
47983fed20 [threat-actors] Add UNC4536 2024-09-09 08:18:23 -07:00
Mathieu4141
d8ee3beada [threat-actors] Add SILKFIN AGENCY 2024-09-09 08:18:22 -07:00
Mathieu4141
0d8e535b88 [threat-actors] Add UNC2970 2024-09-09 08:18:22 -07:00
Mathieu4141
5dcf22e4ef [threat-actors] Add ZeroSevenGroup 2024-09-09 08:18:22 -07:00
Mathieu4141
63566220af [threat-actors] Add Actor240524 2024-09-09 08:18:22 -07:00
Mathieu4141
164222d3c6 [threat-actors] Add TIDRONE 2024-09-09 08:18:22 -07:00
Mathieu4141
d935c1e62a [threat-actors] Add UNC4540 2024-09-09 08:18:22 -07:00
Mathieu4141
f3fe0d59d3 [threat-actors] Add CL-STA-0043 aliases 2024-09-09 08:18:22 -07:00
2efef14a46
Merge pull request #1015 from Delta-Sierra/main
alternate/modified script to generate first csirt services framework galaxy
2024-09-02 10:59:28 +02:00
d0b2e3e456
chg: [tidal] updated 2024-09-02 10:41:59 +02:00
1640effc6a
chg: [ransomware] updated 2024-09-02 10:30:47 +02:00
7258dd683c
chg: [sigma] updated to the latest version
Some checks are pending
Python application / build (3.10) (push) Waiting to run
Python application / build (3.8) (push) Waiting to run
Python application / build (3.9) (push) Waiting to run
2024-09-02 10:16:50 +02:00
Delta-Sierra
2e6fe8ea16 alternate/modified script to generate first csirt services framework galaxy 2024-08-30 09:45:34 +02:00
Jean-Louis Huynen
1882171086
add: [first-csirt] implement @Delta-Sierra comments 2024-08-23 15:36:38 +02:00
Jean-Louis Huynen
a89eceab29
Merge branch 'MISP:main' into main 2024-08-23 15:05:05 +02:00
50b3fe1b73
chg: [ransomware] jq all the things
Some checks are pending
Python application / build (3.10) (push) Waiting to run
Python application / build (3.8) (push) Waiting to run
Python application / build (3.9) (push) Waiting to run
2024-08-23 09:17:52 +02:00
933365fb42
chg: [ransomware] updated 2024-08-23 09:16:08 +02:00
9004c387c0
chg: [ransomware] update the description of ransomware galaxy which is now fully maintained by MISP project 2024-08-23 09:12:26 +02:00
Jean-Louis Huynen
e39ef72be2
add: [first-csirt] with correct cluster file 2024-08-22 16:51:23 +02:00
Jean-Louis Huynen
5cb42e796e
add: [first-csirt] Initial commit for FIRST CSIRT Services Framework 2024-08-22 16:46:56 +02:00
47b6fca308
chg: [sigma-rules] updated to the latest version 2024-08-20 13:57:51 +02:00
cfe1814509
chg: [threat-actor] updated 2024-08-19 18:07:20 +02:00
07a5c68b35
Merge branch 'threat-actors/ba010e21-3184-4bdc-87e0-872f16b95338' of https://github.com/Mathieu4141/misp-galaxy into Mathieu4141-threat-actors/ba010e21-3184-4bdc-87e0-872f16b95338 2024-08-19 18:05:59 +02:00
Christophe Vandeplas
552d80dd9e
chg: [mitre] deprecated entities 2024-08-17 12:41:47 +02:00
Christophe Vandeplas
31227403d7
Merge branch 'main' of https://github.com/cvandeplas/misp-galaxy 2024-08-13 17:58:52 +02:00
dac054e536
chg: [ransomware] updated 2024-08-13 10:13:03 +02:00
251d6c5039
chg: [producer] improved producer list
Some checks are pending
Python application / build (3.10) (push) Waiting to run
Python application / build (3.8) (push) Waiting to run
Python application / build (3.9) (push) Waiting to run
2024-08-13 07:40:29 +02:00
Tom
13c2cbe4a1 chg: [producer] added some security companies & CERTs. 2024-08-12 16:21:19 -04:00
Mathieu4141
1ebe75d3fe [threat-actors] Add Hive0137 2024-07-31 02:14:11 -07:00
Mathieu4141
7289782aae [threat-actors] Add UNC4393 2024-07-31 02:14:11 -07:00
Mathieu4141
a3e9e8c944 [threat-actors] Add SAMBASPIDER 2024-07-31 02:14:11 -07:00
Mathieu4141
ac6c63ba8a [threat-actors] Add Ghostwriter aliases 2024-07-31 02:14:11 -07:00
Mathieu4141
cd621af35c [threat-actors] Add Storm-0506 2024-07-31 02:14:11 -07:00
Mathieu4141
f5687c0162 [threat-actors] Add TA4903 2024-07-31 02:14:11 -07:00
Mathieu4141
793e4b9408 [threat-actors] Add APT45 2024-07-26 06:27:01 -07:00
Mathieu4141
90338e0e0f [threat-actors] Add UAC-0102 2024-07-26 06:27:01 -07:00
Mathieu4141
679a59e96d [threat-actors] Add Stargazer Goblin 2024-07-26 06:27:01 -07:00
Jean-Louis Huynen
fe01d6244d
add: [nist-nice] Initial commit for NIST NICE framework
Introduces galaxies for cybersecurity:
 - Work roles
 - Skills
 - Tasks
 - Knowledges
 - Competency areas
 - OPM codes
2024-07-24 14:29:49 +02:00
Mathieu4141
49093ecf16 [threat-actors] Add UAC-0063 2024-07-24 03:39:38 -07:00
Mathieu4141
d9af67d1df [threat-actors] Add Threat Actor 888 2024-07-24 03:39:38 -07:00
535a6c7c52
Merge branch 'main' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-main 2024-07-23 08:30:12 +02:00
Rony
ebe621a58a
Update threat-actor.json
added original blog link, and removed unnecessary ones.
2024-07-23 00:33:25 +05:30
Mathieu4141
0bf9d66d14 [threat-actors] Add Nullbulge 2024-07-19 09:03:54 -07:00
Mathieu4141
1a7f2beb1a [threat-actors] Add Lifting Zmiy 2024-07-19 09:03:54 -07:00
409e3d7276
chg: [ransomware] groups updated 2024-07-18 09:57:47 +02:00
4fae9bc3df
chg: [producer] ESET added 2024-07-18 09:40:57 +02:00
112200d358
chg: [sigma] updated to the latest version
Some checks are pending
Python application / build (3.10) (push) Waiting to run
Python application / build (3.8) (push) Waiting to run
Python application / build (3.9) (push) Waiting to run
2024-07-17 16:08:37 +02:00
Mathieu4141
a944be0d25 [threat-actors] Add CRYSTALRAY 2024-07-15 08:06:23 -07:00
Mathieu4141
d77d3398ab [threat-actors] Add Void Banshee 2024-07-15 08:06:23 -07:00
Delta-Sierra
dcf00b320b fix version 2024-07-12 14:34:03 +02:00
Delta-Sierra
6e0e8ad416 Merge https://github.com/MISP/misp-galaxy 2024-07-12 14:31:22 +02:00
Delta-Sierra
91333c699b create nace galaxy 2024-07-12 14:12:02 +02:00
b57d77a663
chg: [ransomware] updated
Some checks are pending
Python application / build (3.10) (push) Waiting to run
Python application / build (3.8) (push) Waiting to run
Python application / build (3.9) (push) Waiting to run
2024-07-10 22:54:08 +02:00
3ea10c319c
chg: [ransomware] updated ransomlook 2024-07-08 14:19:53 +02:00
Mathieu4141
9321234588 [threat-actors] Add Scattered Spider aliases 2024-07-08 02:28:35 -07:00
Mathieu4141
68d61732d1 [threat-actors] Add Water Sigbin 2024-07-08 02:28:35 -07:00
Mathieu4141
d8e7fbaa79 [threat-actors] Add CloudSorcerer 2024-07-08 02:28:35 -07:00
Mathieu4141
f7cb975c54 [threat-actors] Add Chamelgang aliases 2024-07-08 02:28:35 -07:00
Mathieu4141
c82f1a4dc8 [threat-actors] Add Boolka 2024-06-28 02:17:32 -07:00
Mathieu4141
da77ee6a61 [threat-actors] Add Dragonbridge 2024-06-28 02:17:32 -07:00
Christophe Vandeplas
886a0e6e1b
Merge pull request #994 from cvandeplas/atrm
Some checks failed
Python application / build (3.10) (push) Has been cancelled
Python application / build (3.8) (push) Has been cancelled
Python application / build (3.9) (push) Has been cancelled
chg: [atrm, tmss] migration to PyMISPGalaxies
2024-06-25 16:15:24 +02:00
Christophe Vandeplas
030e4029fb
fix: [tmss] fix sorting 2024-06-25 14:56:38 +02:00
Christophe Vandeplas
b00d7edaad
chg: [mitre-d3fend] PyMISPGalaxies and sorting 2024-06-25 14:51:29 +02:00
Mathieu4141
05f449dae3 [threat-actors] Add IntelBroker 2024-06-25 05:17:03 -07:00
Mathieu4141
c6fc6f248b [threat-actors] Add HellHounds 2024-06-25 05:17:02 -07:00
Christophe Vandeplas
1128f9ffe7
chg: [atrm] add external_ref and chg to PyMISPGalaxies 2024-06-25 13:21:16 +02:00
Christophe Vandeplas
bbbd2ca36b
chg: [tmss] migration to PyMISPGalaxies 2024-06-25 13:21:10 +02:00
Mathieu4141
0ad87ccef4 [threat-actors] Add BlueHornet 2024-06-24 02:35:58 -07:00
Mathieu4141
5347bcb95c [threat-actors] Add ALTDOS 2024-06-24 02:35:58 -07:00
Mathieu4141
a16cff8e44 [threat-actors] Add SneakyChef 2024-06-24 02:35:58 -07:00
Mathieu4141
13fc125694 [threat-actors] Add RedJuliett 2024-06-24 02:35:57 -07:00
Mathieu4141
4d94ff0c12 [threat-actors] Add JuiceLedger 2024-06-24 02:35:57 -07:00
Mathieu4141
09bd93f488 [threat-actors] Add Adrastea 2024-06-24 02:35:57 -07:00
Mathieu4141
965f1f5be4 [threat-actors] Add Markopolo 2024-06-24 02:35:57 -07:00
Mathieu4141
879ae26c55 [threat-actors] Add Void Arachne 2024-06-24 02:35:57 -07:00
dded13d5c2
chg: [threat-actor] version updated
Some checks failed
Python application / build (3.10) (push) Has been cancelled
Python application / build (3.8) (push) Has been cancelled
Python application / build (3.9) (push) Has been cancelled
2024-06-21 10:24:39 +02:00
400983eccd
chg: [sigma] updated
Some checks are pending
Python application / build (3.10) (push) Waiting to run
Python application / build (3.8) (push) Waiting to run
Python application / build (3.9) (push) Waiting to run
2024-06-19 16:24:13 +02:00
d8ac54d7d6
chg: [ransomware] aligned with ransomlook.io 2024-06-19 10:45:09 +02:00
Christophe Vandeplas
f3c8ccc032
Merge pull request #992 from Mathieu4141/threat-actors/fix-stone-panda-typo
[threat actors] fix stone panda typo
2024-06-19 10:20:17 +02:00
Mathieu Beligon
1e63bfca1b [threat actors] fix stone panda typo 2024-06-19 11:11:40 +03:00
Christophe Vandeplas
6f4b3b1387
fix: fixes CaSe InSenSiTiVe duplicates 2024-06-18 16:58:38 +02:00
Christophe Vandeplas
6341ffce68
fix: [fight] fix duplicates 2024-06-18 16:06:33 +02:00
Christophe Vandeplas
ca3cd1d0fb
fix: [Ransomware] remove Freeme / FreeMe duplicate 2024-06-18 15:54:58 +02:00
Christophe Vandeplas
da2a9c2fa7
fix: [Ransomware] remove Freeme / FreeMe duplicate 2024-06-18 15:54:28 +02:00
25d7755f89
chg: [threat-actor] version updated 2024-06-18 15:43:48 +02:00
Christophe Vandeplas
3dc4075233
chg: [fight] swiched to using PyMISPGalaxies 2024-06-18 14:30:39 +02:00
Mathieu4141
950a6bfa4e [threat-actors] Add TraderTraitor aliases 2024-06-18 04:51:30 -07:00
Mathieu4141
4cabbe3bc9 [threat-actors] Add UAC-0020 2024-06-18 04:51:30 -07:00
Mathieu4141
c8e623e84c [threat-actors] Add Bondnet 2024-06-18 04:51:30 -07:00
Mathieu4141
93cc634d1c [threat-actors] Add TA571 2024-06-18 04:51:29 -07:00
Mathieu4141
8ba48b446a [threat-actors] Add Sp1d3r 2024-06-18 04:51:29 -07:00
Mathieu4141
e7bb6de04a [threat-actors] Add UNC5537 2024-06-18 04:51:29 -07:00
Mathieu4141
b317c4ff6b [threat-actors] Add Gitloker 2024-06-18 04:51:29 -07:00
Mathieu4141
fb177f95db [threat-actors] Add UTG-Q-008 2024-06-18 04:51:29 -07:00
Christophe Vandeplas
5ca2dc6ff7
fix: [fight] ugly workaround for duplicate entries 2024-06-17 15:18:55 +02:00
Christophe Vandeplas
e7c5bc7956
chg: [fight] add ATT&CK rel + fix description bug 2024-06-17 15:05:35 +02:00
Christophe Vandeplas
2f47a3c505
fix: [fight] unique refs 2024-06-17 12:27:17 +02:00
Christophe Vandeplas
a1658b3712
new: [fight] new MITRE FiGHT galaxy fixes #986 2024-06-17 12:21:12 +02:00
Christophe Vandeplas
2f5156b5e8
fix: [GSMA MoTIF] fix empty values 2024-06-11 15:44:02 +02:00
Christophe Vandeplas
50d42dc598
Merge remote-tracking branch 'MISP/main' 2024-06-11 15:23:06 +02:00
Christophe Vandeplas
c948ceaa10
new: [GSMA MoTIF] new galaxy fixes #966 2024-06-11 15:21:03 +02:00
Mathieu4141
7c21eb7aa5 [threat-actors] Add Hunt3r Kill3rs 2024-06-06 01:27:07 -07:00
Mathieu4141
3c7f74913f [threat-actors] Add LilacSquid 2024-06-06 01:27:07 -07:00
Mathieu4141
7ade514644 [threat-actors] Add SEXi 2024-06-06 01:27:07 -07:00
Mathieu4141
b5f257c4e1 [threat-actors] Add FlyingYeti 2024-06-06 01:27:06 -07:00
Mathieu4141
eec91d1465 [threat-actors] Add StucxTeam 2024-06-06 01:27:06 -07:00
Mathieu4141
d0162e654e [threat-actors] Add APT28 aliases 2024-06-06 01:27:06 -07:00
Mathieu4141
4e6fa2191a [threat-actors] Add Unfading Sea Haze 2024-06-06 01:27:06 -07:00
Mathieu4141
f1bbd96d84 [threat-actors] Add RansomHub 2024-06-06 01:27:06 -07:00
97fd1ed309
chg: [threat-actor] jq all the things 2024-06-02 09:30:18 +02:00
ab6be85bc0
Merge pull request #980 from jstnk9/sidewinder-update
update sidewinder information
2024-06-02 09:29:08 +02:00
Delta-Sierra
2a51fc0341 Merge https://github.com/MISP/misp-galaxy 2024-05-31 15:32:40 +02:00
Delta-Sierra
a0ce2266da add Europol as producer (incomplete) 2024-05-31 15:31:43 +02:00
e60b629cd3
chg: [sigma] updated 2024-05-28 11:51:40 +02:00
f3b93a6bef
chg: [threat-actor] version updated 2024-05-28 11:35:39 +02:00
cd89716df4
Merge pull request #979 from Mathieu4141/threat-actor/alpha-spider-f3194f38-902d-4738-91ea-0003abb2c1ab
[threat-actors] Add Alpha Spider
2024-05-28 11:34:49 +02:00
b0ededd744
Merge pull request #981 from cvandeplas/main
Implement MITRE D3FEND matrix #975
2024-05-28 11:29:26 +02:00
a77b860494
Merge pull request #982 from Delta-Sierra/main
update ransomware galaxy with ransomlook data
2024-05-28 10:54:29 +02:00
07514f97fd
chg: [misp-galaxy] version updated 2024-05-28 10:23:07 +02:00
Delta-Sierra
24d259f39e Should fix duplicate 'refs' in newly added ransomware (did not expect this case) 2024-05-28 09:05:05 +02:00
Delta-Sierra
42d8fab8ad update ransomware galaxy with ransomlook data 2024-05-28 08:24:45 +02:00
Christophe Vandeplas
f0457ef883
Merge remote-tracking branch 'MISP/main' 2024-05-28 08:13:13 +02:00
Christophe Vandeplas
2b3d62705d
new: [d3fend] added relationships to ATT&CK 2024-05-28 07:46:20 +02:00
jstnk9
ecf246a103 Update threat-actor.json 2024-05-24 09:39:04 +02:00
Mathieu4141
2698e76043 [threat-actors] Add Alpha Spider 2024-05-22 05:30:08 -07:00
Mathieu Beligon
32b9051873 [threat actors] fix merge 2024-05-21 19:29:26 +02:00
Mathieu Béligon
9e602a977f
Merge branch 'main' into threat-actors/5085bb5f-2aa6-485f-8e57-389d4020b408 2024-05-21 19:23:54 +02:00
Mathieu Béligon
e97ecd46b0
Add phantomcore reference
Co-authored-by: Rony <49360849+r0ny123@users.noreply.github.com>
2024-05-21 19:23:04 +02:00
f3a145c96f
chg: [threat-actor] updated following PR #977
The `master` branch should not be used
2024-05-21 16:59:07 +02:00
Mathieu4141
d172320fad [threat-actors] Add Kimsuky aliases 2024-05-21 06:56:42 -07:00
Mathieu4141
e17f2eda0c [threat-actors] Add Void Manticore 2024-05-21 06:56:41 -07:00
Mathieu4141
754a9b08f8 [threat-actors] Add CiberInteligenciaSV 2024-05-21 06:56:41 -07:00
Mathieu4141
6fe19ac915 [threat-actors] Add PhantomCore 2024-05-21 06:56:41 -07:00
1d5af5c245
chg: [tidal-software] remove duplicate from the API 2024-05-16 20:35:06 +02:00
fe3fead459 chg: [tidal] updated to the latest version 2024-05-16 20:29:18 +02:00
adc70d09e7 chg: [sigma] updated to the latest version 2024-05-16 20:26:58 +02:00
Christophe Vandeplas
f3838f4550
chg: [ATLAS] Update to latest version #newUUIDsForAll 2024-05-13 15:14:20 +02:00
Christophe Vandeplas
93fa68f4a4
chg: [mitre] Use x_mitre_platforms for kill-chain separation 2024-05-13 11:07:34 +02:00
Christophe Vandeplas
25a1776258
chg: [mitre] minor update 2024-05-13 07:14:02 +02:00
894946f25d
chg: [sigma] updated to the latest version 2024-05-08 09:39:09 +02:00
Mathieu4141
303eb8a0d6 [threat-actors] Add SaintBear aliases 2024-05-02 04:50:10 -07:00
Mathieu4141
fc2b5abb6a [threat-actors] Add Water Orthrus 2024-05-02 04:50:10 -07:00
Rony
72402ce38b
chg: [threat-actor] STORM ->> Storm 2024-04-26 19:15:47 +00:00
Rony
e71398bbd5
Merge branch 'main' into fix 2024-04-27 00:31:16 +05:30
Rony
3d5c61a8ef
fix: resolve conflict 2024-04-26 18:56:46 +00:00
Mathieu4141
dd14938a49 [threat-actors] Add USDoD 2024-04-26 09:01:34 -07:00
Mathieu4141
2bf2bad2a9 [threat-actors] Add STORM-1849 2024-04-26 09:01:34 -07:00