MISP data models - MISP core format - MISP taxonomies

MISP is not only a software but also a series of data models created by the MISP community. MISP includes a simple and practical information sharing format expressed in JSON that can be used with MISP software or by any other software. The MISP formats are now standards handled by the MISP standard body.

MISP Core Format

The MISP core format is a simple JSON format used by MISP and other tools to exchange events and attributes. The JSON schema 2.4 is described on the MISP core software and many sample files are available in the OSINT feed.

The MISP format is described as Internet-Draft in misp-rfc. The MISP format are described to support the developer or organisation willing to build your own tool supporting the MISP format (as import or export). The standard is built from practical use-cases and the implementation references within the MISP project. The standard is quickly evolving following the MISP implementation.

MISP default attributes and categories

Attribute Categories vs. Types

Category Antivirus detection Artifacts dropped Attribution External analysis Financial fraud Internal reference
AS X
aba-rtn X
anonymised X X X X X X
attachment X X X
authentihash X
azure-application-id
bank-account-nr X
bic X
bin X
boolean
bro X
btc X
campaign-id X
campaign-name X
cc-number X
cdhash X
chrome-extension-id
comment X X X X X X
community-id X
cookie X
cortex X
counter
country-of-residence
cpe X
dash X
date-of-birth
datetime
dkim
dkim-signature
dns-soa-email X
dom-hash X
domain X
domain|ip X
email X
email-attachment
email-body
email-dst
email-dst-display-name
email-header
email-message-id
email-mime-boundary
email-reply-to
email-src
email-src-display-name
email-subject
email-thread-index
email-x-mailer
eppn
favicon-mmh3
filename X X
filename-pattern X X
filename|authentihash X
filename|impfuzzy X
filename|imphash X
filename|md5 X X
filename|pehash X
filename|sha1 X X
filename|sha224 X
filename|sha256 X X
filename|sha3-224 X X
filename|sha3-256 X X
filename|sha3-384 X X
filename|sha3-512 X X
filename|sha384 X
filename|sha512 X
filename|sha512/224 X
filename|sha512/256 X
filename|ssdeep X
filename|tlsh X
filename|vhash X
first-name
float
frequent-flyer-number
full-name
gender
gene X
git-commit-id X
github-organisation
github-repository X
github-username
hassh-md5 X
hasshserver-md5 X
hex X X X X
hostname X
hostname|port
http-method
iban X
identity-card-number
impfuzzy X
imphash X
integer
ip-dst X
ip-dst|port X
ip-src X
ip-src|port X
issue-date-of-the-visa
ja3-fingerprint-md5 X
jabber-id
jarm-fingerprint X
kusto-query X
last-name
link X X X
mac-address X
mac-eui-64 X
malware-sample X X
malware-type
md5 X X
middle-name
mime-type X
mobile-application-id
mutex X
named pipe X
nationality
onion-address X
other X X X X X X
passenger-name-record-locator-number
passport-country
passport-expiration
passport-number
pattern-in-file X X
pattern-in-memory X X
pattern-in-traffic X
payment-details
pdb X
pehash
pgp-private-key X
pgp-public-key X
phone-number X
place-of-birth
place-port-of-clearance
place-port-of-onward-foreign-destination
place-port-of-original-embarkation
port
primary-residence
process-state X
prtn X
redress-number
regkey X X
regkey|value X X
sha1 X X
sha224 X
sha256 X X
sha3-224 X X
sha3-256 X X
sha3-384 X X
sha3-512 X X
sha384 X
sha512 X
sha512/224 X
sha512/256 X
sigma X
size-in-bytes
snort X
special-service-request
ssdeep X
ssh-fingerprint
stix2-pattern X
target-email
target-external
target-location
target-machine
target-org
target-user
telfhash X
text X X X X X X
threat-actor X
tlsh
travel-details
twitter-id
uri
url X
user-agent X
uuid
vhash X
visa-number
vulnerability X
weakness X
whois-creation-date X
whois-registrant-email X
whois-registrant-name X
whois-registrant-org X
whois-registrant-phone X
whois-registrar X
windows-scheduled-task X
windows-service-displayname X
windows-service-name X
x509-fingerprint-md5 X X X
x509-fingerprint-sha1 X X X
x509-fingerprint-sha256 X X X
xmr X
yara X
zeek X
Category Network activity Other Payload delivery Payload installation Payload type Persistence mechanism
AS X X
aba-rtn
anonymised X X X X X X
attachment X X X
authentihash X X
azure-application-id X X
bank-account-nr
bic
bin
boolean X
bro X
btc
campaign-id
campaign-name
cc-number
cdhash X X
chrome-extension-id X X
comment X X X X X X
community-id X
cookie X
cortex
counter X
country-of-residence
cpe X X X
dash
date-of-birth
datetime X
dkim X
dkim-signature X
dns-soa-email
dom-hash X
domain X X
domain|ip X
email X X
email-attachment X
email-body X
email-dst X X
email-dst-display-name X
email-header X
email-message-id X
email-mime-boundary X
email-reply-to X
email-src X X
email-src-display-name X
email-subject X X
email-thread-index X
email-x-mailer X
eppn X
favicon-mmh3 X
filename X X X
filename-pattern X X X
filename|authentihash X X
filename|impfuzzy X X
filename|imphash X X
filename|md5 X X
filename|pehash X X
filename|sha1 X X
filename|sha224 X X
filename|sha256 X X
filename|sha3-224 X X
filename|sha3-256 X X
filename|sha3-384 X X
filename|sha3-512 X X
filename|sha384 X X
filename|sha512 X X
filename|sha512/224 X X
filename|sha512/256 X X
filename|ssdeep X X
filename|tlsh X X
filename|vhash X X
first-name
float X
frequent-flyer-number
full-name
gender
gene
git-commit-id
github-organisation
github-repository
github-username
hassh-md5 X X
hasshserver-md5 X X
hex X X X X X
hostname X X
hostname|port X X
http-method X
iban
identity-card-number
impfuzzy X X
imphash X X
integer X
ip-dst X X
ip-dst|port X X
ip-src X X
ip-src|port X X
issue-date-of-the-visa
ja3-fingerprint-md5 X X
jabber-id
jarm-fingerprint X X
kusto-query
last-name
link X
mac-address X X
mac-eui-64 X X
malware-sample X X
malware-type X X
md5 X X
middle-name
mime-type X X
mobile-application-id X X
mutex
named pipe
nationality
onion-address X X
other X X X X X X
passenger-name-record-locator-number
passport-country
passport-expiration
passport-number
pattern-in-file X X X
pattern-in-memory X
pattern-in-traffic X X X
payment-details
pdb
pehash X X
pgp-private-key X
pgp-public-key X
phone-number X
place-of-birth
place-port-of-clearance
place-port-of-onward-foreign-destination
place-port-of-original-embarkation
port X X
primary-residence
process-state
prtn
redress-number
regkey X
regkey|value X
sha1 X X
sha224 X X
sha256 X X
sha3-224 X X
sha3-256 X X
sha3-384 X X
sha3-512 X X
sha384 X X
sha512 X X
sha512/224 X X
sha512/256 X X
sigma X X
size-in-bytes X
snort X
special-service-request
ssdeep X X
ssh-fingerprint X
stix2-pattern X X X
target-email
target-external
target-location
target-machine
target-org
target-user
telfhash X X
text X X X X X X
threat-actor
tlsh X X
travel-details
twitter-id
uri X
url X X
user-agent X X
uuid X
vhash X X
visa-number
vulnerability X X
weakness X X
whois-creation-date
whois-registrant-email X
whois-registrant-name
whois-registrant-org
whois-registrant-phone
whois-registrar
windows-scheduled-task
windows-service-displayname
windows-service-name
x509-fingerprint-md5 X X X
x509-fingerprint-sha1 X X X
x509-fingerprint-sha256 X X X
xmr
yara X X
zeek X
Category Person Social network Support Tool Targeting data
AS
aba-rtn
anonymised X X X X
attachment X
authentihash
azure-application-id
bank-account-nr
bic
bin
boolean
bro
btc
campaign-id
campaign-name
cc-number
cdhash
chrome-extension-id
comment X X X X
community-id
cookie
cortex
counter
country-of-residence X
cpe
dash
date-of-birth X
datetime
dkim
dkim-signature
dns-soa-email
dom-hash
domain
domain|ip
email X X
email-attachment
email-body
email-dst X
email-dst-display-name
email-header
email-message-id
email-mime-boundary
email-reply-to
email-src X
email-src-display-name
email-subject
email-thread-index
email-x-mailer
eppn X
favicon-mmh3
filename
filename-pattern
filename|authentihash
filename|impfuzzy
filename|imphash
filename|md5
filename|pehash
filename|sha1
filename|sha224
filename|sha256
filename|sha3-224
filename|sha3-256
filename|sha3-384
filename|sha3-512
filename|sha384
filename|sha512
filename|sha512/224
filename|sha512/256
filename|ssdeep
filename|tlsh
filename|vhash
first-name X
float
frequent-flyer-number X
full-name X
gender X
gene
git-commit-id
github-organisation X
github-repository X
github-username X
hassh-md5
hasshserver-md5
hex X
hostname
hostname|port
http-method
iban
identity-card-number X
impfuzzy
imphash
integer
ip-dst
ip-dst|port
ip-src
ip-src|port
issue-date-of-the-visa X
ja3-fingerprint-md5
jabber-id X
jarm-fingerprint
kusto-query
last-name X
link X
mac-address
mac-eui-64
malware-sample
malware-type
md5
middle-name X
mime-type
mobile-application-id
mutex
named pipe
nationality X
onion-address
other X X X
passenger-name-record-locator-number X
passport-country X
passport-expiration X
passport-number X
pattern-in-file
pattern-in-memory
pattern-in-traffic
payment-details X
pdb
pehash
pgp-private-key X X
pgp-public-key X X
phone-number X
place-of-birth X
place-port-of-clearance X
place-port-of-onward-foreign-destination X
place-port-of-original-embarkation X
port
primary-residence X
process-state
prtn
redress-number X
regkey
regkey|value
sha1
sha224
sha256
sha3-224
sha3-256
sha3-384
sha3-512
sha384
sha512
sha512/224
sha512/256
sigma
size-in-bytes
snort
special-service-request X
ssdeep
ssh-fingerprint
stix2-pattern
target-email X
target-external X
target-location X
target-machine X
target-org X
target-user X
telfhash
text X X X
threat-actor
tlsh
travel-details X
twitter-id X
uri
url
user-agent
uuid
vhash
visa-number X
vulnerability
weakness
whois-creation-date
whois-registrant-email X
whois-registrant-name
whois-registrant-org
whois-registrant-phone
whois-registrar
windows-scheduled-task
windows-service-displayname
windows-service-name
x509-fingerprint-md5
x509-fingerprint-sha1
x509-fingerprint-sha256
xmr
yara
zeek

Categories

  • Antivirus detection: All the info about how the malware is detected by the antivirus products
  • Artifacts dropped: Any artifact (files, registry keys etc.) dropped by the malware or other modifications to the system
  • Attribution: Identification of the group, organisation, or country behind the attack
  • External analysis: Any other result from additional analysis of the malware like tools output
  • Financial fraud: Financial Fraud indicators
  • Internal reference: Reference used by the publishing party (e.g. ticket number)
  • Network activity: Information about network traffic generated by the malware
  • Other: Attributes that are not part of any other category or are meant to be used as a component in MISP objects
  • Payload delivery: Information about how the malware is delivered
  • Payload installation: Info on where the malware gets installed in the system
  • Payload type: Information about the final payload(s)
  • Persistence mechanism: Mechanisms used by the malware to start at boot
  • Person: A human being - natural person
  • Social network: Social networks and platforms
  • Support Tool: Tools supporting analysis or detection of the event
  • Targeting data: Internal Attack Targeting and Compromise Information

Types

  • AS: Autonomous system
  • aba-rtn: ABA routing transit number
  • anonymised: Anonymised value - described with the anonymisation object via a relationship
  • attachment: Attachment with external information
  • authentihash: Authenticode executable signature hash
  • azure-application-id: Azure Application ID.
  • bank-account-nr: Bank account number without any routing number
  • bic: Bank Identifier Code Number also known as SWIFT-BIC, SWIFT code or ISO 9362 code
  • bin: Bank Identification Number
  • boolean: Boolean value - to be used in objects
  • bro: An NIDS rule in the Bro rule-format
  • btc: Bitcoin Address
  • campaign-id: Associated campaign ID
  • campaign-name: Associated campaign name
  • cc-number: Credit-Card Number
  • cdhash: An Apple Code Directory Hash, identifying a code-signed Mach-O executable file
  • chrome-extension-id: Chrome extension id
  • comment: Comment or description in a human language
  • community-id: A community ID flow hashing algorithm to map multiple traffic monitors into common flow id
  • cookie: HTTP cookie as often stored on the user web client. This can include authentication cookie or session cookie.
  • cortex: Cortex analysis result
  • counter: An integer counter, generally to be used in objects
  • country-of-residence: The country of residence of a natural person
  • cpe: Common Platform Enumeration - structured naming scheme for information technology systems, software, and packages.
  • dash: Dash Address
  • date-of-birth: Date of birth of a natural person (in YYYY-MM-DD format)
  • datetime: Datetime in the ISO 8601 format
  • dkim: DKIM public key
  • dkim-signature: DKIM signature
  • dns-soa-email: RFC 1035 mandates that DNS zones should have a SOA (Statement Of Authority) record that contains an email address where a PoC for the domain could be contacted. This can sometimes be used for attribution/linkage between different domains even if protected by whois privacy
  • dom-hash: A dom-hash algorithm is a structural fingerprint of an HTML Document Object Model where all tag names are contained in a single string separated by a pipe. The truncated SHA252 value by the first 32-character serves as fingerprint.
  • domain: A domain name used in the malware
  • domain|ip: A domain name and its IP address (as found in DNS lookup) separated by a |
  • email: An email address
  • email-attachment: File name of the email attachment.
  • email-body: Email body
  • email-dst: The destination email address. Used to describe the recipient when describing an e-mail.
  • email-dst-display-name: Email destination display name
  • email-header: Email header
  • email-message-id: The email message ID
  • email-mime-boundary: The email mime boundary separating parts in a multipart email
  • email-reply-to: Email reply to header
  • email-src: The source email address. Used to describe the sender when describing an e-mail.
  • email-src-display-name: Email source display name
  • email-subject: The subject of the email
  • email-thread-index: The email thread index header
  • email-x-mailer: Email x-mailer header
  • eppn: eduPersonPrincipalName - eppn - the NetId of the person for the purposes of inter-institutional authentication. Should be stored in the form of user@univ.edu, where univ.edu is the name of the local security domain.
  • favicon-mmh3: favicon-mmh3 is the murmur3 hash of a favicon as used in Shodan.
  • filename: Filename
  • filename-pattern: A pattern in the name of a file
  • filename|authentihash: A filename and Authenticode executable signature hash
  • filename|impfuzzy: Import fuzzy hash - a fuzzy hash created based on the imports in the sample.
  • filename|imphash: Import hash - a hash created based on the imports in the sample.
  • filename|md5: A filename and an MD5 hash separated by a |
  • filename|pehash: A filename and a peHash separated by a |
  • filename|sha1: A filename and an SHA1 hash separated by a |
  • filename|sha224: A filename and a SHA-224 hash separated by a |
  • filename|sha256: A filename and an SHA256 hash separated by a |
  • filename|sha3-224: A filename and an SHA3-224 hash separated by a |
  • filename|sha3-256: A filename and an SHA3-256 hash separated by a |
  • filename|sha3-384: A filename and an SHA3-384 hash separated by a |
  • filename|sha3-512: A filename and an SHA3-512 hash separated by a |
  • filename|sha384: A filename and a SHA-384 hash separated by a |
  • filename|sha512: A filename and a SHA-512 hash separated by a |
  • filename|sha512/224: A filename and a SHa-512/224 hash separated by a |
  • filename|sha512/256: A filename and a SHA-512/256 hash separated by a |
  • filename|ssdeep: A checksum in ssdeep format
  • filename|tlsh: A filename and a Trend Micro Locality Sensitive Hash separated by a |
  • filename|vhash: A filename and a VirusTotal hash separated by a |
  • first-name: First name of a natural person
  • float: A floating point value.
  • frequent-flyer-number: The frequent flyer number of a passenger
  • full-name: Full name of a natural person
  • gender: The gender of a natural person (Male, Female, Other, Prefer not to say)
  • gene: GENE - Go Evtx sigNature Engine
  • git-commit-id: A Git commit ID.
  • github-organisation: A GitHub organisation
  • github-repository: A GitHub repository
  • github-username: A GitHub user name
  • hassh-md5: hassh is a network fingerprinting standard which can be used to identify specific Client SSH implementations. The fingerprints can be easily stored, searched and shared in the form of an MD5 fingerprint.
  • hasshserver-md5: hasshServer is a network fingerprinting standard which can be used to identify specific Server SSH implementations. The fingerprints can be easily stored, searched and shared in the form of an MD5 fingerprint.
  • hex: A value in hexadecimal format
  • hostname: A full host/dnsname of an attacker
  • hostname|port: Hostname and port number separated by a |
  • http-method: HTTP method used by the malware (e.g. POST, GET, …).
  • iban: International Bank Account Number
  • identity-card-number: Identity card number
  • impfuzzy: A fuzzy hash of import table of Portable Executable format
  • imphash: Import hash - a hash created based on the imports in the sample.
  • integer: A generic integer generally to be used in objects
  • ip-dst: A destination IP address of the attacker or C&C server
  • ip-dst|port: IP destination and port number separated by a |
  • ip-src: A source IP address of the attacker
  • ip-src|port: IP source and port number separated by a |
  • issue-date-of-the-visa: The date on which the visa was issued
  • ja3-fingerprint-md5: JA3 is a method for creating SSL/TLS client fingerprints that should be easy to produce on any platform and can be easily shared for threat intelligence.
  • jabber-id: Jabber ID
  • jarm-fingerprint: JARM is a method for creating SSL/TLS server fingerprints.
  • kusto-query: Kusto query - Kusto from Microsoft Azure is a service for storing and running interactive analytics over Big Data.
  • last-name: Last name of a natural person
  • link: Link to an external information
  • mac-address: MAC address
  • mac-eui-64: MAC EUI-64 address
  • malware-sample: Attachment containing encrypted malware sample
  • malware-type:
  • md5: A checksum in MD5 format
  • middle-name: Middle name of a natural person
  • mime-type: A media type (also MIME type and content type) is a two-part identifier for file formats and format contents transmitted on the Internet
  • mobile-application-id: The application id of a mobile application
  • mutex: Mutex, use the format \BaseNamedObjects<Mutex>
  • named pipe: Named pipe, use the format .\pipe<PipeName>
  • nationality: The nationality of a natural person
  • onion-address: Onion service (formerly known as “hidden service”) address
  • other: Other attribute
  • passenger-name-record-locator-number: The Passenger Name Record Locator is a key under which the reservation for a trip is stored in the system. The PNR contains, among other data, the name, flight segments and address of the passenger. It is defined by a combination of five or six letters and numbers.
  • passport-country: The country in which the passport was issued
  • passport-expiration: The expiration date of a passport
  • passport-number: The passport number of a natural person
  • pattern-in-file: Pattern in file that identifies the malware
  • pattern-in-memory: Pattern in memory dump that identifies the malware
  • pattern-in-traffic: Pattern in network traffic that identifies the malware
  • payment-details: Payment details
  • pdb: Microsoft Program database (PDB) path information
  • pehash: peHash - a hash calculated based of certain pieces of a PE executable file
  • pgp-private-key: A PGP private key
  • pgp-public-key: A PGP public key
  • phone-number: Telephone Number
  • place-of-birth: Place of birth of a natural person
  • place-port-of-clearance: The port of clearance
  • place-port-of-onward-foreign-destination: A Port where the passenger is transiting to
  • place-port-of-original-embarkation: The original port of embarkation
  • port: Port number
  • primary-residence: The primary residence of a natural person
  • process-state: State of a process
  • prtn: Premium-Rate Telephone Number
  • redress-number: The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems
  • regkey: Registry key or value
  • regkey|value: Registry value + data separated by |
  • sha1: A checksum in SHA1 format
  • sha224: A checksum in SHA-224 format
  • sha256: A checksum in SHA256 format
  • sha3-224: A checksum in SHA3-224 format
  • sha3-256: A checksum in SHA3-256 format
  • sha3-384: A checksum in SHA3-384 format
  • sha3-512: A checksum in SHA3-512 format
  • sha384: A checksum in SHA-384 format
  • sha512: A checksum in SHA-512 format
  • sha512/224: A checksum in the SHA-512/224 format
  • sha512/256: A checksum in the SHA-512/256 format
  • sigma: Sigma - Generic Signature Format for SIEM Systems
  • size-in-bytes: Size expressed in bytes
  • snort: An IDS rule in Snort rule-format
  • special-service-request: A Special Service Request is a function to an airline to provide a particular facility for A Passenger or passengers.
  • ssdeep: A checksum in ssdeep format
  • ssh-fingerprint: A fingerprint of SSH key material
  • stix2-pattern: STIX 2 pattern
  • target-email: Attack Targets Email(s)
  • target-external: External Target Organizations Affected by this Attack
  • target-location: Attack Targets Physical Location(s)
  • target-machine: Attack Targets Machine Name(s)
  • target-org: Attack Targets Department or Organization(s)
  • target-user: Attack Targets Username(s)
  • telfhash: telfhash is symbol hash for ELF files, just like imphash is imports hash for PE files.
  • text: Name, ID or a reference
  • threat-actor: A string identifying the threat actor
  • tlsh: A checksum in the Trend Micro Locality Sensitive Hash format
  • travel-details: Travel details
  • twitter-id: Twitter ID
  • uri: Uniform Resource Identifier
  • url: Uniform Resource Locator
  • user-agent: The user-agent used by the malware in the HTTP request.
  • uuid: UUID - to be used in objects
  • vhash: A VirusTotal checksum
  • visa-number: Visa number
  • vulnerability: A reference to the vulnerability (examples: GCVE id, CVE id, GHSA id, etc)
  • weakness: A reference to the weakness (CWE) used in the exploit
  • whois-creation-date: The date of domain’s creation, obtained from the WHOIS information.
  • whois-registrant-email: The e-mail of a domain’s registrant, obtained from the WHOIS information.
  • whois-registrant-name: The name of a domain’s registrant, obtained from the WHOIS information.
  • whois-registrant-org: The org of a domain’s registrant, obtained from the WHOIS information.
  • whois-registrant-phone: The phone number of a domain’s registrant, obtained from the WHOIS information.
  • whois-registrar: The registrar of the domain, obtained from the WHOIS information.
  • windows-scheduled-task: A scheduled task in windows
  • windows-service-displayname: A windows service’s displayname, not to be confused with the windows-service-name. This is the name that applications will generally display as the service’s name in applications.
  • windows-service-name: A windows service name. This is the name used internally by windows. Not to be confused with the windows-service-displayname.
  • x509-fingerprint-md5: X509 fingerprint in MD5 format
  • x509-fingerprint-sha1: X509 fingerprint in SHA-1 format
  • x509-fingerprint-sha256: X509 fingerprint in SHA-256 format
  • xmr: Monero Address
  • yara: YARA signature
  • zeek: An NIDS rule in the Zeek rule-format

MISP objects

MISP objects are in addition to MISP attributes to allow advanced combinations of attributes. The creation of these objects and their associated attributes are based on real cyber security use-cases and existing practices in information sharing. MISP objects are standardised under a simple templating format and are automatically available in MISP. A series of relationships are also defined along with the objects which can be used to create relationships between objects.

The objects available can be browsed via the web site or downloaded as PDF or directly via the MISP software.

MISP Taxonomies

Along with the core format, MISP taxonomies provide a set of already defined classifications modeling estimative language, CSIRTs/CERTs classifications, national classifications or threat model classification. The fixed taxonomies provide a practical method to tag efficiently events and attributes within a set of MISP instances where taxonomies can be easily cherry-picked or extended to meet the local requirements of an organization or a specific sharing community. When using MISP, the MISP taxonomies are available and can be freely used based on the community practises.

The taxonomies can be browsed via the web site or downloaded as PDF or via the MISP software.

Community classification library

Find the right vocabulary for your events and attributes.

185 taxonomies1,316 predicates13,297 defined tags
Download all metadata (JSON) ↓

Search includes predicate and value labels, descriptions, references and full machine tags.

Showing all 185 taxonomies

abuseipdb

v1

AbuseIPDB

Classifying IP indicators using AbuseIPDB report.

Tag examples & metadata
  • abuseipdb:category="1"
  • abuseipdb:category="2"
  • abuseipdb:category="3"
Predicates
2
Defined values
27
UUID
29046bee-525a-4057-9e22-1b6e8ba658de
References
  • https://www.abuseipdb.com/categories

access-method

v1

Access method

The access method used to remotely access a system.

Tag examples & metadata
  • access-method:brute-force
  • access-method:password-guessing
  • access-method:remote-desktop-application
Predicates
8
Defined values
0
UUID
f8953dae-9821-5003-8a6e-87f53370efc8

accessnow

v3

Access Now classification to classify an issue (such as security, human rights, youth rights).

Tag examples & metadata
  • accessnow:anti-corruption-transparency
  • accessnow:anti-war-violence
  • accessnow:culture
Predicates
22
Defined values
0
UUID
f0eb656a-dd77-5fdb-90aa-37fbe7e93533

acn

v1

Cyber taxonomy for Italian National Cybersecurity Agency (ACN)

Tag examples & metadata
  • acn:impact="account-compromise"
  • acn:impact="application-compromise"
  • acn:impact="availability"
Predicates
21
Defined values
219
UUID
c9127473-ee24-5fc7-87cb-58bd7e93c42e

acs-marking

v2

The Access Control Specification (ACS) marking type defines the object types required to implement automated access control systems based on the relevant policies governing sharing between participants.

Tag examples & metadata
  • acs-marking:privilege_action="DSPLY"
  • acs-marking:privilege_action="IDSRC"
  • acs-marking:privilege_action="TENOT"
Predicates
7
Defined values
46
UUID
d4d020f7-8107-50a3-8d9e-eb8cb4ab5bf7

action-taken

v2

Action taken in the case of a security incident (CSIRT perspective).

Tag examples & metadata
  • action-taken:informed ISP/Hosting Service Provider
  • action-taken:informed Registrar
  • action-taken:informed Registrant
Predicates
6
Defined values
0
UUID
f815ecf0-9879-5439-a2be-a4c56362eebb

admiralty-scale

v5

The Admiralty Scale or Ranking (also called the NATO System) is used to rank the reliability of a source and the credibility of an information. Reference based on FM 2-22.3 (FM 34-52) HUMAN INTELLIGENCE COLLECTOR OPERATIONS and NATO documents.

Tag examples & metadata
  • admiralty-scale:source-reliability="a"
  • admiralty-scale:source-reliability="b"
  • admiralty-scale:source-reliability="c"
Predicates
2
Defined values
13
UUID
97c896f5-df57-517f-be3b-46f7c2dfcaf4

adversary

v6

An overview and description of the adversary infrastructure

Tag examples & metadata
  • adversary:infrastructure-status="unknown"
  • adversary:infrastructure-status="compromised"
  • adversary:infrastructure-status="own-and-operated"
Predicates
4
Defined values
19
UUID
a13370c9-8114-5936-b6df-a7841db82280

agent-threat-rules

v3

Agent Threat Rules

Agent Threat Rules (ATR) is an open detection standard for AI agent threats published under the MIT licence. The taxonomy organises 713 community-maintained rules across ten attack categories covering prompt injection, tool poisoning, skill compromise, context exfiltration, agent manipulation, privilege escalation, excessive autonomy, model abuse, model security, and data poisoning. Predicates name the category; values are individual rule identifiers in the form ATR-YYYY-NNNNN.

Tag examples & metadata
  • agent-threat-rules:agent-manipulation="ATR-2026-00030"
  • agent-threat-rules:agent-manipulation="ATR-2026-00032"
  • agent-threat-rules:agent-manipulation="ATR-2026-00074"
Predicates
10
Defined values
713
UUID
86e4af11-c7bb-5b30-beb3-88eec124e4af
References
  • https://github.com/Agent-Threat-Rule/agent-threat-rules
  • https://github.com/Agent-Threat-Rule/ai-rmf-oscal-catalog

ai-bias-terminology

v1

A list of standalone definitions for each type of bias. Aggregate terms that are in common usage or relevance to AI bias. From NIST.SP.1270-draft (2021)

Tag examples & metadata
  • ai-bias-terminology:bias-definitions="activity-bias"
  • ai-bias-terminology:bias-definitions="amplification-bias"
  • ai-bias-terminology:bias-definitions="annotator-bias"
Predicates
1
Defined values
37
UUID
d60ff0b5-4e73-4f87-b48b-62fc7a1ee009

ai-computer-assisted

v1

AI Computer Assisted

Taxonomy describing the level of AI assistance and the level of review/update involved in the creation of an intelligence package or event.

Tag examples & metadata
  • ai-computer-assisted:assistance-level="none"
  • ai-computer-assisted:assistance-level="ai-assisted-minor"
  • ai-computer-assisted:assistance-level="ai-assisted-substantial"
Predicates
2
Defined values
10
Applies to
event
UUID
bd55f48b-4f46-4447-9b23-2ade3f1823bf

ai-safety-benchmark

v2

AI safety benchmark v0.5, that has been created by the MLCommons AI Safety Working Group (WG)

Tag examples & metadata
  • ai-safety-benchmark:violent-crimes="mass-violence"
  • ai-safety-benchmark:violent-crimes="murder"
  • ai-safety-benchmark:violent-crimes="physical-assault-against-a-person"
Predicates
7
Defined values
34
UUID
e1e1232a-bd97-4ff2-a1a9-146b91b7abf5

ais-marking

v2

The AIS Marking Schema implementation is maintained by the National Cybersecurity and Communication Integration Center (NCCIC) of the U.S. Department of Homeland Security (DHS)

Tag examples & metadata
  • ais-marking:TLPMarking="WHITE"
  • ais-marking:TLPMarking="GREEN"
  • ais-marking:TLPMarking="AMBER"
Predicates
4
Defined values
10
UUID
ef01864a-bfee-58a7-91ab-0cff1ed1a433

analyst-assessment

v4

Analyst (Self) Assessment

A series of assessment predicates describing the analyst capabilities to perform analysis. These assessment can be assigned by the analyst him/herself or by another party evaluating the analyst.

Tag examples & metadata
  • analyst-assessment:experience="less-than-1-year"
  • analyst-assessment:experience="between-1-and-5-years"
  • analyst-assessment:experience="between-5-and-10-years"
Predicates
7
Defined values
33
Applies to
org, user
UUID
9ec3a654-d15e-53a2-ad7b-856bd9971288

anti-piracy

v2

Taxonomy for anti-piracy

Tag examples & metadata
  • anti-piracy:type="copyright-infringement"
  • anti-piracy:type="illegal-gambling"
  • anti-piracy:case-status="ongoing"
Predicates
6
Defined values
30
UUID
6362e9ca-4e7d-598b-a2cb-4a14b05c32bb

approved-category-of-action

v1

Approved category of action

A pre-approved category of action for indicators being shared with partners (MIMIC).

Tag examples & metadata
  • approved-category-of-action:cat1
  • approved-category-of-action:cat2
  • approved-category-of-action:cat3
Predicates
6
Defined values
0
UUID
76c993c1-bf67-5cb6-94d1-ea7101c284e9

artificial-satellites

v1

Artificial satellites taxonomy

This taxonomy was designed to describe artificial satellites

Tag examples & metadata
  • artificial-satellites:Meteorological and Earth observation="3D-Winds"
  • artificial-satellites:Meteorological and Earth observation="ACE"
  • artificial-satellites:Meteorological and Earth observation="ACE (Aer.Clo.Eco.)"
Predicates
12
Defined values
2041
UUID
e4d51d5c-22b5-5b70-9ff6-4e96a3e7ec1b

aviation

v1

A taxonomy describing security threats or incidents against the aviation sector.

Tag examples & metadata
  • aviation:target="airline"
  • aviation:target="airspace users"
  • aviation:target="airport"
Predicates
7
Defined values
64
UUID
bf879f0c-4272-5b2f-86d7-7bb4265a2815

binary-class

v2

Custom taxonomy for types of binary file.

Tag examples & metadata
  • binary-class:type="good"
  • binary-class:type="malicious"
  • binary-class:type="unknown"
Predicates
1
Defined values
3
Exclusive taxonomy
Yes
UUID
38ee9d7b-844a-5591-b56b-8780c0ae8be0

carding

v1

Classifying content, activities, tools, and actors within carding forums and marketplaces: A categorisation model for law enforcement. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission, and subsequently re-extended by the Cátedra Ada Byron UAH-INCIBE.

Tag examples & metadata
  • carding:activity-context="marketplace"
  • carding:activity-context="forum-discussion"
  • carding:activity-context="login-portal"
Predicates
4
Defined values
19
UUID
6a295ea3-5b22-4092-bed8-d1a24e061368

cccs

v12

CCCS Custom Taxonomy

Tag examples & metadata
  • cccs:analytics="icecube"
  • cccs:analytics="ironclaw"
  • cccs:analytics="phishhook"
Predicates
14
Defined values
158
UUID
8639287e-2a00-4753-904b-2e23a72e7a29

ce-uas-classification

v2

European Union (EASA) Drone Classification - C0 to C6.

Tag examples & metadata
  • ce-uas-classification:C0
  • ce-uas-classification:C1
  • ce-uas-classification:C2
Predicates
7
Defined values
0
UUID
1596c572-b5b0-11f0-bbc2-325096b39f47
References
  • https://www.easa.europa.eu/en/document-library/general-publications/drone-class-identification-labels-and-information-notices

CERT-XLM

v2

CERT-XLM Security Incident Classification.

Tag examples & metadata
  • CERT-XLM:abusive-content="spam"
  • CERT-XLM:abusive-content="harmful-speech"
  • CERT-XLM:abusive-content="violence"
Predicates
12
Defined values
36
UUID
2b751334-656b-5186-9dcd-e13362939c31

circl

v6

CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection.

Tag examples & metadata
  • circl:incident-classification="spam"
  • circl:incident-classification="system-compromise"
  • circl:incident-classification="sabotage"
Predicates
3
Defined values
34
UUID
fbe4d192-d8b5-50e2-8e10-b8842ee61bd0

cloud-sovereignty

v1

Cloud Sovereignty Framework

Cloud sovereignty objectives, assurance levels, and scoring weights derived from the European Commission Cloud Sovereignty Framework.

Tag examples & metadata
  • cloud-sovereignty:objective="sov-1"
  • cloud-sovereignty:objective="sov-2"
  • cloud-sovereignty:objective="sov-3"
Predicates
3
Defined values
21
UUID
d8f36495-5fbe-4471-b972-34db2c51d085
References
  • https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en

cnsd

v20220513

CNSD Taxonomia de Incidentes de Seguridad Digital

La presente taxonomia es la primera versión disponible para el Centro Nacional de Seguridad Digital del Perú.

Tag examples & metadata
  • cnsd:Contenido abusivo="spam"
  • cnsd:Contenido abusivo="copyright"
  • cnsd:Contenido abusivo="explotacion sexual infantil"
Predicates
9
Defined values
26
UUID
5e59c815-c054-5211-86b1-b1683548ac89

coa

v2

Course of action taken within organization to discover, detect, deny, disrupt, degrade, deceive and/or destroy an attack.

Tag examples & metadata
  • coa:discover="proxy"
  • coa:discover="ids"
  • coa:discover="firewall"
Predicates
7
Defined values
61
UUID
53b5eab0-d465-53d0-9dcf-a34a9aa874e8

collaborative-intelligence

v3

collaborative intelligence support language

Collaborative intelligence support language is a common language to support analysts to perform their analysis to get crowdsourced support when using threat intelligence sharing platform like MISP. The objective of this language is to advance collaborative analysis and to share earlier than later.

Tag examples & metadata
  • collaborative-intelligence:request="sample"
  • collaborative-intelligence:request="extracted-malware-config"
  • collaborative-intelligence:request="deobfuscated-sample"
Predicates
1
Defined values
14
UUID
cdfee78b-ccf0-522c-9561-95ecbf2cf828

common-taxonomy

v3

Common Taxonomy for Law enforcement and CSIRTs

Tag examples & metadata
  • common-taxonomy:malware="infection"
  • common-taxonomy:malware="distribution"
  • common-taxonomy:malware="command-and-control"
Predicates
9
Defined values
22
UUID
2b701288-6e91-5366-bc3e-f86c57dd233b
References
  • https://www.europol.europa.eu/publications-documents/common-taxonomy-for-law-enforcement-and-csirts
  • https://www.enisa.europa.eu/publications/tools-and-methodologies-to-support-cooperation-between-csirts-and-law-enforcement

content-classification

v26060309

Content Classification

Classification taxonomy for labeling the primary subject matter, intent, market context, and thematic domain of online content, including general information, technology, cybersecurity, cybercrime, markets, communities, finance, illegal markets, technical services, and geopolitical or hacktivist material.

Tag examples & metadata
  • content-classification:general="news"
  • content-classification:general="politics"
  • content-classification:general="economy"
Predicates
11
Defined values
75
UUID
a365078f-6b53-587f-aafe-63091ce1513f

copine-scale

v3

COPINE Scale

The COPINE Scale is a rating system created in Ireland and used in the United Kingdom to categorise the severity of images of child sex abuse. The scale was developed by staff at the COPINE (Combating Paedophile Information Networks in Europe) project. The COPINE Project was founded in 1997, and is based in the Department of Applied Psychology, University College Cork, Ireland.

Tag examples & metadata
  • copine-scale:level-10
  • copine-scale:level-9
  • copine-scale:level-8
Predicates
10
Defined values
0
Exclusive taxonomy
Yes
UUID
fda27af7-7038-581a-a046-9a7b9deae57a
References
  • https://en.wikipedia.org/wiki/COPINE_scale
  • http://journals.sagepub.com/doi/pdf/10.1177/1079063217724768

course-of-action

v3

Courses of Action

A Course Of Action analysis considers six potential courses of action for the development of a cyber security capability.

Tag examples & metadata
  • course-of-action:passive="discover"
  • course-of-action:passive="nodiscover"
  • course-of-action:passive="detect"
Predicates
2
Defined values
8
UUID
6745838c-cae4-5dce-a241-a0da5bb8a0be

crowdsec

v1

Crowdsec IP address classifications and behaviors taxonomy.

Tag examples & metadata
  • crowdsec:behavior="database-bruteforce"
  • crowdsec:behavior="ftp-bruteforce"
  • crowdsec:behavior="generic-exploit"
Predicates
3
Defined values
54
UUID
3db85e55-2971-52e3-8f88-cddc8e9431bc

cryptocurrency-market

v1

Crypto Market

Crypto Market: A categorisation model for cryptocurrency transactions and risk flags. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission, and subsequently re-extended by the Cátedra Ada Byron UAH-INCIBE.

Tag examples & metadata
  • cryptocurrency-market:intent="buy"
  • cryptocurrency-market:intent="other"
  • cryptocurrency-market:intent="sell"
Predicates
3
Defined values
20
UUID
05317a96-7edf-42b7-9f0b-fff88d7f1e19

cryptocurrency-threat

v2

Threats targeting cryptocurrency, based on CipherTrace report.

Tag examples & metadata
  • cryptocurrency-threat:SIM Swapping
  • cryptocurrency-threat:Crypto Dusting
  • cryptocurrency-threat:Sanction Evasion
Predicates
12
Defined values
0
UUID
3c14e684-0ca7-5791-8e3e-2e369555aeaf
References
  • https://ciphertrace.com/wp-content/uploads/2019/01/crypto_aml_report_2018q4.pdf

csirt-americas

v1

Taxonomía CSIRT Américas.

Tag examples & metadata
  • csirt-americas:defacement
  • csirt-americas:malware
  • csirt-americas:ddos
Predicates
14
Defined values
0
UUID
3dce06ae-6d0c-5328-8962-ece187915c14

csirt_case_classification

v1

It is critical that the CSIRT provide consistent and timely response to the customer, and that sensitive information is handled appropriately. This document provides the guidelines needed for CSIRT Incident Managers (IM) to classify the case category, criticality level, and sensitivity level for each CSIRT case. This information will be entered into the Incident Tracking System (ITS) when a case is created. Consistent case classification is required for the CSIRT to provide accurate reporting to management on a regular basis. In addition, the classifications will provide CSIRT IM’s with proper case handling procedures and will form the basis of SLA’s between the CSIRT and other Company departments.

Tag examples & metadata
  • csirt_case_classification:incident-category="DOS"
  • csirt_case_classification:incident-category="forensics"
  • csirt_case_classification:incident-category="compromised-information"
Predicates
3
Defined values
17
UUID
7425d4fe-0be2-5786-b9c2-a6b8f1496117

cssa

v8

The CSSA agreed sharing taxonomy.

Tag examples & metadata
  • cssa:sharing-class="high_profile"
  • cssa:sharing-class="vetted"
  • cssa:sharing-class="unvetted"
Predicates
4
Defined values
14
UUID
7f2de2a2-fa82-5916-a5f7-7f062f37e6b5

cti

v1

Cyber Threat Intelligence cycle to control workflow state of your process.

Tag examples & metadata
  • cti:planning
  • cti:collection
  • cti:processing-and-analysis
Predicates
6
Defined values
0
UUID
074c6a53-14d1-5df9-9717-c616a340fb9c

cti-evaluation

v1

CTI evaluation

Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness.

Tag examples & metadata
  • cti-evaluation:overall-score="very-low"
  • cti-evaluation:overall-score="low"
  • cti-evaluation:overall-score="moderate"
Predicates
12
Defined values
60
UUID
b376f2ae-5e40-47fd-b680-bb0464107949

current-event

v1

Current events - Schemes of Classification in Incident Response and Detection

Tag examples & metadata
  • current-event:pandemic="sars-cov"
  • current-event:pandemic="covid-19"
  • current-event:election="eu-par-2019"
Predicates
2
Defined values
4
UUID
64c18fc1-2054-5f8d-88e2-6feecd7e41a7

cyber-threat-framework

v2

Cyber Threat Framework

Cyber Threat Framework was developed by the US Government to enable consistent characterization and categorization of cyber threat events, and to identify trends or changes in the activities of cyber adversaries. https://www.dni.gov/index.php/cyber-threat-framework

Tag examples & metadata
  • cyber-threat-framework:Preparation="plan-activity"
  • cyber-threat-framework:Preparation="conduct-research-and-analysis"
  • cyber-threat-framework:Preparation="develop-resource-and-capabilities"
Predicates
4
Defined values
19
UUID
982b223f-3ea8-55db-a6da-bebf1540a23a

cycat

v1

Universal Cybersecurity Resource Catalogue

Taxonomy used by CyCAT, the Universal Cybersecurity Resource Catalogue, to categorize the namespaces it supports and uses.

Tag examples & metadata
  • cycat:type="tool"
  • cycat:type="playbook"
  • cycat:type="taxonomy"
Predicates
2
Defined values
19
UUID
0a4ed543-b2b9-5748-8418-7cf2a6796e38
References
  • https://www.cycat.org/

cytomic-orion

v1

Taxonomy to describe desired actions for Cytomic Orion

Tag examples & metadata
  • cytomic-orion:action="upload"
  • cytomic-orion:action="delete"
Predicates
1
Defined values
2
UUID
2276c578-35c8-584d-8c7f-ce7447a21325

dark-web

v11

Dark Web

Criminal motivation and content detection the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission.

Tag examples & metadata
  • dark-web:topic="drugs-narcotics"
  • dark-web:topic="electronics"
  • dark-web:topic="finance"
Predicates
5
Defined values
101
UUID
73e689e1-a993-5962-bed6-6839f5e9d702

data-classification

v1

Data Classification

Data classification for data potentially at risk of exfiltration based on table 2.1 of Solving Cyber Risk book.

Tag examples & metadata
  • data-classification:regulated-data
  • data-classification:commercially-confidential-information
  • data-classification:financially-sensitive-information
Predicates
5
Defined values
0
UUID
0062b703-c194-5a98-bc13-7e2d66be6c0a
References
  • https://www.wiley.com/en-be/Solving+Cyber+Risk:+Protecting+Your+Company+and+Society-p-9781119490920

dcso-sharing

v2

Taxonomy defined in the DCSO MISP Event Guide. It provides guidance for the creation and consumption of MISP events in a way that minimises the extra effort for the sending party, while enhancing the usefulness for receiving parties.

Tag examples & metadata
  • dcso-sharing:event-type="Observation"
  • dcso-sharing:event-type="Incident"
  • dcso-sharing:event-type="Report"
Predicates
1
Defined values
8
UUID
fd8872e4-9be0-5c24-be70-3b3fd95257f2

ddos

v2

Distributed Denial of Service

Distributed Denial of Service - or short: DDoS - taxonomy supports the description of Denial of Service attacks and especially the types they belong too.

Tag examples & metadata
  • ddos:type="amplification-attack"
  • ddos:type="reflected-spoofed-attack"
  • ddos:type="slow-read-attack"
Predicates
1
Defined values
5
UUID
19a97dc6-18a1-5a1a-8436-0944e9bd1d8c
References
  • https://en.wikipedia.org/wiki/Denial-of-service_attack

de-vs

v1

German (DE) Government classification markings (VS).

Tag examples & metadata
  • de-vs:Einstufung="STRENG GEHEIM"
  • de-vs:Einstufung="GEHEIM"
  • de-vs:Einstufung="VS-VERTRAULICH"
Predicates
2
Defined values
5
UUID
199a6c57-375b-5740-9016-69494dc8964f

death-possibilities

v1

Taxonomy of Death Possibilities

Tag examples & metadata
  • death-possibilities:(001-009) Intestinal infectious diseases="001 Cholera"
  • death-possibilities:(001-009) Intestinal infectious diseases="002 Typhoid and paratyphoid fevers"
  • death-possibilities:(001-009) Intestinal infectious diseases="003 Other Salmonella infections"
Predicates
133
Defined values
1077
UUID
d8e541fa-dd32-5435-b23c-df7655284cff

deception

v1

Deception

Deception is an important component of information operations, valuable for both offense and defense.

Tag examples & metadata
  • deception:space="direction"
  • deception:space="location-at"
  • deception:space="location-from"
Predicates
7
Defined values
32
UUID
c01d29dd-e62d-5d84-875e-227158b13e6d
References
  • https://faculty.nps.edu/ncrowe/rowe_iciw06.htm

detection-engineering

v1

Detection engineering

Taxonomy related to detection engineering techniques

Tag examples & metadata
  • detection-engineering:pattern-matching="high"
  • detection-engineering:pattern-matching="medium"
  • detection-engineering:pattern-matching="low"
Predicates
1
Defined values
3
UUID
4bd3c32b-8f54-5f90-8d96-dae00aa8a529

DFRLab-dichotomies-of-disinformation

v1

DFRLab Dichotomies of Disinformation.

Tag examples & metadata
  • DFRLab-dichotomies-of-disinformation:primary-target="AD"
  • DFRLab-dichotomies-of-disinformation:primary-target="AE"
  • DFRLab-dichotomies-of-disinformation:primary-target="AF"
Predicates
17
Defined values
606
UUID
bd0e1c10-df2f-5cad-a596-26360e534b7b
References
  • https://github.com/DFRLab/Dichotomies-of-Disinformation/blob/master/20200204_Codebook.pdf

dga

v2

Domain-Generation Algorithms

A taxonomy to describe domain-generation algorithms often called DGA. Ref: A Comprehensive Measurement Study of Domain Generating Malware Daniel Plohmann and others.

Tag examples & metadata
  • dga:generation-scheme="arithmetic"
  • dga:generation-scheme="hash"
  • dga:generation-scheme="wordlist"
Predicates
2
Defined values
8
UUID
667e9c12-96f1-5f5b-9bc5-c480e43b8dfd

dhs-ciip-sectors

v2

DHS critical sectors as in https://www.dhs.gov/critical-infrastructure-sectors

Tag examples & metadata
  • dhs-ciip-sectors:DHS-critical-sectors="chemical"
  • dhs-ciip-sectors:DHS-critical-sectors="commercial-facilities"
  • dhs-ciip-sectors:DHS-critical-sectors="communications"
Predicates
2
Defined values
16
UUID
263b59a0-268b-5cc5-b4a9-0f32dfa86b66

diamond-model

v1

Diamond Model for Intrusion Analysis

The Diamond Model for Intrusion Analysis establishes the basic atomic element of any intrusion activity, the event, composed of four core features: adversary, infrastructure, capability, and victim.

Tag examples & metadata
  • diamond-model:Adversary
  • diamond-model:Capability
  • diamond-model:Infrastructure
Predicates
4
Defined values
0
UUID
8b0bd21c-bda6-5b16-97d9-e27ac0f31040
References
  • https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf

diamond-model-for-influence-operations

v1

The Diamond Model for Influence Operations Analysis

The diamond model for influence operations analysis is a framework that leads analysts and researchers toward a comprehensive understanding of a malign influence campaign by addressing the socio-political, technical, and psychological aspects of the campaign. The diamond model for influence operations analysis consists of 5 components: 4 corners and a core element. The 4 corners are divided into 2 axes: influencer and audience on the socio-political axis, capabilities and infrastructure on the technical axis. Narrative makes up the core of the diamond.

Tag examples & metadata
  • diamond-model-for-influence-operations:Influencer
  • diamond-model-for-influence-operations:Capabilities
  • diamond-model-for-influence-operations:Infrastructure
Predicates
5
Defined values
0
UUID
012d5680-7177-59d1-a087-9bac2935c43b
References
  • https://go.recordedfuture.com/hubfs/white-papers/diamond-model-influence-operations-analysis.pdf

DML

v1

Detection Maturity Level

The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks. It's designed for organizations who perform intel-driven detection and response and who put an emphasis on having a mature detection program.

Tag examples & metadata
  • DML:8
  • DML:7
  • DML:6
Predicates
9
Defined values
0
UUID
68fd7a37-b7ad-5b3f-a82a-7263cfc64e2c
References
  • http://ryanstillions.blogspot.lu/2014/04/the-dml-model_21.html

dni-ism

v3

A subset of Information Security Marking Metadata ISM as required by Executive Order (EO) 13526. As described by DNI.gov as Data Encoding Specifications for Information Security Marking Metadata in Controlled Vocabulary Enumeration Values for ISM

Tag examples & metadata
  • dni-ism:classification:all="R"
  • dni-ism:classification:all="C"
  • dni-ism:classification:all="S"
Predicates
9
Defined values
77
UUID
3e5c1c55-ef37-5f8c-a262-2a0215462f34

domain-abuse

v2

Domain Name Abuse

Domain Name Abuse - taxonomy to tag domain names used for cybercrime.

Tag examples & metadata
  • domain-abuse:domain-status="active"
  • domain-abuse:domain-status="inactive"
  • domain-abuse:domain-status="suspended"
Predicates
2
Defined values
12
UUID
a2a0788a-3cd1-5b64-b3a8-d50625b67b28

doping-substances

v2

Doping substances

This taxonomy aims to list doping substances

Tag examples & metadata
  • doping-substances:anabolic agents="1-androstenediol"
  • doping-substances:anabolic agents="1-androstenedione"
  • doping-substances:anabolic agents="1-androsterone"
Predicates
13
Defined values
303
UUID
08919298-eb16-529b-828b-964556ed8b7c

drug-form

v2

Primary physical forms of drugs: A categorisation model for narcotics and substances. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission, and subsequently re-extended by the Cátedra Ada Byron UAH-INCIBE.

Tag examples & metadata
  • drug-form:form="powder"
  • drug-form:form="pill-tablet"
  • drug-form:form="crystal-rock"
Predicates
1
Defined values
6
UUID
3c308b00-a189-4d58-a097-bbef465260d7

drugs

v2

A taxonomy based on the superclass and class of drugs. Based on https://www.drugbank.ca/releases/latest

Tag examples & metadata
  • drugs:alkaloids-and-derivatives="ajmaline-sarpagine-alkaloids"
  • drugs:alkaloids-and-derivatives=" allocolchicine-alkaloids"
  • drugs:alkaloids-and-derivatives=" Amaryllidaceae alkaloids"
Predicates
23
Defined values
292
UUID
e71cb3a8-b860-5deb-b2e2-b53c8d282af5

economical-impact

v5

Economical Impact

Economic impact refers to a taxonomy used to describe whether financial effects are positive or negative outcomes related to tagged information. For instance, data exfiltration loss represents a positive outcome for an adversary.

Tag examples & metadata
  • economical-impact:loss="none"
  • economical-impact:loss="less-than-25k-euro"
  • economical-impact:loss="less-than-50k-euro"
Predicates
2
Defined values
18
UUID
c0b06e92-5ecc-5918-af00-c9c0bc838e0d
References
  • https://www.misp-project.org/

ecsirt

v2

Incident Classification by the ecsirt.net version mkVI of 31 March 2015 enriched with IntelMQ taxonomy-type mapping.

Tag examples & metadata
  • ecsirt:abusive-content="spam"
  • ecsirt:abusive-content="harmful-speech"
  • ecsirt:abusive-content="violence"
Predicates
11
Defined values
43
UUID
17586a09-cb6f-595a-9982-57eadeb8e8bf

enisa

v20170725

ENISA Threat Taxonomy

The present threat taxonomy is an initial version that has been developed on the basis of available ENISA material. This material has been used as an ENISA-internal structuring aid for information collection and threat consolidation purposes. It emerged in the time period 2012-2015.

Tag examples & metadata
  • enisa:physical-attack="fraud"
  • enisa:physical-attack="fraud-by-employees"
  • enisa:physical-attack="sabotage"
Predicates
8
Defined values
169
UUID
9e93e79c-c0db-5520-a95c-39e0b98aa017

ensoc

v1

Official ENSOC (or EU CyberHUB) taxonomy covering all labels used during information exchange.

Tag examples & metadata
  • ensoc:workflow="to-validate"
  • ensoc:workflow="validated"
  • ensoc:source="feed"
Predicates
5
Defined values
15
UUID
5921e319-3f00-40c9-9428-322fe4afc88b

estimative-language

v5

Estimative languages

Estimative language to describe quality and credibility of underlying sources, data, and methodologies based Intelligence Community Directive 203 (ICD 203) and JP 2-0, Joint Intelligence

Tag examples & metadata
  • estimative-language:likelihood-probability="almost-no-chance"
  • estimative-language:likelihood-probability="very-unlikely"
  • estimative-language:likelihood-probability="unlikely"
Predicates
2
Defined values
10
UUID
33d478d1-ea19-55f2-9132-1e9b78b7d03b

eu-ai-act

v1

Taxonomy for the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). Classifies AI systems by risk level, prohibited practices, high-risk use cases, and incident types for GRC and SOC reporting.

Tag examples & metadata
  • eu-ai-act:risk-level="unacceptable"
  • eu-ai-act:risk-level="high-risk"
  • eu-ai-act:risk-level="systemic-risk-gpai"
Predicates
5
Defined values
21
UUID
7d3c9b8a-1f2e-4a3b-8c9d-0e1f2a3b4c5d

eu-marketop-and-publicadmin

v1

Market operators and public administrations that must comply to some notifications requirements under EU NIS directive

Tag examples & metadata
  • eu-marketop-and-publicadmin:critical-infra-operators="transport"
  • eu-marketop-and-publicadmin:critical-infra-operators="energy"
  • eu-marketop-and-publicadmin:critical-infra-operators="health"
Predicates
3
Defined values
12
UUID
8b2e0ecb-c289-56a1-9f99-7b624c0e019e

eu-nis-sector-and-subsectors

v1

Sectors, subsectors, and digital services as identified by the NIS Directive

Tag examples & metadata
  • eu-nis-sector-and-subsectors:eu-nis-oes="energy"
  • eu-nis-sector-and-subsectors:eu-nis-oes="transport"
  • eu-nis-sector-and-subsectors:eu-nis-oes="banking"
Predicates
9
Defined values
17
UUID
87b5cc02-0b0c-5a87-8e27-5c2d901839e4

euci

v3

EU classified information (EUCI) means any information or material designated by a EU security classification, the unauthorised disclosure of which could cause varying degrees of prejudice to the interests of the European Union or of one or more of the Member States.

Tag examples & metadata
  • euci:TS-UE/EU-TS
  • euci:S-UE/EU-S
  • euci:C-UE/EU-C
Predicates
4
Defined values
0
Exclusive taxonomy
Yes
UUID
b142e028-10de-5587-82be-f81b8aac6a68

europol-event

v1

Europol type of events taxonomy

This taxonomy was designed to describe the type of events

Tag examples & metadata
  • europol-event:infected-by-known-malware
  • europol-event:dissemination-malware-email
  • europol-event:hosting-malware-webpage
Predicates
46
Defined values
0
UUID
34da0c5e-2d9e-5439-8e4e-f25e087fd3a3

europol-incident

v1

Europol class of incidents taxonomy

This taxonomy was designed to describe the type of incidents by class.

Tag examples & metadata
  • europol-incident:malware="infection"
  • europol-incident:malware="distribution"
  • europol-incident:malware="c&c"
Predicates
9
Defined values
21
UUID
2ccdd18c-7370-5a42-aa96-3d3f5481ff2b

event-assessment

v2

Event Assessment

A series of assessment predicates describing the event assessment performed to make judgement(s) under a certain level of uncertainty.

Tag examples & metadata
  • event-assessment:alternative-points-of-view-process="analytic-debates-within-the-organisation"
  • event-assessment:alternative-points-of-view-process="devils-advocates-methodology"
  • event-assessment:alternative-points-of-view-process="competitive-analysis"
Predicates
1
Defined values
6
UUID
e9279d6f-b066-59ec-af58-569225b4d04d
References
  • http://www.foo.be/docs/intelligence/Tversky_Kahneman_1974.pdf
  • http://www.foo.be/docs/intelligence/PsychofIntelNew.pdf

event-classification

v1

Classification of events as seen in tools such as RT/IR, MISP and other

Tag examples & metadata
  • event-classification:event-class="incident_report"
  • event-classification:event-class="incident"
  • event-classification:event-class="investigation"
Predicates
1
Defined values
6
UUID
40517c50-9736-5833-9a44-2c966f534ea7

exercise

v16

Exercise

Exercise is a taxonomy to describe if the information is part of one or more cyber or crisis exercise.

Tag examples & metadata
  • exercise:cyber-europe="2026"
  • exercise:cyber-europe="2024"
  • exercise:cyber-europe="2022"
Predicates
8
Defined values
31
UUID
56e5fad4-f7ce-5083-b1de-344177bfc208

extended-event

v2

Reasons why an event has been extended. This taxonomy must be used on the extended event. The competitive analysis aspect is from Psychology of Intelligence Analysis by Richard J. Heuer, Jr. ref:http://www.foo.be/docs/intelligence/PsychofIntelNew.pdf

Tag examples & metadata
  • extended-event:competitive-analysis="devil-advocate"
  • extended-event:competitive-analysis="absurd-reasoning"
  • extended-event:competitive-analysis="role-playing"
Predicates
6
Defined values
9
UUID
67aa72aa-a33e-51db-9bc9-7345632a2b15

failure-mode-in-machine-learning

v1

Failure mode in machine learning.

The purpose of this taxonomy is to jointly tabulate both the of these failure modes in a single place. Intentional failures wherein the failure is caused by an active adversary attempting to subvert the system to attain her goals – either to misclassify the result, infer private training data, or to steal the underlying algorithm. Unintentional failures wherein the failure is because an ML system produces a formally correct but completely unsafe outcome.

Tag examples & metadata
  • failure-mode-in-machine-learning:intentionally-motivated-failures-summary="1-perturbation-attack"
  • failure-mode-in-machine-learning:intentionally-motivated-failures-summary="2-poisoning-attack"
  • failure-mode-in-machine-learning:intentionally-motivated-failures-summary="3-model-inversion"
Predicates
2
Defined values
17
UUID
942ead82-1498-531c-8176-794036d2dd55
References
  • https://docs.microsoft.com/en-us/security/failure-modes-in-machine-learning

false-positive

v7

False positive

This taxonomy aims to ballpark the expected amount of false positives.

Tag examples & metadata
  • false-positive:risk="low"
  • false-positive:risk="medium"
  • false-positive:risk="high"
Predicates
2
Defined values
6
UUID
764f0da7-fef4-5a27-bd32-d95ecaea97f0

file-type

v1

List of known file types.

Tag examples & metadata
  • file-type:type="peexe"
  • file-type:type="pedll"
  • file-type:type="neexe"
Predicates
1
Defined values
143
UUID
d83a6813-75d2-55da-bbf3-f496d5b79405

financial

v7

Financial

Financial taxonomy to describe financial services, infrastructure and financial scope.

Tag examples & metadata
  • financial:categories-and-types-of-services="banking"
  • financial:categories-and-types-of-services="private"
  • financial:categories-and-types-of-services="retail"
Predicates
5
Defined values
28
UUID
a5a27569-27a2-5c00-9729-7d7d8cefbaad

flesch-reading-ease

v2

Flesch Reading Ease is a revised system for determining the comprehension difficulty of written material. The scoring of the flesh score can have a maximum of 121.22 and there is no limit on how low a score can be (negative score are valid).

Tag examples & metadata
  • flesch-reading-ease:score="90-100"
  • flesch-reading-ease:score="80-89"
  • flesch-reading-ease:score="70-79"
Predicates
1
Defined values
7
Exclusive taxonomy
Yes
UUID
c048ee3f-9e60-547b-88c1-6ca49b9b36b3

fpf

v0

The Future of Privacy Forum (FPF) [visual guide to practical de-identification](https://fpf.org/2016/04/25/a-visual-guide-to-practical-data-de-identification/) taxonomy is used to evaluate the degree of identifiability of personal data and the types of pseudonymous data, de-identified data and anonymous data. The work of FPF is licensed under a creative commons attribution 4.0 international license.

Tag examples & metadata
  • fpf:degrees-of-identifiability="explicitly-personal"
  • fpf:degrees-of-identifiability="potentially-identifiable"
  • fpf:degrees-of-identifiability="not-readily-identifiable"
Predicates
4
Defined values
10
UUID
85ed8876-c018-5a69-bc03-1b1863a79a57

fr-classif

v6

French gov information classification system

Tag examples & metadata
  • fr-classif:classifiees="TRES_SECRET"
  • fr-classif:classifiees="SECRET"
  • fr-classif:non-classifiees="DIFFUSION_RESTREINTE"
Predicates
3
Defined values
5
UUID
e92de0de-bba7-55be-83e1-848dba05d769

gdpr

v0

Taxonomy related to the REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

Tag examples & metadata
  • gdpr:special-categories="racial-or-ethnic-origin"
  • gdpr:special-categories="political-opinions"
  • gdpr:special-categories="religious-or-philosophical-beliefs"
Predicates
1
Defined values
8
UUID
f36e2b34-a097-5ce1-b92d-cc289103f623

gea-nz-activities

v1

Information needed to track or monitor moments, periods or events that occur over time. This type of information is focused on occurrences that must be tracked for business reasons or represent a specific point in the evolution of ‘The Business’.

Tag examples & metadata
  • gea-nz-activities:cases-compliance="assessment"
  • gea-nz-activities:cases-compliance="audit"
  • gea-nz-activities:cases-compliance="inspection"
Predicates
22
Defined values
149
UUID
5a3819bc-fbdd-5747-bfdd-ce1358641b74
References
  • https://www.dragon1.com/downloads/government-enterprise-architecture-for-new-zealand-v3.1.pdf

gea-nz-entities

v1

Information relating to instances of entities or things.

Tag examples & metadata
  • gea-nz-entities:parties-party="organisation"
  • gea-nz-entities:parties-party="individual"
  • gea-nz-entities:parties-qualification="competence"
Predicates
21
Defined values
116
UUID
bd01f69e-8692-52ea-a64b-0d66feb3d024
References
  • https://www.dragon1.com/downloads/government-enterprise-architecture-for-new-zealand-v3.1.pdf

gea-nz-motivators

v1

Information relating to authority or governance.

Tag examples & metadata
  • gea-nz-motivators:plans-budget="capital"
  • gea-nz-motivators:plans-budget="operating"
  • gea-nz-motivators:plans-strategy="strategic-directive"
Predicates
18
Defined values
96
UUID
14d2b224-8189-5a31-84a5-5c6a548d968a
References
  • https://www.dragon1.com/downloads/government-enterprise-architecture-for-new-zealand-v3.1.pdf

gen-ai-risks

v1

A taxonomy based on NIST AI 600-1 (July 2024), Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. Covers the risks unique to or exacerbated by Generative AI, their mapped Trustworthy AI Characteristics, and the primary GAI considerations derived from the NIST Generative AI Public Working Group.

Tag examples & metadata
  • gen-ai-risks:gai-risk="cbrn-information-or-capabilities"
  • gen-ai-risks:gai-risk="confabulation"
  • gen-ai-risks:gai-risk="dangerous-violent-or-hateful-content"
Predicates
3
Defined values
23
UUID
d6d08803-1b23-4765-9f87-2c9585db56a2

GrayZone

v3

Gray Zone of Active defense includes all elements which lay between reactive defense elements and offensive operations. It does fill the gray spot between them. Taxo may be used for active defense planning or modeling.

Tag examples & metadata
  • GrayZone:Adversary Emulation="Threat Modeling"
  • GrayZone:Adversary Emulation="Purple Teaming"
  • GrayZone:Adversary Emulation="Blue Team"
Predicates
10
Defined values
30
UUID
7bed6f9e-63f6-502d-8b65-ab4444a73a92

gsma-attack-category

v1

Taxonomy used by GSMA for their information sharing program with telco describing the attack categories

Tag examples & metadata
  • gsma-attack-category:denial-of-service
  • gsma-attack-category:exploit-attack
  • gsma-attack-category:information-gathering
Predicates
8
Defined values
0
UUID
da814de2-95db-5a31-a01b-d1861ff653e7

gsma-fraud

v1

Taxonomy used by GSMA for their information sharing program with telco describing the various aspects of fraud

Tag examples & metadata
  • gsma-fraud:technical="mailbox-hacking"
  • gsma-fraud:technical="imei-reprogramming"
  • gsma-fraud:technical="call-forwarding-fraud"
Predicates
5
Defined values
49
UUID
47f4fa60-177d-517d-8e21-a075fc6f86cf

gsma-network-technology

v3

Taxonomy used by GSMA for their information sharing program with telco describing the types of infrastructure. WiP

Tag examples & metadata
  • gsma-network-technology:user
  • gsma-network-technology:applications
  • gsma-network-technology:end-devices-and-components="ms"
Predicates
9
Defined values
2
UUID
6f4f3b7b-3eed-515f-8934-4b6082746cde

honeypot-basic

v4

Updated (CIRCL, Seamus Dowling and EURECOM) from Christian Seifert, Ian Welch, Peter Komisarczuk, ‘Taxonomy of Honeypots’, Technical Report CS-TR-06/12, VICTORIA UNIVERSITY OF WELLINGTON, School of Mathematical and Computing Sciences, June 2006, http://www.mcs.vuw.ac.nz/comp/Publications/archive/CS-TR-06/CS-TR-06-12.pdf

Tag examples & metadata
  • honeypot-basic:interaction-level="high"
  • honeypot-basic:interaction-level="medium"
  • honeypot-basic:interaction-level="low"
Predicates
6
Defined values
21
UUID
ae03db9f-1c0e-50c2-826a-bc69a4f08783

hunt-ex

v4

Hunt Exchange Taxonomy

High-level, human-readable classification of a hunt's approach, provenance and outcome, designed for cross-organisation search and dashboards at ISAC / sector level. Detailed structured data lives in the threat-hunt-context, threat-hunt-hypothesis, threat-hunt-query and threat-hunt-finding objects; lifecycle uses workflow:state. Vocabulary is compatible with the PEAK framework (Splunk / Cisco Talos) and TaHiTI (NVB / FI-ISAC). Pair with existing taxonomies rather than duplicating them: use tlp and PAP for sharing, admiralty-scale and estimative-language for confidence and source reliability, cti-evaluation for CTI quality, priority-level for triage, DML for detection abstraction level, kill-chain / unified-kill-chain for phase, and the mitre-attack-pattern galaxy for technique mapping.

Tag examples & metadata
  • hunt-ex:methodology="structured-hypothesis-driven"
  • hunt-ex:methodology="unstructured-baseline"
  • hunt-ex:methodology="model-assisted"
Predicates
9
Defined values
62
UUID
989ddd32-bd8e-47ca-9ebf-d5abc000cdd6

iab-ad-product-2-0

v1

IAB Tech Lab Ad Product Taxonomy 2.0

IAB Tech Lab Ad Product Taxonomy 2.0 converted from the official TSV. It establishes standardized nomenclature for describing the product or service advertised within a creative unit. Source taxonomy © IAB Tech Lab, licensed under Creative Commons Attribution 3.0.

Tag examples & metadata
  • iab-ad-product-2-0:automotive="auto-parts"
  • iab-ad-product-2-0:automotive="vehicle-dealers"
  • iab-ad-product-2-0:business="business-services"
Predicates
3
Defined values
4
UUID
020bcbc9-d44e-44ac-80b6-61144f3e021a
References
  • https://github.com/InteractiveAdvertisingBureau/Taxonomies
  • https://creativecommons.org/licenses/by/3.0/

iab-audience-1-1

v1

IAB Tech Lab Audience Taxonomy 1.1

IAB Tech Lab Audience Taxonomy 1.1 converted from the official TSV. It provides common nomenclature for audience segment names to improve comparability across data providers. Source taxonomy © IAB Tech Lab, licensed under Creative Commons Attribution 3.0.

Tag examples & metadata
  • iab-audience-1-1:demographic="age-range"
  • iab-audience-1-1:demographic="age-range-18-20"
  • iab-audience-1-1:demographic="education-and-occupation"
Predicates
3
Defined values
7
UUID
c92d3887-907d-4064-9067-40cf8104d8c9
References
  • https://github.com/InteractiveAdvertisingBureau/Taxonomies
  • https://creativecommons.org/licenses/by/3.0/

iab-content-3-0-descriptive-vectors

v1

IAB Tech Lab Content Taxonomy 3.0 Descriptive Vectors

IAB Tech Lab Content Taxonomy 3.0 Descriptive Vectors converted from the official TSV. Source taxonomy © IAB Tech Lab, licensed under Creative Commons Attribution 3.0.

Tag examples & metadata
  • iab-content-3-0-descriptive-vectors:audio="podcast"
  • iab-content-3-0-descriptive-vectors:audio="music"
  • iab-content-3-0-descriptive-vectors:video="in-video"
Predicates
2
Defined values
4
UUID
5b76b469-9ef9-473f-8250-f18746faaf62
References
  • https://github.com/InteractiveAdvertisingBureau/Taxonomies
  • https://creativecommons.org/licenses/by/3.0/

iab-content-3-1

v1

IAB Tech Lab Content Taxonomy 3.1

IAB Tech Lab Content Taxonomy 3.1 converted from the official TSV. It provides a common language for describing content or the aboutness of a webpage, application, or video. Source taxonomy © IAB Tech Lab, licensed under Creative Commons Attribution 3.0.

Tag examples & metadata
  • iab-content-3-1:attractions="amusement-and-theme-parks"
  • iab-content-3-1:attractions="bars-and-restaurants"
  • iab-content-3-1:automotive="auto-body-styles"
Predicates
4
Defined values
7
UUID
c1a96153-59fc-4a15-8b30-fe9bbcfcda50
References
  • https://github.com/InteractiveAdvertisingBureau/Taxonomies
  • https://creativecommons.org/licenses/by/3.0/

ics

v1

Industrial Control System (ICS)

FIRST.ORG CTI SIG - MISP Proposal for ICS/OT Threat Attribution (IOC) Project

Tag examples & metadata
  • ics:ot-security-issues="Message Authentication"
  • ics:ot-security-issues="Message Integrity Checking"
  • ics:ot-security-issues="Message Encryption"
Predicates
10
Defined values
109
UUID
cb92cfe7-ec69-54f7-abe7-339dc0883cd0
References
  • https://www.first.org/global/sigs/cti/
  • https://www.isa.org/isa99/
  • https://www.isa.org/intech/201810standards/

iep

v2

Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) framework

Tag examples & metadata
  • iep:commercial-use="MAY"
  • iep:commercial-use="MUST NOT"
  • iep:external-reference="$text"
Predicates
16
Defined values
32
UUID
8f37c037-abfe-52da-9880-f15fd45ea068

iep2-policy

v1

Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) v2.0 Policy

Tag examples & metadata
  • iep2-policy:id="$text"
  • iep2-policy:name="$text"
  • iep2-policy:description="$text"
Predicates
13
Defined values
25
UUID
6b4b43e7-2ce5-522d-b208-8d6a3847e0b4

iep2-reference

v1

Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) v2.0 Reference

Tag examples & metadata
  • iep2-reference:id_ref="$text"
  • iep2-reference:url="$text"
  • iep2-reference:iep_version="2.0"
Predicates
3
Defined values
3
UUID
de1aa9f3-96c4-557e-8487-3f08a63f7f05

ifx-vetting

v3

The IFX taxonomy is used to categorise information (MISP events and attributes) to aid in the intelligence vetting process

Tag examples & metadata
  • ifx-vetting:vetted="legit-but-compromised"
  • ifx-vetting:vetted="legit"
  • ifx-vetting:vetted="legit-uncertain"
Predicates
2
Defined values
110
UUID
213c89ca-d340-5cb0-b59d-abe63315c7a9

incident-disposition

v2

How an incident is classified in its process to be resolved. The taxonomy is inspired from NASA Incident Response and Management Handbook. https://www.nasa.gov/pdf/589502main_ITS-HBK-2810.09-02%20%5bNASA%20Information%20Security%20Incident%20Management%5d.pdf#page=9

Tag examples & metadata
  • incident-disposition:incident="confirmed"
  • incident-disposition:incident="deferred"
  • incident-disposition:incident="unidentified"
Predicates
3
Defined values
13
UUID
f4157b45-1c27-57f8-b747-9a38a259e0c5

infoleak

v10

A taxonomy describing information leaks and especially information classified as being potentially leaked. The taxonomy is based on the work by CIRCL on the AIL framework. The taxonomy aim is to be used at large to improve classification of leaked information.

Tag examples & metadata
  • infoleak:automatic-detection="credential"
  • infoleak:automatic-detection="credit-card"
  • infoleak:automatic-detection="iban"
Predicates
7
Defined values
92
UUID
f29e5089-bc07-586b-8462-5a346a5e6886

information-origin

v2

Taxonomy for tagging information by its origin: human-generated or AI-generated.

Tag examples & metadata
  • information-origin:human-generated
  • information-origin:AI-generated
  • information-origin:uncertain-origin
Predicates
3
Defined values
0
UUID
a33df8f3-b857-5bfb-a852-356b6ebf9960

information-security-data-source

v1

Taxonomy to classify the information security data sources.

Tag examples & metadata
  • information-security-data-source:type-of-information="vulnerability"
  • information-security-data-source:type-of-information="threat"
  • information-security-data-source:type-of-information="countermeasure"
Predicates
9
Defined values
33
UUID
3afa0c8a-0a0b-5139-9ae4-447487451251
References
  • https://www.sciencedirect.com/science/article/pii/S0167404818304978

information-security-indicators

v1

A full set of operational indicators for organizations to use to benchmark their security posture.

Tag examples & metadata
  • information-security-indicators:IEX="FGY.1"
  • information-security-indicators:IEX="FGY.2"
  • information-security-indicators:IEX="SPM.1"
Predicates
10
Defined values
97
UUID
2ef53734-d7ab-58b5-8a02-f4e00f127eb8

interactive-cyber-training-audience

v1

Interactive Cyber Training - Audience

Describes the target of cyber training and education.

Tag examples & metadata
  • interactive-cyber-training-audience:sector="academic-school"
  • interactive-cyber-training-audience:sector="academic-university"
  • interactive-cyber-training-audience:sector="public-government"
Predicates
4
Defined values
20
UUID
3d85c531-47b3-5566-bd2a-6798987ed385
References
  • https://arxiv.org/abs/2101.05538

interactive-cyber-training-technical-setup

v1

Interactive Cyber Training - Technical Setup

The technical setup consists of environment structure, deployment, and orchestration.

Tag examples & metadata
  • interactive-cyber-training-technical-setup:environment-structure="tabletop-style"
  • interactive-cyber-training-technical-setup:environment-structure="online-collaboration-platform"
  • interactive-cyber-training-technical-setup:environment-structure="online-e-learning-platform"
Predicates
3
Defined values
18
UUID
c7d74326-5f24-5bda-a45c-fb7bf63d8cdc
References
  • https://arxiv.org/abs/2101.05538

interactive-cyber-training-training-environment

v1

Interactive Cyber Training - Training Environment

The training environment details the environment around the training, consisting of training type and scenario.

Tag examples & metadata
  • interactive-cyber-training-training-environment:training-type="tabletop-game-speech"
  • interactive-cyber-training-training-environment:training-type="tabletop-game-text"
  • interactive-cyber-training-training-environment:training-type="tabletop-game-multimedia"
Predicates
2
Defined values
32
UUID
03c61b33-83d8-597b-8ad7-7ea69f19c731
References
  • https://arxiv.org/abs/2101.05538

interactive-cyber-training-training-setup

v1

Interactive Cyber Training - Training Setup

The training setup further describes the training itself with the scoring, roles, the training mode as well as the customization level.

Tag examples & metadata
  • interactive-cyber-training-training-setup:scoring="no-scoring"
  • interactive-cyber-training-training-setup:scoring="assessment-static"
  • interactive-cyber-training-training-setup:scoring="assessment-dynamic"
Predicates
4
Defined values
21
UUID
9c5c897b-bb1b-57df-9067-54f36cfdae28
References
  • https://arxiv.org/abs/2101.05538

interception-method

v1

Interception method

The interception method used to intercept traffic.

Tag examples & metadata
  • interception-method:man-in-the-middle
  • interception-method:man-on-the-side
  • interception-method:passive
Predicates
7
Defined values
0
UUID
81a4a435-76d8-5509-be7a-076db4eae8d3

ioc

v2

An IOC classification to facilitate automation of malicious and non malicious artifacts

Tag examples & metadata
  • ioc:artifact-state="malicious"
  • ioc:artifact-state="not-malicious"
Predicates
1
Defined values
2
UUID
b7b1ce2a-e303-5a67-9e98-c483bc6c688e

iot

v2

Internet of Things

Internet of Things taxonomy, based on IOT UK report https://iotuk.org.uk/wp-content/uploads/2017/01/IOT-Taxonomy-Report.pdf

Tag examples & metadata
  • iot:TCom="0"
  • iot:TCom="1"
  • iot:TCom="2"
Predicates
3
Defined values
18
UUID
1d805a62-39eb-54a5-8ce0-8dcfc2305548

kill-chain

v2

Cyber Kill Chain

The Cyber Kill Chain, a phase-based model developed by Lockheed Martin, aims to help categorise and identify the stage of an attack.

Tag examples & metadata
  • kill-chain:Reconnaissance
  • kill-chain:Weaponization
  • kill-chain:Delivery
Predicates
7
Defined values
0
UUID
b6431778-ce11-5fef-ad2b-13035dac2dba

maec-delivery-vectors

v1

Vectors used to deliver malware based on MAEC 5.0

Tag examples & metadata
  • maec-delivery-vectors:maec-delivery-vector="active-attacker"
  • maec-delivery-vectors:maec-delivery-vector="auto-executing-media"
  • maec-delivery-vectors:maec-delivery-vector="downloader"
Predicates
1
Defined values
17
UUID
1bfc067e-7a55-54c5-98ea-c1d9c8e02ac4

maec-malware-behavior

v1

Malware behaviours based on MAEC 5.0

Tag examples & metadata
  • maec-malware-behavior:maec-malware-behavior="access-premium-service"
  • maec-malware-behavior:maec-malware-behavior="autonomous-remote-infection"
  • maec-malware-behavior:maec-malware-behavior="block-security-websites"
Predicates
1
Defined values
148
UUID
75135f33-bfcb-5606-b7b3-6aea0679d597

maec-malware-capabilities

v2

Malware Capabilities based on MAEC 5.0

Tag examples & metadata
  • maec-malware-capabilities:maec-malware-capability="anti-behavioral-analysis"
  • maec-malware-capabilities:maec-malware-capability="anti-code-analysis"
  • maec-malware-capabilities:maec-malware-capability="anti-detection"
Predicates
1
Defined values
69
UUID
3cbd62f9-3361-58bd-9bca-140de7ecc1be

maec-malware-obfuscation-methods

v1

Obfuscation methods used by malware based on MAEC 5.0

Tag examples & metadata
  • maec-malware-obfuscation-methods:maec-obfuscation-methods="packing"
  • maec-malware-obfuscation-methods:maec-obfuscation-methods="code-encryption"
  • maec-malware-obfuscation-methods:maec-obfuscation-methods="dead-code-insertion"
Predicates
1
Defined values
12
UUID
2a0c959f-2a45-5475-9c2c-d0de3be62df4

malware_classification

v3

Classification based on different categories. Based on https://www.sans.org/reading-room/whitepapers/incident/malware-101-viruses-32848

Tag examples & metadata
  • malware_classification:malware-category="Virus"
  • malware_classification:malware-category="Worm"
  • malware_classification:malware-category="Trojan"
Predicates
4
Defined values
31
UUID
443f0cbf-b1cb-5320-a58c-a7140185b022

meteorstorm

v2

METEORSTORM

Multiple Environment Threat Evaluation of Resources Space Threats and Operational Risk to Missions (meteorstorm) taxonomy for modeling space, cyber, and multi-domain threats and resilience across five layers: Primary Capability Environment (PCE), Segment (SEG), Service (SVC), Asset (AST), and Analytic (AN).

Tag examples & metadata
  • meteorstorm:PCE="PCE-TE"
  • meteorstorm:PCE="PCE-AQ"
  • meteorstorm:PCE="PCE-AE"
Predicates
5
Defined values
30
UUID
ce710476-c476-518d-a35c-69eef1f3fc1d

misinformation-website-label

v1

classification for the identification of type of misinformation among websites. Source:False, Misleading, Clickbait-y, and/or Satirical News Sources by Melissa Zimdars 2019

Tag examples & metadata
  • misinformation-website-label:fake-news
  • misinformation-website-label:satire="humor"
  • misinformation-website-label:satire="irony"
Predicates
13
Defined values
15
UUID
eeec3f2b-51bf-5058-a913-acb9d5d99666

misp

v14

MISP

MISP taxonomy to infer with MISP behavior or operation.

Tag examples & metadata
  • misp:ui="hide"
  • misp:api="hide"
  • misp:expansion="block"
Predicates
12
Defined values
32
UUID
5101b1e6-f050-5052-b7ed-9e862a7e7fb8

misp-workflow

v3

MISP workflow

MISP workflow taxonomy to support result of workflow execution.

Tag examples & metadata
  • misp-workflow:action-taken="ids-flag-removed"
  • misp-workflow:action-taken="ids-flag-added"
  • misp-workflow:action-taken="pushed-to-zmq"
Predicates
4
Defined values
11
UUID
3ba568ad-ac97-5e13-9952-93c95e7ab2fc

monarc-threat

v1

MONARC Threats

MONARC Threats Taxonomy

Tag examples & metadata
  • monarc-threat:compromise-of-functions="error-in-use"
  • monarc-threat:compromise-of-functions="forging-of-rights"
  • monarc-threat:compromise-of-functions="eavesdropping"
Predicates
6
Defined values
30
UUID
d816996b-3a69-5178-a094-64c9bb79eedc
References
  • https://monarc.lu

ms-caro-malware

v1

Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families.

Tag examples & metadata
  • ms-caro-malware:malware-type="Adware"
  • ms-caro-malware:malware-type="Backdoor"
  • ms-caro-malware:malware-type="Behavior"
Predicates
2
Defined values
108
UUID
80915321-ca12-52f2-8226-c1f0199a9ba4

ms-caro-malware-full

v2

Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families.

Tag examples & metadata
  • ms-caro-malware-full:malware-type="Adware"
  • ms-caro-malware-full:malware-type="Backdoor"
  • ms-caro-malware-full:malware-type="Behavior"
Predicates
3
Defined values
565
UUID
df7fd106-c640-5981-a7c2-a8b62946a164

mwdb

v2

Malware Database (mwdb) Taxonomy - Tags used across the platform

Tag examples & metadata
  • mwdb:location_type="cnc"
  • mwdb:location_type="download_url"
  • mwdb:location_type="panel"
Predicates
2
Defined values
106
UUID
87794ce2-de9d-58dd-8445-aedcb566fb21

nato

v2

NATO classification markings.

Tag examples & metadata
  • nato:classification="CTS"
  • nato:classification="CTS-B"
  • nato:classification="NS"
Predicates
1
Defined values
9
Exclusive taxonomy
Yes
UUID
d92870ce-b304-521b-9d84-efaaac9ef415

nato-uas-classification

v1

NATO UAS Classification.

Tag examples & metadata
  • nato-uas-classification:CLASS-I="small"
  • nato-uas-classification:CLASS-I="mini"
  • nato-uas-classification:CLASS-I="micro"
Predicates
3
Defined values
7
UUID
8ecc9d38-c957-40a5-93b4-56b5d3faaa15

nis

v2

The taxonomy is meant for large scale cybersecurity incidents, as mentioned in the Commission Recommendation of 13 September 2017, also known as the blueprint. It has two core parts: The nature of the incident, i.e. the underlying cause, that triggered the incident, and the impact of the incident, i.e. the impact on services, in which sector(s) of economy and society.

Tag examples & metadata
  • nis:impact-sectors-impacted="energy"
  • nis:impact-sectors-impacted="transport"
  • nis:impact-sectors-impacted="banking"
Predicates
6
Defined values
27
UUID
ed27ea00-d130-5e82-a6e2-15e6d819f117

nis2

v5

The taxonomy is meant for large scale cybersecurity incidents, as mentioned in the Commission Recommendation of 13 May 2022, also known as the provisional agreement. It has two core parts: The nature of the incident, i.e. the underlying cause, that triggered the incident, and the impact of the incident, i.e. the impact on services, in which sector(s) of economy and society.

Tag examples & metadata
  • nis2:impact-sectors-impacted="energy"
  • nis2:impact-sectors-impacted="transport"
  • nis2:impact-sectors-impacted="banking"
Predicates
9
Defined values
75
UUID
0399728c-b066-5727-9a59-5f1e1b1d9164

niso-credit

v1

NISO CRediT Contributor Roles Taxonomy

NISO CRediT (Contributor Roles Taxonomy) roles for describing contributor roles and optional contribution degrees in scholarly outputs.

Tag examples & metadata
  • niso-credit:contributor-role="conceptualization"
  • niso-credit:contributor-role="data-curation"
  • niso-credit:contributor-role="formal-analysis"
Predicates
2
Defined values
17
UUID
7552ebaf-19e9-543b-a25a-ac7fc22646c4
References
  • https://groups.niso.org/higherlogic/ws/public/download/26466/ANSI-NISO-Z39.104-2022.pdf
  • https://credit.niso.org/
  • https://github.com/MISP/misp-taxonomies/issues/252

open_threat

v1

Open Threat Taxonomy v1.1 base on James Tarala of SANS http://www.auditscripts.com/resources/open_threat_taxonomy_v1.1a.pdf, https://files.sans.org/summit/Threat_Hunting_Incident_Response_Summit_2016/PDFs/Using-Open-Tools-to-Convert-Threat-Intelligence-into-Practical-Defenses-James-Tarala-SANS-Institute.pdf, https://www.youtube.com/watch?v=5rdGOOFC_yE, and https://www.rsaconference.com/writable/presentations/file_upload/str-r04_using-an-open-source-threat-model-for-prioritized-defense-final.pdf

Tag examples & metadata
  • open_threat:threat-category="Physical"
  • open_threat:threat-category="Resource"
  • open_threat:threat-category="Personal"
Predicates
2
Defined values
79
UUID
8940527b-afd2-5330-b0a4-992bdba7ec9c

organizational-cyber-harm

v1

organizational cyber- arm

A taxonomy to classify organizational cyber harms based on categories like physical, economic, psychological, reputational, and social/societal impacts.

Tag examples & metadata
  • organizational-cyber-harm:physical-digital="damaged-or-unavailable"
  • organizational-cyber-harm:physical-digital="destroyed"
  • organizational-cyber-harm:physical-digital="theft"
Predicates
5
Defined values
57
UUID
42602a10-a966-53a3-af5f-377e51cbdab4
References
  • https://academic.oup.com/cybersecurity/article/4/1/tyy006/5133288?login=false

osint

v11

Open Source Intelligence - Classification (MISP taxonomies)

Tag examples & metadata
  • osint:source-type="blog-post"
  • osint:source-type="microblog-post"
  • osint:source-type="technical-report"
Predicates
3
Defined values
27
UUID
a86e35e6-b0cb-5b30-99df-013b40040cbc

pandemic

v4

Pandemic

Tag examples & metadata
  • pandemic:covid-19="health"
  • pandemic:covid-19="cyber"
  • pandemic:covid-19="disinformation"
Predicates
1
Defined values
4
UUID
ffb57e54-a340-50c6-a8f1-dee3b713924a

PAP

v3

Permissible Actions Protocol

The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used.

Tag examples & metadata
  • PAP:RED
  • PAP:AMBER
  • PAP:GREEN
Predicates
5
Defined values
0
Exclusive taxonomy
Yes
UUID
8d7472b0-8a76-5be9-bfe0-185cc9ca9c30

passivetotal

v2

PassiveTotal

Tags from RiskIQ's PassiveTotal service

Tag examples & metadata
  • passivetotal:sinkholed="yes"
  • passivetotal:sinkholed="no"
  • passivetotal:ever-compromised="yes"
Predicates
4
Defined values
10
UUID
57dae4d0-8e88-5a55-9bee-674348826af9

pentest

v3

Penetration test (pentest) classification.

Tag examples & metadata
  • pentest:approach="blackbox"
  • pentest:approach="greybox"
  • pentest:approach="whitebox"
Predicates
8
Defined values
41
UUID
c6febb56-c468-53de-bf14-b01f7df1e63a

pfc

v1

Protocole des Feux de Circulation

Le Protocole des feux de circulation (PFC) est basé sur le standard « Traffic Light Protocol (TLP) » conçu par le FIRST. Il a pour objectif d’informer sur les limites autorisées pour la diffusion des informations. Il est classé selon des codes de couleurs.

Tag examples & metadata
  • pfc:rouge
  • pfc:ambre
  • pfc:ambre+strict
Predicates
5
Defined values
0
Exclusive taxonomy
Yes
UUID
2e48f5a7-e33b-5026-9d7c-204dcb35d20f
References
  • https://www.cyber.gouv.qc.ca/pfc

phishing

v5

Taxonomy to classify phishing attacks including techniques, collection mechanisms and analysis status.

Tag examples & metadata
  • phishing:techniques="fake-website"
  • phishing:techniques="email-spoofing"
  • phishing:techniques="clone-phishing"
Predicates
8
Defined values
31
UUID
3dee20a7-fadb-52c7-80cf-c67280257ec2

poison-taxonomy

v1

Non-exhaustive taxonomy of natural poison

Tag examples & metadata
  • poison-taxonomy:Poisonous plant
  • poison-taxonomy:Poisonous fungus="Agaricus californicus/California "
  • poison-taxonomy:Poisonous fungus="Agaricus hondensis/Felt-ringed "
Predicates
2
Defined values
152
UUID
35705cb8-bd3d-580c-b717-45a5264b095f

political-spectrum

v1

Political Spectrum

A political spectrum is a system to characterize and classify different political positions in relation to one another.

Tag examples & metadata
  • political-spectrum:ideology="agrarianism"
  • political-spectrum:ideology="anarchism"
  • political-spectrum:ideology="centrism"
Predicates
2
Defined values
22
UUID
e6977409-e8d4-5867-b6a6-9b6823fd4974

priority-level

v2

After an incident is scored, it is assigned a priority level. The six levels listed below are aligned with NCCIC, DHS, and the CISS to help provide a common lexicon when discussing incidents. This priority assignment drives NCCIC urgency, pre-approved incident response offerings, reporting requirements, and recommendations for leadership escalation. Generally, incident priority distribution should follow a similar pattern to the graph below. Based on https://www.cisa.gov/news-events/news/cisa-national-cyber-incident-scoring-system-nciss.

Tag examples & metadata
  • priority-level:emergency
  • priority-level:severe
  • priority-level:high
Predicates
7
Defined values
0
Exclusive taxonomy
Yes
UUID
4cf39590-12be-547c-bc1b-36cf0ee9603e

ptrclassify

v1

Explainable classifications inferred from reverse-DNS PTR hostnames.

Tag examples & metadata
  • ptrclassify:allocation="dynamic"
  • ptrclassify:allocation="static"
  • ptrclassify:allocation="reserved"
Predicates
10
Defined values
44
UUID
fd2dec0f-be35-424e-a194-c6f8492b04a9

pyoti

v3

PyOTI Enrichment

PyOTI automated enrichment schemes for point in time classification of indicators.

Tag examples & metadata
  • pyoti:checkdmarc="spoofable"
  • pyoti:disposable-email
  • pyoti:emailrepio="spoofable"
Predicates
10
Defined values
59
UUID
a1a51ceb-177d-5920-bd8a-7c656ecb82af
References
  • https://github.com/RH-ISAC/PyOTI
  • https://github.com/RH-ISAC/PyOTI/blob/main/examples/enrich_misp_event.py

ransomware

v6

ransomware types and elements

Ransomware is used to define ransomware types and the elements that compose them.

Tag examples & metadata
  • ransomware:type="scareware"
  • ransomware:type="locker-ransomware"
  • ransomware:type="crypto-ransomware"
Predicates
8
Defined values
55
UUID
7a364755-6a93-501f-8e70-5c6a2f18e9e4
References
  • https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the-evolution-of-ransomware.pdf
  • https://docs.apwg.org/ecrimeresearch/2018/5357083.pdf
  • https://bartblaze.blogspot.com/p/the-purpose-of-ransomware.html
  • https://arxiv.org/pdf/2102.06249.pdf

ransomware-roles

v1

Ransomware Actor Roles

The seven roles seen in most ransomware incidents.

Tag examples & metadata
  • ransomware-roles:1 - Initial Access Broker
  • ransomware-roles:2 - Ransomware Affiliate
  • ransomware-roles:3 - Data Manager
Predicates
7
Defined values
0
UUID
732925d0-77b7-5e2d-8725-fe9f74e98e92
References
  • https://www.northwave-security.com/

retention

v4

Add a retention time to events to automatically remove the IDS-flag on ip-dst or ip-src attributes. We calculate the time elapsed based on the date of the event. Supported time units are: d(ays), w(eeks), m(onths), y(ears). The numerical_value is just for sorting in the web-interface and is not used for calculations.

Tag examples & metadata
  • retention:expired
  • retention:1d
  • retention:2d
Predicates
14
Defined values
0
Exclusive taxonomy
Yes
UUID
900c3de3-ceca-5565-8471-bb395f2800f7
References
  • https://en.wikipedia.org/wiki/Retention_period

rsit

v1003

Reference Security Incident Classification Taxonomy

Tag examples & metadata
  • rsit:abusive-content="spam"
  • rsit:abusive-content="harmful-speech"
  • rsit:abusive-content="violence"
Predicates
11
Defined values
39
UUID
ce5853b9-fd53-5476-afaf-39f48d326897

rstcloud

v1

RST Cloud

RST Cloud threat intelligence scoring and verdicts for indicators enriched from RST Cloud. score-total (0-100) is the base score of the RST Cloud decaying models, computed as 100 * (source-confidence * context-confidence * relevance) where each sub-score is in [0,1]; because it is a product the total is heavily compressed (all-very-high inputs 0.9*0.9*0.9 = 72.9), so 90+ is rarely reached. Clients typically use 45+ for real-time detection and 50+ for blocking. context-confidence and relevance are coarse bands derived from the corresponding RST sub-scores and are human triage signals; context-confidence also reflects how dangerous the associated threat type is, and relevance also factors in novelty/freshness. noise-control / noise-category carry RST Noise Control and false-positive verdicts surfaced by the enrichment modules. By RST Cloud.

Tag examples & metadata
  • rstcloud:score-total="0"
  • rstcloud:score-total="1"
  • rstcloud:score-total="2"
Predicates
5
Defined values
113
UUID
b6cafb3c-0c4d-5a66-b3be-52e0a3eca696

rt_event_status

v2

Status of events used in Request Tracker.

Tag examples & metadata
  • rt_event_status:event-status="new"
  • rt_event_status:event-status="open"
  • rt_event_status:event-status="stalled"
Predicates
1
Defined values
6
Exclusive taxonomy
Yes
UUID
2e619f0f-6b5c-57d8-a848-97ad437249dc

runtime-packer

v3

Runtime or software packer used to combine compressed or encrypted data with the decompression or decryption code. This code can add additional obfuscations mechanisms including polymorphic-packer, virtualization or other obfuscation techniques. This taxonomy lists all the known or official packer used for legitimate use or for packing malicious binaries.

Tag examples & metadata
  • runtime-packer:dex="apk-protect"
  • runtime-packer:dex="appcode-packer"
  • runtime-packer:dex="appsealing"
Predicates
5
Defined values
108
UUID
ae8064ed-ba82-5ec3-a1a1-09353f8eae7e

scrippsco2-fgc

v1

Flags describing the sample

Tag examples & metadata
  • scrippsco2-fgc:-3
  • scrippsco2-fgc:-2
  • scrippsco2-fgc:-1
Predicates
12
Defined values
0
UUID
7edd4cc4-b168-55a3-b0e2-ab1bcab618b5

scrippsco2-fgi

v1

Flags describing the sample for isotopic data (C14, O18)

Tag examples & metadata
  • scrippsco2-fgi:-3
  • scrippsco2-fgi:0
  • scrippsco2-fgi:3
Predicates
7
Defined values
0
UUID
964eddd6-1099-5b13-8e4e-be34a8f13dc6

scrippsco2-sampling-stations

v1

Sampling stations of the Scripps CO2 Program

Tag examples & metadata
  • scrippsco2-sampling-stations:ALT
  • scrippsco2-sampling-stations:PTB
  • scrippsco2-sampling-stations:STP
Predicates
13
Defined values
0
UUID
ab32aa14-4f37-5884-9c47-ee0c196a2ef8

sentinel-threattype

v1

Sentinel indicator threat types.

Tag examples & metadata
  • sentinel-threattype:Botnet
  • sentinel-threattype:C2
  • sentinel-threattype:CryptoMining
Predicates
11
Defined values
0
Exclusive taxonomy
Yes
UUID
7bd7105b-847b-5494-9df5-c107d17acaa2
References
  • https://learn.microsoft.com/en-us/graph/api/resources/tiindicator?view=graph-rest-beta#threattype-values

smart-airports-threats

v1

Threat taxonomy in the scope of securing smart airports by ENISA. https://www.enisa.europa.eu/publications/securing-smart-airports

Tag examples & metadata
  • smart-airports-threats:human-errors="configuration-errors"
  • smart-airports-threats:human-errors="operator-or-user-error"
  • smart-airports-threats:human-errors="loss-of-hardware"
Predicates
5
Defined values
68
UUID
f87eddfd-2bf6-56b6-9ca0-6ed79ce05917

social-engineering-attack-vectors

v1

Social Engineering Attack Vectors

Attack vectors used in social engineering as described in 'A Taxonomy of Social Engineering Defense Mechanisms' by Dalal Alharthi and others.

Tag examples & metadata
  • social-engineering-attack-vectors:technical="vishing"
  • social-engineering-attack-vectors:technical="spear-phishing"
  • social-engineering-attack-vectors:technical="interesting-software"
Predicates
2
Defined values
18
Exclusive taxonomy
No
UUID
6b5ba18c-d2ab-5949-b495-63f4149b099b
References
  • https://www.researchgate.net/publication/339224082_A_Taxonomy_of_Social_Engineering_Defense_Mechanisms

sov

v1

Cloud Sovereignty Framework

SoV Cloud sovereignty objectives, assurance levels, and scoring weights derived from the European Commission Cloud Sovereignty Framework.

Tag examples & metadata
  • sov:objective="sov-1"
  • sov:objective="sov-2"
  • sov:objective="sov-3"
Predicates
3
Defined values
21
UUID
bdd1d952-daa5-4c5c-b2e1-ecede105f143
References
  • https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en

srbcert

v3

SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection

Tag examples & metadata
  • srbcert:incident-type="virus"
  • srbcert:incident-type="worm"
  • srbcert:incident-type="ransomware"
Predicates
2
Defined values
40
UUID
bc16857c-9d2a-544c-92eb-89bb5aacf5c8

state-responsibility

v1

The Spectrum of State Responsibility

A spectrum of state responsibility to more directly tie the goals of attribution to the needs of policymakers.

Tag examples & metadata
  • state-responsibility:state-prohibited.
  • state-responsibility:state-prohibited-but-inadequate.
  • state-responsibility:state-ignored
Predicates
10
Defined values
0
UUID
b1479ee0-1cec-5085-9909-6168325a8ecc
References
  • https://www.atlanticcouncil.org/wp-content/uploads/2012/02/022212_ACUS_NatlResponsibilityCyber.PDF

stealth_malware

v1

Classification based on malware stealth techniques. Described in https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf

Tag examples & metadata
  • stealth_malware:type="0"
  • stealth_malware:type="I"
  • stealth_malware:type="II"
Predicates
1
Defined values
4
UUID
27cf86e4-eb7b-510b-804d-dc78e9a53182
References
  • https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf

stix-ttp

v1

STIX TTP

TTPs are representations of the behavior or modus operandi of cyber adversaries.

Tag examples & metadata
  • stix-ttp:victim-targeting="business-professional-sector"
  • stix-ttp:victim-targeting="retail-sector"
  • stix-ttp:victim-targeting="financial-sector"
Predicates
1
Defined values
23
UUID
0b0bc55f-347d-507f-99aa-84cf246a4fd1
References
  • http://stixproject.github.io/documentation/idioms/industry-sector/

targeted-threat-index

v3

The Targeted Threat Index is a metric for assigning an overall threat ranking score to email messages that deliver malware to a victim’s computer. The TTI metric was first introduced at SecTor 2013 by Seth Hardy as part of the talk “RATastrophe: Monitoring a Malware Menagerie” along with Katie Kleemola and Greg Wiseman.

Tag examples & metadata
  • targeted-threat-index:targeting-sophistication-base-value="not-targeted"
  • targeted-threat-index:targeting-sophistication-base-value="targeted-but-not-customized"
  • targeted-threat-index:targeting-sophistication-base-value="targeted-and-poorly-customized"
Predicates
2
Defined values
11
UUID
a993a1f6-20b9-5694-94b0-4e26e144a069
References
  • https://citizenlab.org/2013/10/targeted-threat-index/
  • https://www.usenix.org/system/files/conference/usenixsecurity14/sec14-paper-hardy.pdf

thales_group

v4

Thales Group Taxonomy

Thales Group Taxonomy - was designed with the aim of enabling desired sharing and preventing unwanted sharing between Thales Group security communities.

Tag examples & metadata
  • thales_group:distribution="team_eyes_only"
  • thales_group:distribution="limited_distribution"
  • thales_group:distribution="external_alliances"
Predicates
10
Defined values
7
UUID
c76581f5-9cc1-532e-98fd-9d1518871849
References
  • https://www.thalesgroup.com/en/cert

threatmatch

v3

ThreatMatch categories for sharing into ThreatMatch and MISP

The ThreatMatch Sectors, Incident types, Malware types and Alert types are applicable for any ThreatMatch instances and should be used for all CIISI and TIBER Projects.

Tag examples & metadata
  • threatmatch:sector="Banking & Capital Markets"
  • threatmatch:sector="Financial Services"
  • threatmatch:sector="Insurance"
Predicates
4
Defined values
117
UUID
f2cd4dc4-1c05-5b9c-8e49-63c9763c25d2
References
  • https://www.secalliance.com/platform/
  • https://www.ecb.europa.eu/press/pr/date/2020/html/ecb.pr200227_1~062992656b.en.html

threats-to-dns

v1

Threats to DNS

An overview of some of the known attacks related to DNS as described by Torabi, S., Boukhtouta, A., Assi, C., & Debbabi, M. (2018) in Detecting Internet Abuse by Analyzing Passive DNS Traffic: A Survey of Implemented Systems. IEEE Communications Surveys & Tutorials, 1–1. doi:10.1109/comst.2018.2849614

Tag examples & metadata
  • threats-to-dns:dns-protocol-attacks="man-in-the-middle-attack"
  • threats-to-dns:dns-protocol-attacks="dns-spoofing"
  • threats-to-dns:dns-protocol-attacks="dns-rebinding"
Predicates
3
Defined values
18
UUID
b6c92874-0971-53d2-adc9-d26cbc06566c

tlp

v10

Traffic Light Protocol

The Traffic Light Protocol (TLP) (v2.0) was created to facilitate greater sharing of potentially sensitive information and more effective collaboration. Information sharing happens from an information source, towards one or more recipients. TLP is a set of four standard labels (a fifth label is included in amber to limit the diffusion) used to indicate the sharing boundaries to be applied by the recipients. Only labels listed in this standard are considered valid by FIRST. This taxonomy includes additional labels for backward compatibility which are no more validated by FIRST SIG.

Tag examples & metadata
  • tlp:red
  • tlp:amber
  • tlp:amber+strict
Predicates
8
Defined values
0
Exclusive taxonomy
Yes
UUID
34c3905d-5e01-5b53-aebc-6aca2b78eb2b
References
  • https://www.first.org/tlp

tor

v1

Taxonomy to describe Tor network infrastructure

Tag examples & metadata
  • tor:tor-relay-type="entry-guard-relay"
  • tor:tor-relay-type="middle-relay"
  • tor:tor-relay-type="exit-relay"
Predicates
1
Defined values
4
UUID
c9d4ae98-b97c-5e3a-920f-b870c57bc4e6

trust

v1

Indicators of Trust

The Indicator of Trust provides insight about data on what can be trusted and known as a good actor. Similar to a whitelist but on steroids, reusing features one would use with Indicators of Compromise, but to filter out what is known to be good.

Tag examples & metadata
  • trust:trust="unknown"
  • trust:trust="none"
  • trust:trust="partial"
Predicates
3
Defined values
12
Exclusive taxonomy
Yes
UUID
a0a7da02-7f88-5a0c-b78e-61505fa37533
References
  • https://trust.fyi/

type

v1

Taxonomy to describe different types of intelligence gathering discipline which can be described the origin of intelligence.

Tag examples & metadata
  • type:OSINT
  • type:SIGINT
  • type:TECHINT
Predicates
11
Defined values
0
UUID
242f2e2b-dfec-5021-b014-933464d4acd3

uas-additionnal-classification

v2

Additional UAV and UCAV-related tags for qualifying usage and model specifications.

Tag examples & metadata
  • uas-additionnal-classification:FPV
  • uas-additionnal-classification:VTOL
  • uas-additionnal-classification:LM
Predicates
14
Defined values
0
UUID
3f6c2b8e-7c41-4f92-9d63-8e2a1c5b7d44

unified-kill-chain

v1

Unified Kill Chain

The Unified Kill Chain is a refinement to the Kill Chain.

Tag examples & metadata
  • unified-kill-chain:Initial Foothold="reconnaissance"
  • unified-kill-chain:Initial Foothold="weaponization"
  • unified-kill-chain:Initial Foothold="delivery"
Predicates
3
Defined values
19
UUID
9851d9e5-43e9-5792-8dba-feb471a2c49c

unified-ransomware-kill-chain

v1

Unified Ransomware Kill Chain

The Unified Ransomware Kill Chain, a intelligence driven model developed by Oleg Skulkin, aims to track every single phase of a ransomware attack.

Tag examples & metadata
  • unified-ransomware-kill-chain:Gain Access
  • unified-ransomware-kill-chain:Establish Foothold
  • unified-ransomware-kill-chain:Network Discovery
Predicates
9
Defined values
0
UUID
5dcfa500-e8f0-5dab-ac94-674326bcb64d

use-case-applicability

v1

Continuous Monitoring Resolution Category

The Use Case Applicability categories reflect standard resolution categories, to clearly display alerting rule configuration problems.

Tag examples & metadata
  • use-case-applicability:announced-administrative/user-action
  • use-case-applicability:unannounced-administrative/user-action
  • use-case-applicability:log-management-rule-configuration-error
Predicates
8
Defined values
0
UUID
348f77af-bbd1-52e8-b672-0f7375edc4e4

veris

v2

Vocabulary for Event Recording and Incident Sharing (VERIS)

Tag examples & metadata
  • veris:confidence="High"
  • veris:confidence="Low"
  • veris:confidence="Medium"
Predicates
59
Defined values
1992
UUID
6bf15218-9435-5cb0-a8bf-125042c3df24

vmray

v1

VMRay taxonomies to map VMRay Thread Identifier scores and artifacts.

Tag examples & metadata
  • vmray:verdict="malicious"
  • vmray:verdict="suspicious"
  • vmray:verdict="clean"
Predicates
3
Defined values
11
UUID
0d87cdba-a147-5f1e-9126-8efc9a20840c

vocabulaire-des-probabilites-estimatives

v3

Vocabulaire des probabilités estimatives

Ce vocabulaire attribue des valeurs en pourcentage à certains énoncés de probabilité

Tag examples & metadata
  • vocabulaire-des-probabilites-estimatives:degré-de-probabilité="presque-aucune-chance"
  • vocabulaire-des-probabilites-estimatives:degré-de-probabilité="probablement-pas"
  • vocabulaire-des-probabilites-estimatives:degré-de-probabilité="chances-à-peu-près-egales"
Predicates
1
Defined values
5
Exclusive taxonomy
Yes
UUID
81bf8e10-597e-585e-91d6-8886564b03c5
References
  • http://publications.gc.ca/collections/collection_2013/sp-ps/PS64-106-2007-fra.pdf

vulnerability

v7

A taxonomy for describing vulnerabilities (software, hardware, or social) on different scales or with additional available information.

Tag examples & metadata
  • vulnerability:sighting="seen"
  • vulnerability:sighting="confirmed"
  • vulnerability:sighting="published-proof-of-concept"
Predicates
5
Defined values
23
UUID
7639759c-8386-5aa9-b531-8a4081e65017

workflow

v15

workflow to support analysis

Workflow support language is a common language to support intelligence analysts to perform their analysis on data and information.

Tag examples & metadata
  • workflow:todo="expansion"
  • workflow:todo="review"
  • workflow:todo="review-for-privacy"
Predicates
2
Defined values
33
UUID
d8559955-134a-52a9-afc2-17cb38ec5ac7

Source revision 3bb56dbbf541. Counts include enumerated values and predicates without values; they do not enumerate free-text tags. Deprecated taxonomies remain included for compatibility.

MISP Galaxy

MISP galaxy is a simple method to express a large object called cluster that can be attached to MISP events or attributes. A cluster can be composed of one or more elements. Elements are expressed as key-values. There are default vocabularies available in MISP galaxy but those can be overwritten, replaced or updated as you wish. Existing clusters and vocabularies can be used as-is or as a template. MISP distribution can be applied to each cluster to permit a limited or broader distribution scheme. Many MISP galaxy clusters are already available like Exploit-Kit, Microsoft Activity Group actor, Preventive Measure, Ransomware, TDS, Threat actor or Tool used by adversaries.

The galaxy can be browsed via the web site or downloaded as PDF or directly via the MISP software. There is also the website for the misp-galaxy project.