twigs / messages / announcement

A bundle of STIX content not explicitly solicited by another party.

Fields

Name Type Description
id string ID for this message
created_at string The time at which this message was produced
producer_ref string The ID number of the producer of this message
sources array <information-source>
id string The format used for all IDs in TWIGS
identity identity-characteristics
title string A title for this construct
description string A description for this construct
tool tool
title string A title for this construct
description string A description for this construct
data_markings array <data-marking>
id string The ID of this marking
producer_ref string The producer of this marking
contents array <one of: asset, attack-pattern, campaign, configuration, course-of-action, exploit, identity, incident, indicator, malicious-infrastructure, kill-chain, malware, observation, opinion, persona, report, threat-actor, malicious-tool, victim-targeting, vulnerability, weakness>
type string Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
variety ["Server", "Desktop", "Networking"] The type of asset this represents
ownership string The ownership category for this asset
management string The management category for this asset
compromised boolean Whether or not this asset has been compromised
owner_aware boolean Whether or not the owner is aware that this asset has been compromised
technical_characteristics characterization A characterization of some observable condition (object or action)
object object CybOX object that characterizes this construct
action object CybOX action that characterizes this construct
type ["attack-pattern"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact on operations if this TTP were to be realized.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
capec_id string CAPEC ID for this attack pattern
type ["campaign"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact of this campaign on operations (assuming the organization is under attack)
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
status object The status of this campaign (historic, ongoing, or future)
value ["Historic", "Ongoing", "Future"] A value from the enumeration for this statement
extended_value object
description string A textual description of this statement
credibility integer The credibility of this statement, using the Admirality scale
type ["configuration"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact of this vulnerability were it to be exploited
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
cce_id string The CCE ID for this configuration
type ["course-of-action"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
stage ["Remedy", "Response"] Whether this course of action is a preemptive remedy or a response action.
kind ["Perimeter Blocking", "Internal Blocking", "Redirection", "Redirection (Honey Pot)", "Hardening", "Patching", "Eradication", "Rebuilding", "Training", "Monitoring", "Physical Access Restrictions", "Logical Access Restrictions", "Public Disclosure", "Diplomatic Actions", "Policy Actions", "Other"] The type of course of action this describes, such as a policy change, monitoring, or redirection.
objective object
description string A textual description for this COA objective
applicability_confidence integer The likelihood that carrying out the COA will achieve this objective, using the Admirality scale
structured_coa object A structured representation for how this course of action can be achieved. For example, a Snort blocking rule.
impact object The impact that implementing this COA would have on system operations
value ["high", "medium", "low"] A value from the enumeration for this statement
extended_value object
description string A textual description of this statement
credibility integer The credibility of this statement, using the Admirality scale
cost object The cost of implementing this COA (monetary, operational, or other)
value ["high", "medium", "low"] A value from the enumeration for this statement
extended_value object
description string A textual description of this statement
credibility integer The credibility of this statement, using the Admirality scale
type ["exploit"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact on operations if this TTP were to be realized.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
type ["identity", "threat-actor"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
type ["incident"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
category ["Investigation", "Incident"]
impact impact The impact of this attack on operations
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
type string Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
pattern one of: twigs, snort, snort-so, yara The pattern used to identify the presence of this indicator
type ["twigs"] Type of pattern
properties object A list of properties that are applied in the condition
conditions string The string conditions for when this indicator should match
type ["snort"] Type of pattern
rules array <object> The set of snort rules to match this indicator
type ["snort-so"] Type of pattern
rule_stub string The plain text rule stub
rule_binary external A structure to represent external data (e.g. binary, XML)
content_type string MIME type of the external data
charset string For content that has an encoding, the charset of the encoded content
content string The content itself. Content must either be base64 encoded and base64 must be set to true or it must be escaped per JSON string escape rules.
type ["yara"] Type of pattern
rules array <object> The set of YARA rules to match this indicator
start_time date-time The time at which this indicator should be considered valid. If omitted, unknown.
end_time date-time The time at which this indicator should no longer be considered valid. If omitted, unknown or ongoing.
impact impact The impact to operations of the TTP(s) that this indicator detects were they to be realized (individually)
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
type ["malicious-infrastructure"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact on operations if this TTP were to be realized.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
kind array <object> The type of infrastructure being described
type ["kill-chain"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
phases array <kill-chain-phase>
title string A title for this construct
description string A description for this construct
id string The ID of this kill chain phase
type ["malware"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact on operations if this TTP were to be realized.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
kind array <object> The type of malware being described
maec object MAEC characterization of this malware
type ["observation"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
object object CybOX object that characterizes this construct
action object CybOX action that characterizes this construct
observed_at array <string> A list of times that this sighting was observed.
observed_at_precision string
type ["opinion"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
object_ref string The id of the object to which this opinion refers
agreement array <object> The type of opinion being made
type ["persona"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact on operations if this TTP were to be realized.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
identity identity-characteristics The identifying characteristics that this persona describes.
title string A title for this construct
description string A description for this construct
type ["report"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
type ["threat-actor"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact that an attack by this threat actor could have on operations.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
identity identity-characteristics The identity of this threat actor
title string A title for this construct
description string A description for this construct
kind object The type of threat actor
motivation object The motivation for why this threat actor carries out malicious attacks.
sophistication object The sophistication of this threat actor.
planning_and_operational_support object The planning and operational support available to this threat actor.
type ["malicious-tool"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact on operations if this TTP were to be realized.
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
compensation_model string The type of compensation model used for this tool.
kind array <object> The type of tool being described
type ["victim-targeting"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
targets array <object>
type ["vulnerability"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact of this vulnerability were it to be exploited
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
cve_id string The CVE ID for this vulnerability
type ["weakness"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
title string A title for this construct
description string A description for this construct
impact impact The impact of this vulnerability were it to be exploited
level integer The estimated severity of the impact.
intended_effects array <["Military Advantage", "Economic Advantage", "Political Advantage", "Intellectual Property Theft", "Identify Theft", "Brand Damage", "Degredation of Service", "Denial and Deception", "Destruction", "Disruption", "Exposure", "Extortion", "Fraud", "Harassment", "Watch the World Burn"]>
description string A prose description of the impact.
credibility integer The credibility of this statement, using the Admirality scale
cwe_id string The CWE ID for this weakness
relationships array <relationship>
type ["relationship"] Hardcoded value to indicate what type of construct this is
id string Globally unique identifier for this construct.
revision integer The revision number of this construct. MUST be omitted if this is the first version, otherwise required.
created_at string Time at which this construct was created.
external_ids array <object> A list of external identifiers by which this construct may be known.
source string The source of this ID, i.e. name of an external system.
id string ID itself
link string A link to this construct in the external system
producer_ref string ID to the information source that produced this content
marking_refs array <string> The set of markings to be applied to this construct
structured_markings array <structured-marking> The set of L2 markings to be applied to this construct
controlled_structures array <string> A list of JSONPath statements, rooted at the top-level object that the structured_markings key is contained in, that the marking_refs apply to.
marking_refs array <string> The set of markings applied to the fields selected by the controlled_structures.
value string The type of relationship being described.
source_ref string The id of the source (from node) of the relationship.
target_ref string The id of the target (to node) of the relationship
observed_at array <date-time> A list of times that this relationship was observed.
credibility integer The credibility of this construct, using the Admirality scale