cyboxproject.github.io
Getting Started | CybOX Project Documentation
http://cyboxproject.github.io/getting-started
Frequently Asked Questions (FAQs). CybOX v2.1 (current release). The first and most important step to getting started with CybOX is to understand why it was developed, what problems it is designed to solve, and how you can use it to solve those problems. The About CybOX. Page is a great start to understanding this. Familiarize Yourself with the Data Model and Schemas. If you’re an XML person, now would be a good time to download the schemas. To do so, visit the CybOX Releases. In either case, the schema ...
cyboxproject.github.io
Tools and Programmatic Support | CybOX Project Documentation
http://cyboxproject.github.io/documentation/tools
Frequently Asked Questions (FAQs). CybOX v2.1 (current release). Tools and Programmatic Support. This page gives an overview of the tools and utilities that are available to help you work with (and learn) CybOX. It does not go into depth on each tool, but links to the in-depth documentation for that tool directly. CybOX-to-HTML is an XSLT stylesheet that can take a CybOX XML document and turn it into a more readable HTML view. Developer Tools and Utilities. The Email-to-CybOX tool is written in Python an...
cyboxproject.github.io
Versioning Policy | CybOX Project Documentation
http://cyboxproject.github.io/documentation/versioning-policy
Frequently Asked Questions (FAQs). CybOX v2.1 (current release). This document details the current methodology for determining whether a new revision will require a major version change, minor version change, or a version update, and how version information is represented and conveyed in the CybOX Language. Versioning for the four broad categories of the CybOX Language schemas:. CybOX Core, which consists of the cybox core.xsd and cybox common.xsd schemas. An update release may only be initiated to addre...
stixproject.github.io
CourseOfActionType | STIX Project Documentation
http://stixproject.github.io/data-model/1.2/coa/CourseOfActionType
Getting Started with Python. STIX 1.1.1. STIX 1.0.1. CourseOfActionType Course of Action Schema. Represents a single STIX Course of Action. STIX 1.1.1. STIX 1.0.1. Specifies a globally unique identifier for this COA. Specifies a globally unique identifier of a COA specified elsewhere. When idref is specified, the id attribute must not be specified, and any instance of this COA should not hold content. Specifies the relevant STIX-COA schema version for this content. This field is implemented through the x...
stixproject.github.io
Sample Walkthrough | STIX Project Documentation
http://stixproject.github.io/getting-started/sample-walkthrough
Getting Started with Python. STIX 1.1.1. STIX 1.0.1. This walkthrough will look at a simple STIX document and look through it piece by piece to help describe basic STIX concepts. Specifically, we’ll look at a watchlist for IP addresses to see how STIX can be used to describe indicators of malicious activity. Page and reading through the whitepaper and other materials linked from there. First, download the IP Watchlist sample. Attribute to use the online schemas so you can validate it without a local copy...
stixproject.github.io
IncidentType | STIX Project Documentation
http://stixproject.github.io/data-model/1.2/incident/IncidentType
Getting Started with Python. STIX 1.1.1. STIX 1.0.1. Represents a single STIX Incident. STIX 1.1.1. STIX 1.0.1. Specifies a globally unique identifier for this cyber threat Incident. Specifies a globally unique identifier for a cyber threat Incident specified elsewhere. When idref is specified, the id attribute must not be specified, and any instance of this Incident should not hold content. Specifies the relevant STIX-Incident schema version for this content. External ID 0.n. Short Description 0.n.
stixproject.github.io
IndicatorType | STIX Project Documentation
http://stixproject.github.io/data-model/1.2/indicator/IndicatorType
Getting Started with Python. STIX 1.1.1. STIX 1.0.1. Represents a single STIX Indicator. STIX 1.1.1. STIX 1.0.1. If possible, an indicator should include the following fields:. Either Observable, Observable Composition, or Indicator Composition to represent the detectable pattern. Indicated TTP, even if pointing to a very simple TTP with just a title. Creating pattern observables for indicators. Specifies a unique ID for this Indicator. Specifies a reference to the ID of an Indicator specified elsewhere.
stixproject.github.io
Getting Started | STIX Project Documentation
http://stixproject.github.io/getting-started
Getting Started with Python. STIX 1.1.1. STIX 1.0.1. For Analysts and Managers. The Analysts and Manager tutorial track will walk you through understanding the STIX data model and how content is expressed in it at a high level. You won't have to deal with XML or Python at all. The STIX Whitepaper explains why STIX was developed, what problems it solves, and how it solves those problems. It also goes into detail on the individual components of STIX and how they fit together. Python STIX Getting Started.
stixproject.github.io
Authoring Tutorial | STIX Project Documentation
http://stixproject.github.io/getting-started/authoring-tutorial
Getting Started with Python. STIX 1.1.1. STIX 1.0.1. This authoring tutorial will walk you through how to create a simple STIX indicator that looks for a file hash and, if that file hash is found, points to a piece of malware that might be present. You can think of it as a correlary to the sample walkthrough. While that takes an existing piece of content and explains what it means, this will walk through how to actually author content. If you’re using the Python API, the Your First STIX Application.
cyboxproject.github.io
Object Relationships | CybOX Project Documentation
http://cyboxproject.github.io/documentation/object-relationships
Frequently Asked Questions (FAQs). CybOX v2.1 (current release). This page contains a listing of some of the available CybOX Object Object relationships (from the ObjectRelationshipVocab-1.1. Win Memory Page Region. Win Memory Page Region. Win Memory Page Region. Win Memory Page Region. Applicable to a wide range of Objects, particularly in the context of a Process. That creates other Objects. A self-extracting archive file created a file upon extraction. A process created a file during its execution.