diff --git a/STIX_for_digital_forensics/CFO_intro.svg b/STIX_for_digital_forensics/CFO_intro.svg index 7eca914..f007adb 100644 --- a/STIX_for_digital_forensics/CFO_intro.svg +++ b/STIX_for_digital_forensics/CFO_intro.svg @@ -23,10 +23,10 @@ .st9 {font-size:1em} .st10 {marker-end:url(#mrkr4-61);stroke:#008cd8;stroke-linecap:round;stroke-linejoin:round;stroke-width:0.75} .st11 {fill:#008cd8;fill-opacity:1;stroke:#008cd8;stroke-opacity:1;stroke-width:0.22935779816514} - .st12 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} + .st12 {fill:#ffffff;stroke:none;stroke-linecap:butt} .st13 {fill:#002f49;font-family:Franklin Gothic Demi;font-size:0.666664em} - .st14 {fill:#a0370b;font-family:Franklin Gothic Demi;font-size:1.00001em} - .st15 {fill:#ffffff;stroke:none;stroke-linecap:butt} + .st14 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} + .st15 {fill:#a0370b;font-family:Franklin Gothic Demi;font-size:1.00001em} .st16 {fill:none;fill-rule:evenodd;font-size:12px;overflow:visible;stroke-linecap:square;stroke-miterlimit:3} ]]> @@ -377,7 +377,7 @@ - + Indicated-by Dynamic connector.1018 @@ -385,7 +385,7 @@ - + based-on Dynamic connector.1019 @@ -410,7 +410,7 @@ - + evidence-of Dynamic connector.1025 @@ -418,7 +418,7 @@ - + action_refs Dynamic connector.1026 @@ -427,7 +427,7 @@ - + has Dynamic connector.1027 @@ -435,7 +435,7 @@ - + reconstructed_from @@ -451,12 +451,12 @@ class="st9" v:langID="1033">2 Dynamic connector.1029 - output-to + sved-to - + - - output-to + + sved-to Rectangle.1030 software--2 @@ -473,7 +473,7 @@ - + browser_ref Sheet.1032 @@ -496,7 +496,7 @@ - + contains-refs @@ -520,7 +520,7 @@ - + attributed-to Dynamic connector.1038 @@ -528,7 +528,7 @@ - + related-to Rectangle.1039 @@ -539,7 +539,7 @@ - x-investigatorx-investigator--2 Dynamic connector.1040 @@ -556,7 +556,7 @@ - + secondary_storage_refs Rectangle.1042 @@ -594,7 +594,7 @@ - + based-on Dynamic connector.1046 @@ -602,7 +602,7 @@ - + object_refs @@ -618,12 +618,12 @@ class="st9" v:langID="1033">4 Dynamic connector.1048 - output-to + sved-to - + - - output-to + + sved-to Sheet.1049 directory-3 @@ -637,7 +637,7 @@ - + parent_directory_ref Dynamic connector.1051 @@ -683,7 +683,7 @@ - + based-on Dynamic connector.1056 @@ -707,12 +707,12 @@ class="st9" v:langID="1033">3 Dynamic connector.1058 - output-to + sved-to - + - - output-to + + sved-to Sheet.1059 directory-2 @@ -741,9 +741,9 @@ contains-refs - - + + contains-refs @@ -753,7 +753,7 @@ - + contains-refs @@ -782,7 +782,7 @@ - x-investigator--1 + x-investigator--1 Rectangle.1069 x-investigation-tool--1 @@ -836,7 +836,7 @@ - + object_refs Rectangle.1075 @@ -850,19 +850,19 @@ file--1 Dynamic connector.1076 - output-to + saved-to - + - - output-to + + saved-to Dynamic connector.1077 contains-refs - + contains-refs @@ -872,7 +872,7 @@ - + object-refs Rectangle.1079 @@ -912,7 +912,7 @@ - + assigned-to Dynamic connector.1083 @@ -944,7 +944,7 @@ - + exploits Rectangle.1087 @@ -962,7 +962,7 @@ - + url_ref Dynamic connector.1089 @@ -970,7 +970,7 @@ - + object_refs @@ -989,7 +989,7 @@ - + ram_refs Dynamic connector.1092 @@ -997,7 +997,7 @@ - + image-of Sheet.1093 @@ -1020,7 +1020,7 @@ - + communicates-use Rectangle.1098 @@ -1032,15 +1032,7 @@ x-investigation-tool--2 - - Dynamic connector.1099 - processed-by - - - - - processed-by - + Rectangle.1100 x-investigation-tool--3 @@ -1050,7 +1042,7 @@ x-investigation-tool--3 - + Rectangle.1101 x-investigation-tool--4 @@ -1060,31 +1052,31 @@ x-investigation-tool--4 - + Dynamic connector.1102 processed-by - + processed-by - + Dynamic connector.1103 processed-by - + processed-by - + Dynamic connector.1104 has - + has - + Rectangle.1105 x-cloud-storage--1 @@ -1095,7 +1087,7 @@ x-cloud-storage--1 - + Sheet.1106 directory-4 @@ -1103,25 +1095,25 @@ directory-4 - + Dynamic connector.1107 local_directory_ref - + local_directory_ref - + Dynamic connector.1108 contains-refs - + contains-refs - + Rectangle.1130 user-account --2 @@ -1132,21 +1124,37 @@ user-account --2 - + Dynamic connector.1131 requires - + requires - + Dynamic connector investigates - + investigates + + Dynamic connector.1135 + inputs_ref + + + + + inputs_ref + + Dynamic connector.1136 + outputs_refs + + + + + outputs_refs diff --git a/STIX_for_digital_forensics/CFO_intro.vsdx b/STIX_for_digital_forensics/CFO_intro.vsdx index caca691..1ead416 100644 Binary files a/STIX_for_digital_forensics/CFO_intro.vsdx and b/STIX_for_digital_forensics/CFO_intro.vsdx differ diff --git a/STIX_for_digital_forensics/readme.md b/STIX_for_digital_forensics/readme.md index c93a644..e02380a 100644 --- a/STIX_for_digital_forensics/readme.md +++ b/STIX_for_digital_forensics/readme.md @@ -178,8 +178,8 @@ Investigation Tools are software that can be used by cyber investigators to perf | last_modified | timestamps | The last modified date of the investigation tool. | | description | string | A description that provides more details and context about the investigation tool. | | functions | list of type open-vocab | Specifies a list of functions of an Investigation Tool. Each function is summarized in one activity, which SHOULD come from the x-activity-name-ov open vocabulary. | -| input_refs | list of type identifer | Specifies a list of function inputs. It Should come from any STIX objects or CFOs. | -| output_refs | list of type identifer | Specifies a list of function outputs or partial outputs. It Should come from any objects that an Observed Data references to. | +| inputs_refs | list of type identifer | Specifies a list of function inputs. It Should come from any STIX objects or CFOs. | +| outputs_refs | list of type identifer | Specifies a list of function outputs or partial outputs. It Should come from any objects that an Observed Data references to. | | aliases | list of type string | Alternative names used to identify this investigation tool. | | version | string | The version identifier associated with the investigation tool. | | software_ref | identifier | Specifies the software product (if CPE or SWID is known) used as the investigation tool. | @@ -193,7 +193,7 @@ The Activity Name vocabulary is shared by both attackers and investigators. | Vocabulary Value | Description | | ---------------- | ------------------------------------------------------------------- | | steganalysis | | -| browse | | +| browse | Browse webpages, directories, etc. | | carve | | | config | | | copy | | @@ -252,8 +252,8 @@ Use an open-source software to parse and decode $LogFile records "name": "LogFileParser", "functions": ["decode", "parse"], "description": "This program decodes and parses $LogFile records and transaction entries.", - "input_refs": ["file--ce068941-4b0f-4d7f-812d-49735b4a364b"], - "output_refs": ["artifact--ff97e664-7f1e-4e0d-87b0-e37b878c22f4"], + "inputs_refs": ["file--ce068941-4b0f-4d7f-812d-49735b4a364b"], + "outputs_refs": ["artifact--ff97e664-7f1e-4e0d-87b0-e37b878c22f4"], "external_references": [ { "source_name": "LogFileParser",