Commit graph

2626 commits

Author SHA1 Message Date
niclas
5d8dbf0d91 Add [cluster] country code 2024-03-12 13:55:00 +01:00
niclas
c88253baea Add [synonyms] and fixed indivdual mistakes 2024-03-12 13:00:57 +01:00
niclas
bb28408b14 Add [agencies] refs 2024-03-12 11:22:30 +01:00
Daniel Plohmann
77b7ed2f01
adding aliases from UA's H1'2023 report 2024-03-12 10:15:12 +01:00
3f039b5932
fix: [threat-actor] fix #942
`Hyppo Team` was present in two clusters. We just kept the alias
for `Turla`.
2024-03-11 10:00:15 +01:00
Delta-Sierra
5d8d0d294e Merge https://github.com/MISP/misp-galaxy 2024-03-07 14:10:29 +01:00
Delta-Sierra
d9214cff89 update producers 2024-03-07 13:48:22 +01:00
b43f9d7b3d
Merge pull request #941 from NMD03/main
Add [galaxies] Tidal Cyber
2024-03-06 11:07:29 +01:00
niclas
098f0e6ecd Fix [config] uuids 2024-03-06 09:54:06 +01:00
niclas
4f07fbdcdd Fix [config] typo 2024-03-06 09:35:35 +01:00
niclas
c28a001b4f Fix [tidal] check for existing sub clusters 2024-03-06 09:19:11 +01:00
niclas
03c6e3cb00 Fix [duplicates] list 2024-03-05 17:22:03 +01:00
niclas
a3071cf270 Add [techniques] codeblock for duplicates 2024-03-05 17:15:21 +01:00
niclas
16366f6893 Chg [tidal] add associated to name 2024-03-05 16:24:29 +01:00
niclas
a88b3ced33 Chg [groups] change name for Volt Typhoon duplicate 2024-03-05 16:15:58 +01:00
niclas
9e78c85124 Fix [references] no empty refs 2024-03-05 15:55:07 +01:00
niclas
2b383338f0 Fix [software] type as array 2024-03-05 15:46:35 +01:00
niclas
b2cc4ccd08 Fix [galaxies] add version 2024-03-05 15:33:10 +01:00
niclas
f756c18d1d Fix [clusters] authors 2024-03-05 15:11:57 +01:00
niclas
5be77f6c2d Fix [tidal] exclude empty meta fields 2024-03-05 14:41:53 +01:00
niclas
8e345c3684 Add [galaxies] Cyber Tidal 2024-03-05 14:27:25 +01:00
Mathieu4141
c11834aec4 [threat-actors] Add R00tK1T 2024-02-29 10:38:27 -08:00
Mathieu4141
39f89c900c [threat-actors] Add Mogilevich 2024-02-29 10:38:27 -08:00
Mathieu4141
cc68b22fe2 [threat-actors] Add UNC1549 2024-02-29 10:38:27 -08:00
Mathieu4141
7b3c8a87c3 [threat-actors] Add UAC-0184 2024-02-29 10:38:27 -08:00
Mathieu4141
b010a75426 [threat-actors] Add SPIKEDWINE 2024-02-29 10:38:27 -08:00
838f649766
chg: [sigma] updated to the latest version 2024-02-27 14:10:36 +01:00
Delta-Sierra
7481cce57d fix double 2024-02-23 16:14:42 +01:00
Delta-Sierra
42b3319e69 typo~ 2024-02-23 16:13:14 +01:00
Delta-Sierra
8e07569da2 Fix ENORMOUS TYPO and add a few description (wip) 2024-02-23 16:11:23 +01:00
Delta-Sierra
667263a512 add producer names 2024-02-23 16:02:22 +01:00
39d40a991f
chg: [producer] Sophos added 2024-02-23 15:51:56 +01:00
364b835d8e
chg: [threat-actor] version updated 2024-02-23 15:46:11 +01:00
efb3c3995a
new: [producer] Skeleton for threat intelligence producer to be attached
as producer of Intelligence in MISP feed.

In the realm of cybersecurity, numerous security firms produce feeds and threat intelligence conforming to the MISP standards. However, a significant challenge arises due to the often insufficient or vague descriptions of the origins of this intelligence within these standards. This lack of clarity hinders the effectiveness and credibility of the threat intelligence shared across platforms and organizations.
2024-02-23 15:30:53 +01:00
Mathieu4141
9c85cbc223 [threat-actors] Add GoldFactory 2024-02-20 05:22:26 -08:00
Mathieu4141
82b347682c [threat-actors] Add Winter Vivern aliases 2024-02-20 05:22:26 -08:00
Mathieu4141
4e61e7275a [threat-actors] Add Cyber.Anarchy.Squad 2024-02-20 05:22:26 -08:00
Mathieu4141
ccfd207e59 [threat-actors] Add LabHost 2024-02-20 05:22:26 -08:00
Mathieu4141
83198aa663 [threat-actors] Add ShadowSyndicate 2024-02-20 05:22:25 -08:00
Mathieu4141
d3f5a26ec0 [threat-actors] Add ResumeLooters 2024-02-20 05:22:25 -08:00
Mathieu4141
6ddf39e1ae [threat-actors] Add Charming Kitten aliases 2024-02-20 05:22:25 -08:00
Mathieu4141
96adf0ba8f [threat-actors] Add ProCC 2024-02-20 05:22:25 -08:00
niclas
e90ae3e5d9 Fix [mitre] new galaxy enrichments 2024-02-19 13:44:32 +01:00
niclas
bdd2329163 reset enrichment 2024-02-19 13:42:27 +01:00
7ed94eb865
chg: [threat-actor] fixed 2024-02-16 18:41:46 +01:00
jstnk9
b3a25c57b3 added new information in relation to the Mandiant-Google TAG Report
New information added via https://services.google.com/fh/files/misc/tool-of-first-resort-israel-hamas-war-cyber.pdf
2024-02-16 17:36:09 +01:00
Delta-Sierra
ef8c6c95eb add relationships between surveillance vendors 2024-02-16 15:37:14 +01:00
9cf86925f1
Merge pull request #931 from NMD03/enrich_new_mitre
Add [mitre] relations from deprecated galaxies
2024-02-15 16:31:08 +01:00
niclas
777ead0170 Fix [mitre] running jq_all_the_things.sh 2024-02-15 14:26:04 +01:00
Mathieu4141
f4d69382cf [threat-actors] Add Blackatom 2024-02-15 03:42:29 -08:00
Mathieu4141
ed26f4d246 [threat-actors] Add TA2725 2024-02-15 03:42:28 -08:00
niclas
1e60ee58a7 Add [mitre] relations from deprecated galaxies 2024-02-15 11:59:17 +01:00
8f3c662961
chg: [sigma] updated to the latest version 2024-02-12 21:24:11 +01:00
Daniel Plohmann
8a359dbd43
merge KNOCKOUT SPIDER -> Evilnum
Based on newer public reporting grouping these.
2024-02-08 10:38:04 +01:00
Delta-Sierra
a8496a939e Merge https://github.com/MISP/misp-galaxy 2024-02-07 10:53:31 +01:00
Delta-Sierra
4686aae3d5 add COATHANGER ref 2024-02-07 10:52:40 +01:00
Delta-Sierra
6222443b24 add COATHANGER RAT 2024-02-07 10:51:47 +01:00
94051bb5ef
chg: [surveillance-vendor] updated 2024-02-07 10:39:03 +01:00
c867adcbf3
Merge branch 'main' of github.com:MISP/misp-galaxy into main 2024-02-07 10:22:24 +01:00
d07c584525
chg: [surveillance-vendor] updated following https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Buying_Spying_-_Insights_into_Commercial_Surveillance_Vendors_-_TAG_report.pdf 2024-02-07 10:21:40 +01:00
Mathieu4141
02bec6da4f [threat-actors] Add TwoSail Junk aliases 2024-02-06 07:30:07 -08:00
Mathieu4141
6235ee49f7 [threat-actors] Add Operation Emmental 2024-02-06 07:30:07 -08:00
Mathieu4141
c740c6f1e1 [threat-actors] Add Urpage 2024-02-06 07:30:06 -08:00
Mathieu4141
f58c20fc20 [threat-actors] Add APT23 aliases 2024-02-06 07:30:06 -08:00
Mathieu4141
9a2e09d86c [threat-actors] Add Operation C-Major aliases 2024-02-06 07:30:06 -08:00
Mathieu4141
5194939603 [threat-actors] Add Tonto Team aliases 2024-02-06 07:30:06 -08:00
Mathieu4141
cc4dca679b [threat-actors] Add Earth Yako 2024-02-06 07:30:06 -08:00
Mathieu4141
baaf153229 [threat-actors] Add Operation Red Signature 2024-02-06 07:30:06 -08:00
Mathieu4141
859d3f7ac0 [threat-actors] Add Earth Berberoka aliases 2024-02-06 07:30:06 -08:00
Mathieu4141
55083776a0 [threat-actors] Add Domestic Kitten aliases 2024-02-06 07:30:05 -08:00
Delta-Sierra
8643f5f555 Merge https://github.com/MISP/misp-galaxy 2024-02-06 15:11:53 +01:00
Delta-Sierra
ea16f1811a adding several webshells and open source tools 2024-02-06 15:09:41 +01:00
Mathieu4141
957e848a6f [threat-actors] Add Ferocious Kitten 2024-02-05 09:20:11 -08:00
Mathieu4141
3a44200a0c [threat-actors] Add APT5 aliases 2024-02-05 09:20:11 -08:00
Mathieu4141
d2586524e3 [threat-actors] Add CardinalLizard 2024-02-05 09:20:11 -08:00
Mathieu4141
045ec7071f [threat-actors] Add Operation Ghoul 2024-02-05 09:20:11 -08:00
Mathieu4141
3a15a27584 [threat-actors] Add Operation Triangulation 2024-02-05 09:20:11 -08:00
Mathieu4141
c97fc15d59 [threat-actors] Add GhostEmperor 2024-02-05 09:20:11 -08:00
Mathieu4141
cff0da0b3a [threat-actors] Add RevengeHotels 2024-02-05 09:20:10 -08:00
Mathieu4141
40becc0ee9 [threat-actors] Add Fishing Elephant 2024-02-05 09:20:10 -08:00
Mathieu4141
dd01813e51 [threat-actors] Add ShaggyPanther 2024-02-05 09:20:10 -08:00
Mathieu4141
bffb0ef644 [threat-actors] Add Tomiris 2024-02-05 09:20:10 -08:00
Mathieu4141
3379a0777b [threat-actors] Add Karkadann 2024-02-05 09:20:10 -08:00
b35d4bd07a
chg: [threat-actor] version updated 2024-02-05 15:21:25 +01:00
Mathieu4141
ffeed3447f [threat-actors] Add Silent Librarian aliases 2024-02-05 03:39:17 -08:00
Mathieu4141
9c5bc36ab4 [threat-actors] Add MuddyWater aliases 2024-02-05 03:39:17 -08:00
Mathieu4141
4699f65425 [threat-actors] Add TA2719 2024-02-05 03:39:17 -08:00
Mathieu4141
fc173c1a78 [threat-actors] Add APT10 aliases 2024-02-05 03:39:17 -08:00
Mathieu4141
bd0d541a7a [threat-actors] Add OilRig aliases 2024-02-05 03:39:16 -08:00
Mathieu4141
9cb1fd6aa8 [threat-actors] Add Lazarus Group aliases 2024-02-05 03:39:16 -08:00
Mathieu4141
57016ac3ae [threat-actors] Add TA2722 2024-02-05 03:39:16 -08:00
Mathieu4141
be8e127590 [threat-actors] Add APT39 aliases 2024-02-05 03:39:16 -08:00
Mathieu4141
40f65a9d91 [threat-actors] Add Evilnum aliases 2024-02-05 03:39:16 -08:00
Mathieu4141
3f6ff94c89 [threat-actors] Add APT33 aliases 2024-02-05 03:39:16 -08:00
Mathieu4141
72504d286a [threat-actors] Add MUSTANG PANDA aliases 2024-02-05 03:39:16 -08:00
Mathieu4141
3690ab0e24 [threat-actors] Add TA2552 2024-02-05 03:39:16 -08:00
Mathieu4141
a456e419d8 [threat-actors] Add APT31 aliases 2024-02-05 03:39:16 -08:00
Christophe Vandeplas
ca366fc16a
chg: [ATRM] bump to latest ATRM version 2024-02-05 07:34:58 +01:00
effee963cc
chg: [microsoft] updated version 2024-02-02 15:32:02 +01:00
Mathieu4141
e497ec2b38 [threat-actors] Add Storm-1575 2024-02-01 11:02:05 -08:00
Mathieu4141
a42dc67fb6 [threat-actors] Add Storm-0835 2024-02-01 11:02:05 -08:00
Mathieu4141
1589a943a9 [threat-actors] Add Storm-1674 2024-02-01 11:02:05 -08:00
Mathieu4141
0b571d7e76 [threat-actors] Add Storm-0829 2024-02-01 11:02:05 -08:00
Mathieu4141
7607dc70cf [threat-actors] Add Storm-1567 2024-02-01 11:02:05 -08:00
Mathieu4141
eb8db810c0 [threat-actors] Add Storm-1152 2024-02-01 11:02:05 -08:00
Mathieu4141
991765a1c7 [threat-actors] Add SaintBear aliases 2024-02-01 11:02:05 -08:00
Mathieu4141
b3f440203a [threat-actors] Add Storm-0539 2024-02-01 11:02:05 -08:00
Mathieu4141
b645975616 [threat-actors] Add DarkHotel aliases 2024-02-01 11:02:04 -08:00
Mathieu4141
fa7709e63c [threat-actors] Add Storm-0530 2024-02-01 11:02:04 -08:00
Mathieu4141
a6c451be2d [threat-actors] Add Storm-0381 2024-02-01 11:02:04 -08:00
Mathieu4141
3a193291b9 [threat-actors] Add Storm-1101 2024-02-01 11:02:04 -08:00
Mathieu4141
3fda32a0d6 [threat-actors] Add Ghostwriter aliases 2024-02-01 11:02:04 -08:00
Mathieu4141
de04fe33e1 [threat-actors] Add Storm-1286 2024-02-01 11:02:04 -08:00
Mathieu4141
68e0ffb006 [threat-actors] Add Storm-1099 2024-02-01 11:02:04 -08:00
Mathieu4141
972ed33536 [threat-actors] Add TA2101 aliases 2024-02-01 11:02:03 -08:00
Mathieu4141
83f874da2c [threat-actors] Add LYCEUM aliases 2024-02-01 11:02:03 -08:00
Mathieu4141
6f61a3fc3e [threat-actors] Add Storm-1084 2024-02-01 11:02:03 -08:00
Mathieu4141
73d23f6211 [threat-actors] Add Sandworm aliases 2024-02-01 11:02:03 -08:00
Mathieu4141
ba7137c5a3 [threat-actors] Add Lazarus Group aliases 2024-02-01 11:02:03 -08:00
Mathieu4141
49c3e06605 [threat-actors] Add FIN7 aliases 2024-02-01 11:02:02 -08:00
Mathieu4141
43f9587469 [threat-actors] Add POLONIUM aliases 2024-02-01 11:02:02 -08:00
Mathieu4141
ae82f07fd8 [threat-actors] Add Pink Sandstorm 2024-02-01 11:02:02 -08:00
Mathieu4141
22d3ea5ebf [threat-actors] Add Storm-1044 2024-02-01 11:02:02 -08:00
Mathieu4141
0dcbc136a7 [threat-actors] Add Opal Sleet 2024-02-01 11:02:02 -08:00
Mathieu4141
44a446c63f [threat-actors] Add APT15 aliases 2024-02-01 11:02:02 -08:00
Mathieu4141
72073b2384 [threat-actors] Add APT5 aliases 2024-02-01 11:02:01 -08:00
Mathieu4141
681784a3ec [threat-actors] Add Storm-1167 2024-02-01 11:02:01 -08:00
Mathieu4141
475dc88296 [threat-actors] Add Storm-1295 2024-02-01 11:02:01 -08:00
Mathieu4141
76430b605e [threat-actors] Add Scattered Spider aliases 2024-02-01 11:02:01 -08:00
Mathieu4141
ce3a5dd182 [threat-actors] Add MuddyWater aliases 2024-02-01 11:02:01 -08:00
Mathieu4141
ba525e4c54 [threat-actors] Add TA505 aliases 2024-02-01 11:02:01 -08:00
Mathieu4141
447c064477 [threat-actors] Add Phlox Tempest 2024-02-01 11:02:01 -08:00
Mathieu4141
a1dfeca461 [threat-actors] Add Raspberry Typhoon 2024-02-01 11:02:01 -08:00
Mathieu4141
7a2cfa4f42 [threat-actors] Add Silent Chollima aliases 2024-02-01 11:02:00 -08:00
Mathieu4141
5ffdc0f868 [threat-actors] Add APT33 aliases 2024-02-01 11:02:00 -08:00
Mathieu4141
a1ea480023 [threat-actors] Add PARINACOTA aliases 2024-02-01 11:02:00 -08:00
Mathieu4141
da57d8c5fd [threat-actors] Add Bohrium aliases 2024-02-01 11:02:00 -08:00
Mathieu4141
6fdd037988 [threat-actors] Add Ruby Sleet 2024-02-01 11:02:00 -08:00
Mathieu4141
2dc29dc6c7 [threat-actors] Add WIZARD SPIDER aliases 2024-02-01 11:02:00 -08:00
Mathieu4141
5afd682215 [threat-actors] Add MosesStaff aliases 2024-02-01 11:02:00 -08:00
Mathieu4141
837ce84344 [threat-actors] Add Lilac Typhoon 2024-02-01 11:01:59 -08:00
Mathieu4141
646206e70a [threat-actors] Add Fox Kitten aliases 2024-02-01 11:01:59 -08:00
Mathieu4141
9e940af919 [threat-actors] Add OilRig aliases 2024-02-01 11:01:59 -08:00
Mathieu4141
de63377c99 [threat-actors] Add APT31 aliases 2024-02-01 11:01:59 -08:00
Mathieu4141
42bad34d91 [threat-actors] Add Vanilla Tempest 2024-02-01 11:01:59 -08:00
Mathieu4141
0668ed368d [threat-actors] Add ENERGETIC BEAR aliases 2024-02-01 11:01:59 -08:00
Mathieu4141
9645731e76 [threat-actors] Add Kimsuky aliases 2024-02-01 11:01:58 -08:00
Mathieu4141
f35df2c9fe [threat-actors] Add Sunglow Blizzard 2024-02-01 11:01:58 -08:00
Mathieu4141
8ebdd40e42 [threat-actors] Add Velvet Tempest 2024-02-01 11:01:58 -08:00
Mathieu4141
4cbf4353b0 [threat-actors] Add Storm-0867 2024-02-01 11:01:58 -08:00