OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] malware and tool


I’m can support this.

 

 

Paul Patrick

 

 

From: <cti-stix@lists.oasis-open.org> on behalf of "Jordan, Bret" <bret.jordan@bluecoat.com>
Date: Wednesday, June 15, 2016 at 9:55 AM
To: "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Subject: [cti-stix] malware and tool
Resent-From: <Paul.Patrick@FireEye.com>

 

All,

 

We had a discussion today on Slack and I think most of us came to agreement on the following design... I will let everyone voice their own support for it...

 

1) We will have a TLO called "malware" and one called "tool (final word smithed name TBD)".  

 

2) A tool can be related to an incident, campaign, Intrusion Set, threat actor, etc with a relationship object.  This relationship object will have verbs like "used-maliciously" etc.

 

3) There will be no flag or categorization on the actual TLO to say it was used maliciously.  The reason for that is a tool is only used maliciously, at a certain time, by a certain person, in a certain way.  RDP / VNC are good examples of this.  

 

4) Malware will also have relationships to the various places that make sense.  

 

5) The tool TLO will have optional fields / properties to allow it to be used for all the uses cases people need. 

 

If you support this or don't support this, please speak up so we can start closing out this issue and moving on. 

 

 

Bret

 

 



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]