Commit graph

1317 commits

Author SHA1 Message Date
Christophe Vandeplas
4ab9bbbfa3 chg: [attack] update to latest ATT&CK data 2019-10-25 10:12:41 +02:00
1581827875
chg: [attck4fraud] jq all the things 2019-10-20 20:07:29 +02:00
Christophe Vandeplas
eb594cba0f fix: [misinfosec] fixes inconsistent filename 2019-10-20 18:53:02 +02:00
2b84592ff5
Merge branch 'master' of github.com:MISP/misp-galaxy 2019-10-18 14:28:41 +02:00
77605f8d43
chg: [attck4fraud] updates based on issue #466 2019-10-18 14:27:36 +02:00
Rony
1fc0f5e2e7
Update threat-actor.json 2019-10-17 09:46:56 +05:30
Deborah Servili
88025a541f
add operation soft cell 2019-10-14 16:07:35 +02:00
4d4bd3a70c fix: [misinfosec] fixed kill_chain fields 2019-10-09 09:45:52 +02:00
VVX7
e4998efec9 chg: [galaxy] added AMITT galaxy/cluster generator script 2019-10-08 13:52:08 -04:00
VVX7
a0357c735e chg: [galaxy] version number to int 2019-10-07 19:19:45 -04:00
VVX7
0a29445b44 new: [galaxy] AMITT (Adversarial Misinformation and Influence Tactics and Techniques) framework for describing disinformation incidents. AMITT is part of misinfosec - work on adapting information security practices to help track and counter misinformation - and is designed as far as possible to fit existing infosec practices and tools. 2019-10-07 19:07:25 -04:00
Deborah Servili
c27385cfa4
jq 2019-10-07 14:38:16 +02:00
Deborah Servili
5355910a8f
add legitimate tools 2019-10-07 13:38:40 +02:00
Deborah Servili
19452d8c1f Merge branch 'master' of https://github.com/MISP/misp-galaxy 2019-10-07 11:07:00 +02:00
Deborah Servili
569d453ff2
update version 2019-10-07 11:06:27 +02:00
Deborah Servili
0795eecd01
add PlugX rat sysnonyms 2019-10-07 11:04:33 +02:00
ac8236d16d
chg: [misp-galaxy] jq all the things 2019-10-03 14:46:07 +02:00
9e82b025b5
chg: [tool] COMPfun - Reductor added
Ref: https://securelist.com/compfun-successor-reductor/93633/
2019-10-03 14:25:44 +02:00
Deborah Servili
cb774002c9
add Sodinokibi synonym 2019-10-02 11:44:54 +02:00
Deborah Servili
82824be700
fix empty string 2019-09-30 12:55:31 +02:00
Deborah Servili
b7c9d3e034
jq 2019-09-30 11:56:28 +02:00
Deborah Servili
fca032ea73
add TVSPY tool 2019-09-30 10:45:53 +02:00
Deborah Servili
f6c075c3df
WIP update target info 2019-09-27 16:22:01 +02:00
Deborah Servili
c305640290
new galaxy - Region based on UN M49 2019-09-26 13:01:41 +02:00
Deborah Servili
d0068b0ce0
WIP update target info 2019-09-25 15:39:02 +02:00
Deborah Servili
a4b59f647c
jq 2019-09-25 13:41:55 +02:00
Deborah Servili
335402c886 Merge branch 'master' of https://github.com/MISP/misp-galaxy into target-location-galaxy 2019-09-25 13:39:33 +02:00
Deborah Servili
bb3f9dc183
WIP update target info - fix empty string 2019-09-25 13:31:46 +02:00
309109eb27
chg: [threat-actor] new LookBack (Malware?Campaign?TA?)
Signed-off: During MISP training
2019-09-25 12:12:34 +02:00
Deborah Servili
9068e3c742
WIP update target info 2019-09-25 11:46:10 +02:00
a5ae130916
chg: [threat-actor] Evil Eye and POISON CARP
Ref: https://citizenlab.ca/2019/09/poison-carp-tibetan-groups-targeted-with-1-click-mobile-exploits/
Signed-off: Jean-Louis during training session
2019-09-25 11:27:03 +02:00
Deborah Servili
83ee520dd5
WIP update target info 2019-09-25 09:44:34 +02:00
Deborah Servili
638cdd4198
version update 2019-09-20 14:54:56 +02:00
Deborah Servili
b9b4b9c651
Add Tortoiseshell thrat actor 2019-09-20 14:53:25 +02:00
Deborah Servili
6d88367497
moar clusters 2019-09-20 09:50:37 +02:00
42f457fc22
Merge pull request #457 from rmkml/master
Add Mr.Dec Ransomware
2019-09-17 10:17:11 +02:00
rmkml
5631d210a0 Add Mr.Dec Ransomware 2019-09-17 00:44:56 +02:00
cc134d7dff
Merge pull request #456 from rmkml/master
Add Hildacrypt Ransomware
2019-09-15 18:24:03 +02:00
rmkml
dff982be20 Add Hildacrypt Ransomware 2019-09-14 21:49:16 +02:00
55da11f8ba
Merge pull request #455 from rmkml/master
Add InnfiRAT
2019-09-14 08:16:35 +02:00
rmkml
f907797d41 Add InnfiRAT 2019-09-14 00:08:54 +02:00
Deborah Servili
7e892eaa7d
update target information [draft] 2019-09-13 16:35:20 +02:00
Deborah Servili
2588df01cc
update target information 2019-09-12 16:22:11 +02:00
StefanKelm
db2b5a13ef
Update threat-actor.json
Silent Librarian
2019-09-12 11:57:03 +02:00
Deborah Servili
1eb23bc55b
update target information 2019-09-12 11:10:41 +02:00
Deborah Servili
6c430ad21e
improve target-information 2019-09-11 16:32:29 +02:00
rmkml
7c89cb308c
Merge branch 'master' into master 2019-09-07 19:52:05 +02:00
rmkml
dfc6321e0c Add AsyncRAT 2019-09-07 19:43:08 +02:00
Deborah Servili
718ea55dd7
Merge branch 'master' into master 2019-09-04 14:42:47 +02:00
Deborah Servili
9e3a998dfc
aff SectorJ04 group 2019-09-03 15:51:21 +02:00
9690d070ab
Merge pull request #450 from rmkml/master
Add Buran Ransomware
2019-09-02 07:39:19 +02:00
rmkml
28ec696272 Add Buran Ransomware 2019-09-01 21:20:28 +02:00
Daniel Plohmann
f40b7dd132
'SectorJ04 Group' as alias introduced by NSHC for TA505
Not explicitly mentioned in the blog post but it looks like we just got an alias for TA505... https://threatrecon.nshc.net/2019/08/29/sectorj04-groups-increased-activity-in-2019/
2019-09-01 15:46:36 +02:00
9920461294
Merge pull request #448 from rmkml/master
Add Nemty Ransomware
2019-08-31 21:27:50 +02:00
rmkml
e79310c861 Add Nemty Ransomware 2019-08-31 21:08:50 +02:00
c7e6a17a31
Merge pull request #447 from Delta-Sierra/target-location-galaxy
improve more clusters
2019-08-30 16:37:39 +02:00
Deborah Servili
5504c10e3d
improve more clusters 2019-08-30 16:32:02 +02:00
b986f06cb4
Merge pull request #446 from wagner-certat/tool-empty-strings
Add test for empty strings
2019-08-30 11:10:16 +02:00
0966e58da6
Merge branch 'master' of github.com:MISP/misp-galaxy 2019-08-30 11:06:29 +02:00
f5056ff02e
chg: [threat-actor] add machete-apt synonyms as reported in #445 2019-08-30 11:03:30 +02:00
Deborah Servili
2c248db419
Merge pull request #441 from Delta-Sierra/target-location-galaxy
More clusters improved
2019-08-30 10:15:56 +02:00
Sebastian Wagner
e13087a9c4
target-information: fix territory-type for China 2019-08-30 10:08:19 +02:00
StefanKelm
49f8f60a85
Update threat-actor.json
Add ITG08 as synonym for FIN6
2019-08-29 13:13:00 +02:00
8d78a2a108
chg: [threat-actor] jq all 2019-08-29 08:31:10 +02:00
791c88f2eb
Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master 2019-08-29 08:30:41 +02:00
Deborah Servili
395dd93e0f
add Asruex Backdoor 2019-08-28 15:40:03 +02:00
9926ea8826
chg: [threat-actor] LYCEUM added - 443 #fixed 2019-08-28 14:35:12 +02:00
Deborah Servili
ea68336b96
add ref for Gamaredon 2019-08-27 08:28:58 +02:00
Deborah Servili
300e3c2bfb
More clusters improved 2019-08-26 17:50:20 +02:00
775b6d1a09
Merge pull request #440 from Delta-Sierra/target-location-galaxy
Target location galaxy
2019-08-23 16:29:23 +02:00
Deborah Servili
fcded146c2
More clusters improved 2019-08-23 16:01:12 +02:00
Deborah Servili
bae47241f0
More clusters improved 2019-08-23 11:14:14 +02:00
a68577a967
Merge pull request #439 from Delta-Sierra/target-location-galaxy
Target location galaxy
2019-08-22 16:24:57 +02:00
Deborah Servili
a579c041d2
More clusters improved 2019-08-22 15:59:11 +02:00
Deborah Servili
b7a97d1baf
More clusters improved 2019-08-22 11:49:09 +02:00
Deborah Servili
6944236943
more countries 2019-08-20 15:24:16 +02:00
Sebastian Wagner
38aebbf42a
remove empty strings 2019-08-19 17:04:07 +02:00
Deborah Servili
93ca9a3123
Merge pull request #437 from Delta-Sierra/target-location-galaxy
Target location galaxy
2019-08-19 08:57:48 +02:00
Deborah Servili
754f8f2a48
complete more cluster + country is now an array 2019-08-14 16:30:28 +02:00
Deborah Servili
3e651e2d74
target-informatione - add membership member-of attribute - Example:member-of NATO 2019-08-13 15:36:10 +02:00
6ca4e4cb17
Merge pull request #436 from Delta-Sierra/target-location-galaxy
Target location galaxy
2019-08-13 15:17:41 +02:00
Deborah Servili
e00f139fa2
jq 2019-08-13 13:01:36 +02:00
Deborah Servili
9accc832e3
change attribute name 2019-08-13 12:08:03 +02:00
Deborah Servili
389a82701a
jq 2019-08-13 11:57:28 +02:00
Deborah Servili
e946ce66db
complete some clusters 2019-08-13 11:55:18 +02:00
d48d2ccd3e
Merge pull request #435 from hackunagi/master
Adding Amavaldo Banking Trojan
2019-08-10 18:53:05 +02:00
3841447e16
Merge pull request #434 from r0ny123/patch-1
added microsoft naming for the groups
2019-08-10 18:52:26 +02:00
Thomas Dupuy
df5c9057a1 add synonyme for Turla 2019-08-09 17:34:22 -04:00
Carlos Borges
d96dc39c5a
Adding Amavaldo Banking Trojan 2019-08-09 18:00:37 -03:00
Rony
feac39db6b
added microsoft naming for the groups 2019-08-09 22:19:09 +05:30
Thomas Dupuy
320e298549 update victims 2019-08-09 10:45:10 -04:00
Thomas Dupuy
1988662ee5 add APT41 2019-08-09 10:24:06 -04:00
Deborah Servili
e239619d15
jq 2019-08-06 15:42:20 +02:00
Deborah Servili
53df0908c7
update version 2019-08-06 15:34:23 +02:00
Deborah Servili
4bef48b33e
add Amavaldo 2019-08-06 13:28:32 +02:00
Nils Kuhnert
17925f3e10
Remove local file link :) 2019-08-03 18:55:00 +02:00
Deborah Servili
21318cdf3d
fix building mistakes 2019-08-02 16:28:32 +02:00
7913adad61
chg: [threat-actor] rollback as discussed by chat with Andras until version 2.0 2019-08-02 16:08:40 +02:00
Andras Iklody
984be50396
lowercased value field for DarkHotel 2019-08-02 15:40:31 +02:00
17452d31a7
chg: [att&ck] July ATT&CK release included in MISP galaxy 2019-08-01 15:51:03 +02:00
a401ff7405
Merge branch 'master' into patch-13 2019-08-01 08:52:27 +02:00
Daniel Plohmann
0367e16ce0
adding secureworks actor names for energetic bear and teamspy 2019-07-31 14:35:09 +02:00
Daniel Plohmann
a4a72d0698
adding Proofpoint's TA428 2019-07-31 14:08:50 +02:00
Deborah Servili
08f713cb7d add tld
Signed-off-by: Deborah Servili <deborah.servili@gmail.com>
2019-07-26 16:22:45 +02:00
Deborah Servili
427b424cf7
rename galaxy target-location -> target-information 2019-07-19 13:49:43 +02:00
Deborah Servili
294a8bf6a2
new galaxy target-location [DRAFT] 2019-07-19 10:30:47 +02:00
Deborah Servili
2861d2d78c
jq 2019-07-16 10:13:10 +02:00
Deborah Servili
ea4d8a2d42
add SWEED threat actor 2019-07-16 10:03:07 +02:00
Deborah Servili
ca45f0deec
jq 2019-06-24 10:22:38 +02:00
Deborah Servili
32ffc98e5d
add Felipe Trojan 2019-06-24 10:20:29 +02:00
9517c8b878
chg: [threat-actor] version updated 2019-06-20 17:58:35 +02:00
8c90f7231c
chg: [threat-actor] duplicated refs removed 2019-06-20 17:35:35 +02:00
5e9d075ae5
chg: [threat-actor] synonyms fixed 2019-06-20 17:30:01 +02:00
195406cc6b
chg: [threat-actor] jq everything 2019-06-20 17:27:55 +02:00
d018519700
Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy 2019-06-20 17:23:04 +02:00
Deborah Servili
30f042211b
fix duplicate 2019-06-20 16:35:49 +02:00
Deborah Servili
a984786c8b
update threat actor galaxy 2019-06-20 16:25:23 +02:00
Rony
7afb9083b2
Update threat-actor.json 2019-06-19 23:29:35 +05:30
Deborah Servili
4bd37e2b2d
update threat actor galaxy 2019-06-19 16:38:04 +02:00
Deborah Servili
52e51833de
update threat actor galaxy 2019-06-18 16:05:49 +02:00
Deborah Servili
431e7a36c1
update threat actor galaxy 2019-06-17 16:36:42 +02:00
Deborah Servili
b966369933
##COMMA## 2019-06-14 16:35:55 +02:00
Deborah Servili
1e5292d999
fix duplicate 2019-06-14 16:21:33 +02:00
Deborah Servili
ead217eb28
Update version 2019-06-14 16:11:02 +02:00
Deborah Servili
98f0572d51
update threat actor galaxy 2019-06-14 16:06:09 +02:00
Deborah Servili
b040f9f57b
fix duplicate and links update (APT34) 2019-06-14 08:41:38 +02:00
Deborah Servili
2001652dae
fix duplicate 2019-06-14 08:28:44 +02:00
Deborah Servili
20e77afcc3
update threat actor galaxy 2019-06-13 16:19:21 +02:00
Deborah Servili
11c2f43c9f
tryto fix duplicate 2019-06-13 11:26:42 +02:00
Deborah Servili
e4245ee991
update threat actor galaxy 2019-06-12 16:25:24 +02:00
Deborah Servili
5a3d7e816f
fix duplicate 2019-06-12 09:24:05 +02:00
Deborah Servili
01fade422f Merge branch 'master' of https://github.com/MISP/misp-galaxy 2019-06-12 09:20:38 +02:00
Deborah Servili
1ba7f19ca2
update threat actor galaxy 2019-06-11 16:14:58 +02:00
Deborah Servili
347ed5d529
jq 2019-06-11 15:57:21 +02:00
Deborah Servili
79f11de6db
update threat actor galaxy 2019-06-11 15:54:39 +02:00
Deborah Servili
d6b458520b
update threat actor galaxy 2019-06-11 11:57:04 +02:00
8c69da1fd9
Merge pull request #413 from Delta-Sierra/master
update threat actor galaxy
2019-06-07 20:14:49 +02:00
Deborah Servili
1f2e59addb
update Threat actor galaxy 2019-06-07 16:34:43 +02:00
Deborah Servili
185763a63a
update threat actor 2019-06-06 16:34:09 +02:00
Deborah Servili
b809b9cfbb
update threat actor darkhotel (nemim might be a typo) 2019-06-06 11:58:19 +02:00
Deborah Servili
189c3066a5
update threat actor 2019-06-04 16:32:39 +02:00
3948cc24c1
Merge pull request #412 from Delta-Sierra/master
update threat actors and tools
2019-06-04 09:56:47 +02:00
Deborah Servili
468800ed59
FlawedAmmy RAT 2019-06-04 09:10:44 +02:00
Deborah Servili
a6c9d335ee
fix multiple refs 2019-06-04 08:52:34 +02:00
Deborah Servili
b47863f1c1
update threat actors 2019-05-29 16:18:50 +02:00
Deborah Servili
f48167ce77
update threat actors 2019-05-29 15:34:20 +02:00
Deborah Servili
f4cf3464ce
update threat actors and tools 2019-05-28 16:05:54 +02:00
9eac2a3923
Merge pull request #411 from Delta-Sierra/master
update threat-actor galaxy
2019-05-28 09:37:14 +02:00
Deborah Servili
bf19ed9d8d
fix merge mistakes 2019-05-28 09:26:24 +02:00
Deborah Servili
77d20739db
update threat actor 2019-05-28 09:24:29 +02:00
Deborah Servili
940762e0c5
update threat actor 2019-05-28 09:22:26 +02:00
Deborah Servili
0bb1420ab7
update threat-actor galaxy 2019-05-27 16:38:01 +02:00
Deborah Servili
af6241fd20
update Anchor Panda Threat Actor 2019-05-27 11:47:05 +02:00
555a87275f
Merge pull request #409 from rmkml/master
Add GetCrypt Ransomware
2019-05-25 13:56:30 +02:00
rmkml
de9cc6898a Add GetCrypt Ransomware 2019-05-25 13:30:15 +02:00
3420e50bfd
Merge pull request #408 from rmkml/master
Add Phobos Ransomware
2019-05-25 08:42:26 +02:00
1ece51ed48
chg: [branded_vulnerability] version updated 2019-05-25 08:41:33 +02:00
rmkml
6f140ce358
Merge branch 'master' into master 2019-05-25 00:03:34 +02:00
Deborah Servili
0d97013022
add BlueKeep 2019-05-24 15:55:58 +02:00
Deborah Servili
9d8d5ce1c8
fix ransomware ransomnotes 2019-05-23 16:23:09 +02:00
Deborah Servili
f5a7efaadc
jq 2019-05-23 12:39:53 +02:00
Deborah Servili
b4e4d2e539
rework of ransomware galaxy 2019-05-23 12:39:33 +02:00
Daniel Plohmann
1cc0137c38
adding TA542 to MUMMY SPIDER (emotet) 2019-05-17 17:36:57 +02:00
Rony
380006ecbb
merging Pacifier & Turla 2019-05-16 23:57:49 +05:30
32af463dd1
Merge pull request #403 from Delta-Sierra/master
add Reaver and probably related tools
2019-05-16 17:04:14 +02:00
Deborah Servili
9f801122da
add Reaver and probably related tools 2019-05-16 15:45:03 +02:00
Daniel Plohmann
a20f7fbe91
adding APT31/ZIRCONIUM 2019-05-15 22:43:33 +02:00
rmkml
cd58833770 Add Phobos Ransomware 2019-05-15 21:02:32 +02:00
Raphaël Vinot
59869bf145 fix: o365-exchange-techniques (duplicate values, duplicate UUIDs) 2019-05-13 11:15:38 +02:00
Deborah Servili
f8e356e042
Merge pull request #400 from Delta-Sierra/master
add Sodinokibi
2019-05-13 08:50:26 +02:00
678b2a5621
chg: [o365-exchange-techniques] Actions on Intent added (finalized) 2019-05-12 18:25:01 +02:00
5d1565152c
chg: [o365-exchange-techniques] Expansion added (WiP) 2019-05-12 18:19:00 +02:00
ee0f793e49
chg: [o365-exchange-techniques] Persistence kill-chain added (WiP) 2019-05-12 17:54:53 +02:00
3a75c6a3df
chg: [o365-exchange-techniques] Compromise row added (WiP) 2019-05-12 12:07:30 +02:00
a2df5c46d8
chg: [o365-exchange-techniques] [WiP] based on John Lambert matrix techniques 2019-05-12 09:51:41 +02:00
Rony
7c0ea4949a
Update threat-actor.json 2019-05-12 11:11:09 +05:30
Deborah Servili
5bbb0ab53d
add Sodinokibi 2019-05-08 15:54:37 +02:00
Raphaël Vinot
82ebbc6612 fix: UUID issues 2019-05-07 12:09:39 +02:00
Raphaël Vinot
988586fde0 fix: Duplicate values, typos. 2019-05-06 17:17:16 +02:00
36f317b4a8
Merge pull request #395 from Delta-Sierra/master
add Scranos
2019-05-03 16:22:20 +02:00
Deborah Servili
ad00477c87
add Scarnos 2019-05-03 15:55:19 +02:00
6aa7c39714
Merge pull request #394 from StefanKelm/master
Update threat-actor.json
2019-05-02 16:50:25 +02:00
20007e7b7c
Merge pull request #393 from Delta-Sierra/master
add AESDDoS Botnet and JasperLoader
2019-05-02 16:48:55 +02:00
StefanKelm
7e329855b2
Update threat-actor.json
Silent Librarian / COBALT DICKENS
2019-05-02 15:34:19 +02:00
b77087d59e
chg: [malpedia] duplicates fixed 2019-05-02 14:48:17 +02:00
b706738d46
chg: [malpedia] jq all the things 2019-05-02 14:47:00 +02:00
1ddb38341b
Merge branch 'master' of https://github.com/nao-sec/misp-galaxy into nao-sec-master 2019-05-02 14:46:34 +02:00
Deborah Servili
dda2ede5f2
add JasperLoader 2019-05-02 13:02:00 +02:00
Deborah Servili
f51f13e84b
add AESDDoS Botnet 2019-05-02 10:15:26 +02:00
37da9bebdf
chg: [threat-actor] FIN4 updates 2019-05-01 17:41:03 +02:00
Rony
0afaf81438
Update threat-actor.json 2019-05-01 15:54:38 +05:30
Rony
c565f61761
Update threat-actor.json 2019-05-01 15:51:56 +05:30
Rony
3b185d8435
Update threat-actor.json 2019-05-01 15:40:10 +05:30
Rony
ed351b4eae
updated FIN4 2019-05-01 15:24:59 +05:30
94466d8196
chg: [ATT&CK] updated to the latest version 2019-04-30 19:07:57 +02:00
Rintaro KOIKE
57735a5b5c
chg: [malpedia] updated to the latest version
Ref: https://malpedia.caad.fkie.fraunhofer.de/api/get/misp
2019-04-30 20:41:12 +09:00
f9a030ce54
chg: [exploit-kit] jq all the things 2019-04-28 19:12:06 +02:00
82a85d1651
Merge branch 'master' of https://github.com/Kafeine/misp-galaxy into Kafeine-master 2019-04-28 19:11:20 +02:00
Kafeine
915b673b7a
+= Spelevo 2019-04-28 12:24:48 +02:00
2405f1c59e
chg: [tool] Cowboy and KimJongRAT (Sorry Paul, we forgot ;-)
ref: https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/
2019-04-27 09:33:55 +02:00