Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
370 changes: 75 additions & 295 deletions mocks/details.json
Original file line number Diff line number Diff line change
Expand Up @@ -40,303 +40,83 @@
"uuid": "report-uuid-def-456"
}
],
"indicators": {
"tool": {
"name": "elastic",
"version": "7.10"
"indicators": [
{
"created_at": "2024-01-01T00:00:00Z",
"last_seen_at": "2026-02-27T07:36:19.093000Z",
"latest_sighting": {
"description": "Observation: cobaltstrike [2026-02-27T04:19:50.126Z]",
"sighted_at": "2026-02-27T04:19:50.126000Z",
"source": "flashpoint_extraction",
"tags": [
"beacontype:hybrid http dns",
"extracted_config:true",
"httpposturi:/n4215/adj/amzn.us.sr.aps",
"malware:cobaltstrike",
"source:flashpoint_extraction",
"type:backdoor"
]
},
"modified_at": "2026-02-27T09:25:27.557000Z",
"score": {
"last_scored_at": "2025-07-30T07:26:25.981000Z",
"value": "malicious"
},
"total_sightings": 344776,
"type": "domain",
"value": "ns8.softline.top"
},
"took": 145,
"hits": {
"total": 3,
"hits": [
{
"_id": "indicator_id_001",
"_source": {
"fpid": "fp_indicator_88776",
"uuid": "indicator-uuid-aaa-111",
"event_uuid": "event-uuid-bbb-222",
"header_": "some_internal_header",
"first_observed_at": {
"date-time": "2024-01-05T10:20:30Z",
"timestamp": 1704450030
},
"last_observed_at": {
"date-time": "2024-01-15T16:45:22Z",
"timestamp": 1705337122
},
"Attribute": {
"type": "ip-dst",
"category": "Network activity",
"value": "192.168.100.50",
"timestamp": "1704450030"
},
"mitre": {
"fpid": "fp_mitre_55443",
"created_at": {
"date-time": "2023-12-20T09:00:00Z",
"timestamp": 1703062800
},
"last_observed_at": {
"date-time": "2024-01-15T14:20:10Z",
"timestamp": 1705328410
},
"site": {
"fpid": "fp_site_33221",
"title": "MITRE ATT&CK Framework",
"description": {
"raw": "Adversarial tactics and techniques based on real-world observations",
"sanitized": "Adversarial tactics..."
},
"created_at": {
"date-time": "2020-01-01T00:00:00Z",
"timestamp": 1577836800
},
"updated_at": {
"date-time": "2024-01-01T00:00:00Z",
"timestamp": 1704067200
}
},
"body": {
"text/html-sanitized": "<div>HTML body content</div>",
"text/plain": "Plain text body content",
"enrichments": {
"links": [
{
"href": "https://attack.mitre.org/techniques/T1566/",
"title": "Phishing"
},
{
"href": "https://attack.mitre.org/techniques/T1059/",
"title": "Command and Scripting Interpreter"
}
]
}
}
},
"nist": {
"fpid": "fp_nist_77665",
"created_at": {
"date-time": "2023-11-15T08:30:00Z",
"timestamp": 1700036600
},
"updated_at": {
"date-time": "2024-01-10T12:00:00Z",
"timestamp": 1704888000
},
"last_observed_at": {
"date-time": "2024-01-14T18:25:33Z",
"timestamp": 1705257933
},
"site": {
"fpid": "fp_nist_site_44332",
"title": "NIST Vulnerability Database",
"description": {
"raw": "National Vulnerability Database providing CVE information",
"sanitized": "National Vulnerability..."
},
"created_at": {
"date-time": "2019-01-01T00:00:00Z",
"timestamp": 1546300800
},
"updated_at": {
"date-time": "2024-01-15T00:00:00Z",
"timestamp": 1705276800
},
"tags": [
{
"name": "vulnerability",
"id": "tag_001"
},
{
"name": "cve",
"id": "tag_002"
},
{
"name": "exploit",
"id": "tag_003"
}
]
},
"body": {
"enrichments": {
"links": [
{
"href": "https://nvd.nist.gov/vuln/detail/CVE-2023-12345",
"title": "CVE-2023-12345"
},
{
"href": "https://nvd.nist.gov/vuln/detail/CVE-2023-67890",
"title": "CVE-2023-67890"
}
]
}
}
},
"cve": {
"nist": {
"configurations": [
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.0"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.1"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.2"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.3"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.4"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.5"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.6"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.7"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.8"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:1.9"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:2.0"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:2.1"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:2.2"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:2.3"]}]},
{"nodes": [{"operator": "OR", "cpe_match": ["cpe:2.3:a:vendor:product:2.4"]}]}
]
}
},
"enrichments": {
"v1": {
"email_addresses": [
{
"email_address": "threat.actor@malicious.com",
"positions": [[0, 27]]
},
{
"email_address": "contact@bad-domain.ru",
"positions": [[50, 72]]
}
],
"urls": [
{
"url": "https://malicious-site.com/payload",
"positions": [[100, 135]]
},
{
"url": "http://phishing-domain.net/login",
"positions": [[200, 231]]
}
],
"ip_addresses": [
{
"ip_address": "45.123.67.89",
"positions": [[300, 313]]
},
{
"ip_address": "198.51.100.42",
"positions": [[350, 364]]
}
],
"vulnerability": [
{
"CVE-2023-12345": {
"vulnerability": "CVE-2023-12345",
"cvss_score": 9.8
},
"positions": [[400, 414]]
},
{
"CVE-2023-67890": {
"vulnerability": "CVE-2023-67890",
"cvss_score": 7.5
},
"positions": [[450, 464]]
},
{
"CVE-2023-11111": {
"vulnerability": "CVE-2023-11111",
"cvss_score": 8.1
},
"positions": [[500, 514]]
},
{
"CVE-2023-22222": {
"vulnerability": "CVE-2023-22222",
"cvss_score": 6.5
},
"positions": [[550, 564]]
},
{
"CVE-2023-33333": {
"vulnerability": "CVE-2023-33333",
"cvss_score": 7.8
},
"positions": [[600, 614]]
},
{
"CVE-2023-44444": {
"vulnerability": "CVE-2023-44444",
"cvss_score": 9.1
},
"positions": [[650, 664]]
},
{
"CVE-2023-55555": {
"vulnerability": "CVE-2023-55555",
"cvss_score": 5.3
},
"positions": [[700, 714]]
},
{
"CVE-2023-66666": {
"vulnerability": "CVE-2023-66666",
"cvss_score": 8.8
},
"positions": [[750, 764]]
},
{
"CVE-2023-77777": {
"vulnerability": "CVE-2023-77777",
"cvss_score": 7.2
},
"positions": [[800, 814]]
},
{
"CVE-2023-88888": {
"vulnerability": "CVE-2023-88888",
"cvss_score": 6.8
},
"positions": [[850, 864]]
},
{
"CVE-2023-99999": {
"vulnerability": "CVE-2023-99999",
"cvss_score": 9.3
},
"positions": [[900, 914]]
},
{
"CVE-2024-00001": {
"vulnerability": "CVE-2024-00001",
"cvss_score": 8.5
},
"positions": [[950, 964]]
}
]
}
},
"_meta": {
"size": 45632,
"enrichments": {
"v1": {
"email_addresses": {
"enriched_at": "2024-01-15T10:00:00Z",
"version": "1.0"
},
"urls": {
"enriched_at": "2024-01-15T10:00:00Z",
"version": "1.0"
},
"vulnerability": {
"enriched_at": "2024-01-15T10:00:00Z",
"version": "1.0"
}
}
}
}
}
}
]
{
"created_at": "2024-01-01T00:00:00Z",
"last_seen_at": "2026-02-27T07:36:19.019000Z",
"latest_sighting": {
"description": "Observation: cobaltstrike [2026-02-27T04:19:50.126Z]",
"sighted_at": "2026-02-27T04:19:50.126000Z",
"source": "flashpoint_extraction",
"tags": [
"beacontype:hybrid http dns",
"extracted_config:true",
"httpposturi:/n4215/adj/amzn.us.sr.aps",
"malware:cobaltstrike",
"source:flashpoint_extraction",
"type:backdoor"
]
},
"modified_at": "2026-02-27T09:25:25.234000Z",
"score": {
"last_scored_at": "2025-07-30T07:26:22.823000Z",
"value": "malicious"
},
"total_sightings": 345024,
"type": "domain",
"value": "ns7.softline.top"
},
{
"created_at": "2024-01-01T00:00:00Z",
"last_seen_at": "2026-02-27T07:36:19.093000Z",
"latest_sighting": {
"description": "Observation: cobaltstrike [2026-02-27T04:24:23.734Z]",
"sighted_at": "2026-02-27T04:24:23.734000Z",
"source": "flashpoint_extraction",
"tags": [
"beacontype:hybrid http dns",
"extracted_config:true",
"httpposturi:/n4215/adj/amzn.us.sr.aps",
"malware:cobaltstrike",
"source:flashpoint_extraction",
"type:backdoor"
]
},
"modified_at": "2026-02-27T09:25:18.078000Z",
"score": {
"last_scored_at": "2025-07-30T07:26:35.100000Z",
"value": "malicious"
},
"total_sightings": 344874,
"type": "domain",
"value": "ns9.softline.top"
}
},
],
"vulnerabilities": [
{
"cve_id": "CVE-2023-12345",
Expand Down
Loading