From 41bcbecbf2332f8d286b8b1cf139da7b1a819032 Mon Sep 17 00:00:00 2001 From: Frank Xu Date: Wed, 17 Feb 2021 11:14:25 -0500 Subject: [PATCH] add relation saved-to to events and visits --- STIX_for_digital_forensics/CFO_intro.svg | 268 +++++++++--------- STIX_for_digital_forensics/~$$CFO_intro.~vsdx | Bin 4096 -> 0 bytes 2 files changed, 133 insertions(+), 135 deletions(-) delete mode 100644 STIX_for_digital_forensics/~$$CFO_intro.~vsdx diff --git a/STIX_for_digital_forensics/CFO_intro.svg b/STIX_for_digital_forensics/CFO_intro.svg index 58fa0a2..d093fcc 100644 --- a/STIX_for_digital_forensics/CFO_intro.svg +++ b/STIX_for_digital_forensics/CFO_intro.svg @@ -3,7 +3,7 @@ + xml:space="preserve" color-interpolation-filters="sRGB" class="st16"> @@ -23,10 +23,11 @@ .st9 {font-size:1em} .st10 {marker-end:url(#mrkr4-61);stroke:#008cd8;stroke-linecap:round;stroke-linejoin:round;stroke-width:0.75} .st11 {fill:#008cd8;fill-opacity:1;stroke:#008cd8;stroke-opacity:1;stroke-width:0.22935779816514} - .st12 {fill:#ffffff;stroke:none;stroke-linecap:butt} + .st12 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} .st13 {fill:#002f49;font-family:Franklin Gothic Demi;font-size:0.666664em} - .st14 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} - .st15 {fill:none;fill-rule:evenodd;font-size:12px;overflow:visible;stroke-linecap:square;stroke-miterlimit:3} + .st14 {fill:#ffffff;stroke:none;stroke-linecap:butt} + .st15 {fill:#a0370b;font-family:Franklin Gothic Demi;font-size:1.00001em} + .st16 {fill:none;fill-rule:evenodd;font-size:12px;overflow:visible;stroke-linecap:square;stroke-miterlimit:3} ]]> @@ -89,7 +90,6 @@ - Plain.1125 @@ -308,14 +308,14 @@ x-crime-case--1 Rectangle.1006 - x-timeline + x-timeline--1 - x-timeline + x-timeline--1 Rectangle.1008 x-action--2 @@ -369,7 +369,7 @@ - + action_refs Dynamic connector.1017 @@ -377,7 +377,7 @@ - + Indicated-by Dynamic connector.1018 @@ -385,7 +385,7 @@ - + based-on Dynamic connector.1019 @@ -393,7 +393,7 @@ - + object_refs @@ -402,7 +402,7 @@ - + image-of Dynamic connector.1024 @@ -410,7 +410,7 @@ - + evidence-of Dynamic connector.1025 @@ -418,7 +418,7 @@ - + action_refs Dynamic connector.1026 @@ -427,7 +427,7 @@ - + has Dynamic connector.1027 @@ -435,7 +435,7 @@ - + reconstructed_from @@ -451,12 +451,12 @@ class="st9" v:langID="1033">2 Dynamic connector.1029 - source_ref + sved-to - + - - source_ref + + sved-to Rectangle.1030 software--2 @@ -473,7 +473,7 @@ - + browser_ref Sheet.1032 @@ -520,7 +520,7 @@ - + attributed-to Dynamic connector.1038 @@ -528,38 +528,37 @@ - + related-to Rectangle.1039 - identity--2 + x-investigator--2 - - identity--2 - + + x-investigator--2 + Dynamic connector.1040 reconstructed_by - + reconstructed_by - + Dynamic connector.1041 secondary_storage_refs - + secondary_storage_refs - + Rectangle.1042 indicator--3 @@ -569,7 +568,7 @@ indicator--3 - + Rectangle.1043 observed-data--3 @@ -579,7 +578,7 @@ observed-data--3 - + Rectangle.1044 x-pnp-evt--1 @@ -589,24 +588,24 @@ x-pnp-evt--1 - + Dynamic connector.1045 based-on - + based-on - + Dynamic connector.1046 object_refs - + object_refs - + Rectangle.1047 file--4 @@ -617,22 +616,22 @@ file--4 - + Dynamic connector.1048 - source_ref + sved-to - + - - source_ref - + + sved-to + Sheet.1049 directory-3 directory-3 - + Dynamic connector.1050 parent_directory_ref @@ -640,15 +639,15 @@ parent_directory_ref - + Dynamic connector.1051 indicated-by - + indicated-by - + Rectangle.1052 indicator—2 @@ -658,7 +657,7 @@ indicator—2 - + Rectangle.1053 observed-data—2 @@ -668,7 +667,7 @@ observed-data—2 - + Rectangle.1054 x-windows-evt-2 @@ -678,24 +677,24 @@ x-windows-evt-2 - + Dynamic connector.1055 based-on - + based-on - + Dynamic connector.1056 object_refs - + object_refs - + Rectangle.1057 file--3 @@ -706,30 +705,30 @@ file--3 - + Dynamic connector.1058 - source_ref + sved-to - + - - source_ref - + + sved-to + Sheet.1059 directory-2 directory-2 - + Dynamic connector.1060 parent_directory_ref - + parent_directory_ref - + Dynamic connector.1061 indicated-by @@ -737,18 +736,18 @@ indicated-by - + Dynamic connector.1062 contains-refs - + contains-refs - + Dynamic connector.1063 contains-refs @@ -758,7 +757,7 @@ contains-refs - + Dynamic connector.1065 part-of @@ -766,7 +765,7 @@ part-of - + Dynamic connector.1066 used-in @@ -774,7 +773,7 @@ used-in - + Rectangle.1067 x-investigator--1 @@ -782,10 +781,9 @@ - - x-investigator--1 - + + x-investigator--1 + Rectangle.1069 x-investigation-tool--1 @@ -795,7 +793,7 @@ x-investigation-tool--1 - + Dynamic connector.1070 acquired_using_ref @@ -803,7 +801,7 @@ acquired_using_ref - + Rectangle.1071 software--1 @@ -813,15 +811,15 @@ software--1 - + Dynamic connector.1072 software_ref - + software_ref - + Rectangle.1073 x-file-visit--1 @@ -832,15 +830,15 @@ x-file-visit--1 - + Dynamic connector.1074 object_refs - + object_refs - + Rectangle.1075 file--1 @@ -850,15 +848,15 @@ file--1 - + Dynamic connector.1076 - source-ref + saved-to - + - - source-ref - + + saved-to + Dynamic connector.1077 contains-refs @@ -868,7 +866,7 @@ contains-refs - + Dynamic connector.1078 object-refs @@ -876,7 +874,7 @@ object-refs - + Rectangle.1079 Cyber Forensic Domain Object @@ -887,7 +885,7 @@ Cyber Forensic Domain Object - + Rectangle.1080 Cyber Forensic Domain Object @@ -898,7 +896,7 @@ Cyber Forensic Domain Object - + Rectangle.1081 STIX Object @@ -908,7 +906,7 @@ STIX Object - + Dynamic connector.1082 assigned-to @@ -916,39 +914,39 @@ assigned-to - + Dynamic connector.1083 invovles - + invovles - + Dynamic connector.1084 acquired_by_ref - + acquired_by_ref - + Dynamic connector.1085 exploits - + exploits - + Dynamic connector.1086 exploits - + exploits - + Rectangle.1087 url @@ -958,24 +956,24 @@ url - + Dynamic connector.1088 url_ref - + url_ref - + Dynamic connector.1089 object_refs - + object_refs - + Rectangle.1090 x-ram @@ -985,7 +983,7 @@ x-ram - + Dynamic connector.1091 ram_refs @@ -993,15 +991,15 @@ ram_refs - + Dynamic connector.1092 image-of - + image-of - + Sheet.1093 mac-addr--1 @@ -1009,22 +1007,22 @@ mac-addr--1 - + Sheet.1094 ipv4-addr--1 ipv4-addr--1 - + Dynamic connector.1096 communicates-use - + communicates-use - + Rectangle.1098 x-investigation-tool--2 @@ -1034,15 +1032,15 @@ x-investigation-tool--2 - + Dynamic connector.1099 processed-by - + processed-by - + Rectangle.1100 x-investigation-tool--3 @@ -1052,7 +1050,7 @@ x-investigation-tool--3 - + Rectangle.1101 x-investigation-tool--4 @@ -1062,15 +1060,15 @@ x-investigation-tool--4 - + Dynamic connector.1102 processed-by - + processed-by - + Dynamic connector.1103 processed-by @@ -1078,7 +1076,7 @@ processed-by - + Dynamic connector.1104 has @@ -1086,7 +1084,7 @@ has - + Rectangle.1105 x-cloud-storage--1 @@ -1097,7 +1095,7 @@ x-cloud-storage--1 - + Sheet.1106 directory-4 @@ -1105,15 +1103,15 @@ directory-4 - + Dynamic connector.1107 local_directory_ref - + local_directory_ref - + Dynamic connector.1108 contains-refs @@ -1123,7 +1121,7 @@ contains-refs - + Rectangle.1130 user-account --2 @@ -1134,21 +1132,21 @@ user-account --2 - + Dynamic connector.1131 requires - + requires - + Dynamic connector investigates - + investigates diff --git a/STIX_for_digital_forensics/~$$CFO_intro.~vsdx b/STIX_for_digital_forensics/~$$CFO_intro.~vsdx deleted file mode 100644 index 915070ac9921d456eecca2ecaf6f956025539d4f..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 4096 zcmeHJJxc>Y5PkVj5F*6JB3R@P1Oh2S8nHcALHB@lTmWLDSPN}iU9{I&9dscp}w-A{B=C|?1QH6kCwb;rpUxjsDb0k`SSPPV& zX-$~AW$hp5IA+A3G47QG?m19q=0%+pkIzMYrG6h9){+69k=n*KT90HZv8I=@>y8`