← Prev in month ← Prev in thread
Next in thread → Next in month →

STIX2 Ideas

From
Pumphrey, Mark K [US] (MS) <>
Date
2020-04-06T20:22:18+00:00
ID
Thread
STIX2 Ideas
Some ideas for STIX 2.2...

1) Add the ability to indicate 

a spoofed network connections and email.  In the indicator you can specify 

email-address:from_ref.value, email-message:subject, email-message:additional_head_fields, etc, but nowhere

to put a spoofed boolean flag. Same for network-traffic.

2) Add a similar  definition for the LM Kill chain as you have for TLP

(a marking-definition for reconnaissance or c2 for instance)
← Prev in month ← Prev in thread
Next in thread → Next in month →