From be3411d89e00a6c293cb78938c19d992d1a9d6f2 Mon Sep 17 00:00:00 2001 From: Frank Xu Date: Mon, 15 Feb 2021 08:56:04 -0500 Subject: [PATCH] add cloud storage object --- STIX_for_digital_forensics/CFO_intro.svg | 89 +++++++++++------- STIX_for_digital_forensics/readme.md | 34 ++++--- STIX_for_digital_forensics/~$$CFO_intro.~vsdx | Bin 4096 -> 0 bytes 3 files changed, 75 insertions(+), 48 deletions(-) delete mode 100644 STIX_for_digital_forensics/~$$CFO_intro.~vsdx diff --git a/STIX_for_digital_forensics/CFO_intro.svg b/STIX_for_digital_forensics/CFO_intro.svg index b565c0d..08de200 100644 --- a/STIX_for_digital_forensics/CFO_intro.svg +++ b/STIX_for_digital_forensics/CFO_intro.svg @@ -23,9 +23,9 @@ .st9 {font-size:1em} .st10 {marker-end:url(#mrkr4-61);stroke:#008cd8;stroke-linecap:round;stroke-linejoin:round;stroke-width:0.75} .st11 {fill:#008cd8;fill-opacity:1;stroke:#008cd8;stroke-opacity:1;stroke-width:0.22935779816514} - .st12 {fill:#ffffff;stroke:none;stroke-linecap:butt} + .st12 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} .st13 {fill:#002f49;font-family:Franklin Gothic Demi;font-size:0.666664em} - .st14 {fill:#ffffff;stroke:none;stroke-linecap:butt;stroke-width:7.2} + .st14 {fill:#ffffff;stroke:none;stroke-linecap:butt} .st15 {fill:none;fill-rule:evenodd;font-size:12px;overflow:visible;stroke-linecap:square;stroke-miterlimit:3} ]]> @@ -427,7 +427,7 @@ - + has Dynamic connector.1027 @@ -435,7 +435,7 @@ - + reconstructed_from @@ -455,7 +455,7 @@ - + source_ref Rectangle.1030 @@ -473,7 +473,7 @@ - + browser_ref Sheet.1032 @@ -488,7 +488,7 @@ - + parent_directory_ref Dynamic connector.1034 @@ -496,7 +496,7 @@ - + contains-refs @@ -520,7 +520,7 @@ - + attributed-to Dynamic connector.1038 @@ -548,7 +548,7 @@ - + reconstructed_by @@ -557,7 +557,7 @@ - + secondary_storage_refs Rectangle.1042 @@ -595,7 +595,7 @@ - + based-on Dynamic connector.1046 @@ -603,7 +603,7 @@ - + object_refs @@ -623,7 +623,7 @@ - + source_ref Sheet.1049 @@ -638,7 +638,7 @@ - + parent_directory_ref Dynamic connector.1051 @@ -646,7 +646,7 @@ - + indicated-by Rectangle.1052 @@ -727,7 +727,7 @@ - + parent_directory_ref Dynamic connector.1061 @@ -735,7 +735,7 @@ - + indicated-by Dynamic connector.1062 @@ -754,7 +754,7 @@ - + contains-refs @@ -764,7 +764,7 @@ - + part-of Dynamic connector.1066 @@ -801,7 +801,7 @@ - + acquired_using_tool_ref Rectangle.1071 @@ -819,7 +819,7 @@ - + software_ref Rectangle.1073 @@ -838,7 +838,7 @@ - + object_refs Rectangle.1075 @@ -874,7 +874,7 @@ - + object-refs Rectangle.1079 @@ -914,7 +914,7 @@ - + assigned-to Dynamic connector.1083 @@ -938,7 +938,7 @@ - + exploits Dynamic connector.1086 @@ -964,7 +964,7 @@ - + url_ref Dynamic connector.1089 @@ -972,7 +972,7 @@ - + object_refs @@ -1022,7 +1022,7 @@ - + communicates-use Rectangle.1098 @@ -1040,7 +1040,7 @@ - + processed-by Rectangle.1100 @@ -1068,7 +1068,7 @@ - + processed-by Dynamic connector.1103 @@ -1076,7 +1076,7 @@ - + processed-by Dynamic connector.1104 @@ -1084,7 +1084,7 @@ - + has Rectangle.1105 @@ -1111,7 +1111,7 @@ - + local_directory_ref Dynamic connector.1108 @@ -1119,9 +1119,28 @@ - + contains-refs + + Rectangle.1130 + user-account --2 + + + + + + + user-account --2 + + Dynamic connector.1131 + requires + + + + + requires diff --git a/STIX_for_digital_forensics/readme.md b/STIX_for_digital_forensics/readme.md index 4106d77..efb1a3c 100644 --- a/STIX_for_digital_forensics/readme.md +++ b/STIX_for_digital_forensics/readme.md @@ -796,19 +796,27 @@ Cloud Storage object represent a cloud space to store data. ### Example 1: describes a "logon" event recorded in the security event file. ```json -{ - "type": "x-cloud-storage", - "spec_version": "2.1", - "id": " x-cloud-storage--771c2a9a-db0c-4328-bfa0-5d1b5359da45", - "software_ref": "software--fe5b3c0d-810c-4e08-bdff-de9084aff90d", - "cloud_url_ref": "url--26164fad-f2c1-4aee-b517-bbedb84094ec", - "cloud_file_refs": [ - "file--39f88548-ff7f-4377-a79e-bd95aa92bf0b", - "file--dc2771e8-5b45-4e39-a162-a1465e80850f" - ], - "local_directory_ref": "directory--2c1f4e62-c6c7-48cc-b682-cbc04dc7c27b", - "size": 150000 -} +[ + { + "type": "x-cloud-storage", + "spec_version": "2.1", + "id": " x-cloud-storage--771c2a9a-db0c-4328-bfa0-5d1b5359da45", + "software_ref": "software--fe5b3c0d-810c-4e08-bdff-de9084aff90d", + "cloud_url_ref": "url--26164fad-f2c1-4aee-b517-bbedb84094ec", + "cloud_file_refs": [ + "file--39f88548-ff7f-4377-a79e-bd95aa92bf0b", + "file--dc2771e8-5b45-4e39-a162-a1465e80850f" + ], + "local_directory_ref": "directory--2c1f4e62-c6c7-48cc-b682-cbc04dc7c27b", + "size": 150000 + }, + { + "type": "url", + "spec_version": "2.1", + "id": "url--26164fad-f2c1-4aee-b517-bbedb84094ec", + "value": "https://www.dropbox.com/h" + } +] ``` ## Windows Event Object diff --git a/STIX_for_digital_forensics/~$$CFO_intro.~vsdx b/STIX_for_digital_forensics/~$$CFO_intro.~vsdx deleted file mode 100644 index 2f2f0565f2d7c1697caa8f984a76938bdfe87437..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 4096 zcmeHJyH3ME5S%1{gcPLEP(&2|fk=^3L}?IB+7yvc9vy;2xFC^uiob!9lAeEnjuw7_ zo|qYA3&%;!o}fwaTDI@@=623|ySILR+J3!zD8C^gdnjNMY+@s(&#|44`XykUZRsXK z5J+9%&1NP`$*HF7hu|v=7<1?F8HJ;?$qU9x$mdjdRF||53t&^~HTHB% z#<(W0)={-ePF}o8QKlL={7R)nY5Zd==Go&5>yRQ7uq@ zW;Nl