← Prev in month
← Prev in thread
Next in thread →
Next in month →
STIX2 Ideas
Some ideas for STIX 2.2... 1) Add the ability to indicate a spoofed network connections and email. In the indicator you can specify email-address:from_ref.value, email-message:subject, email-message:additional_head_fields, etc, but nowhere to put a spoofed boolean flag. Same for network-traffic. 2) Add a similar definition for the LM Kill chain as you have for TLP (a marking-definition for reconnaissance or c2 for instance)
← Prev in month
← Prev in thread
Next in thread →
Next in month →