O7Xi?F2|RYd~>rClMv2iGnDcf1zd?634Ke9yk_Jm$^1erTt4
z!6!LE(-M~BiuwsWhn7{MoZ?r>W|0LiSp6|2!c3h45FznV9BGt=)zIr_JHhluLH0mUk59a--N8)BVTv
z@5JZ>Xosh16WPTOvEWh*=`ssmOp;pWM9TlEO#Giwl}^h~SMQM7F~rN|IZ^v>=ag_@
ze^cvPR&M#48XN69Z`XXprk$`2N~(Um}@mwZB}zE;w06W`9%eRVVNNm
z&;{nffpKRKl8|Cak*So2*QVM$?h}p8OBvo_H1;O%2`-}}{8GK3VQ>269QA!k_eeA3
zO~L$>^vjA`YShswzAJ<9gc}7SX+qW#y#8*BQk?CVjAB0qYChRY=ufo%;8GsTOG$hi
zbALQfrp-lHzzL-CXq~NXP7<*TmPv($*GTzm&T^rI`9oO9e1MOL(xiRw%q;3wegkN;
zG-0nxBaSZ3)pr%i!qK1A4lw?IlZp5%GHJ%Mp*zouRhK`f4T~8d
z)Ow*por7a+P{uCp2vq4+6P?s&X@&p_3CL_l?FLJanCV(OOvL%NA}3@Gu2jx(wI$jw
zU;z{&0Ja&zY+%r&D`~E36b8uDv28Wy;I499B;yWgT#G_2Ss
zj}MMfLVv-J)YJQNd+6J;Z?{GTsjg+fFln>STXp@D%)JOWtF(^wNEOIUgNmg8yDoAx7K)4&P!WD9Cd-gL*bn9
zDFt2hJncj5a-*FWs7icB64NAPqCt@sLcw&@)6I4ehpp>W@
zr0vkg##;K{WMeAB&B{{GA7k1Z?Uv_Fn{J|`oQ-7UyzI~za$RQ;U*AiJMjCII-NA1X
zTZ658wzg`$zC7P*mYYz<8~8}VM7!7WZot$#ch=FIv*wZ{naL(~
z#&>6StF6}!p>K$GE3am+4qq|%vCnX&U0u|G%??QqbL;xe+=K<895-b08{bgx$mn#{uUS&@;g&x;r;`LNK3*r2+()L|7~F${mp!P24A7<
z{PMorL6TJs54RYCh47u4{k{ijs(=#VY(VUNP;$;up^U!x4cmrZH}`axuzPw+
zN0gCxfgTWfa@mSx^gXRG^eo%+9vpgbg;25cd$ukB{T}+UD0+L0afYGX&
z=-yCtI}EPSaIfMUKqp=M$&siwhqTe35{(9`@-LKG^S4&BM-CSCnOZ^%g}9>5;5>@?
zwd5~F_+MmdD)bmX2lx%<^ra?{=^^MR*@jTB{eE@ZFfsD=FG@zaU}5~6lOzLB;4s5j
zF(e@E@2pVHk?@oT7?7;+bnrwtwjND*+Q`CKE2}ya%~r5=n#HfxBFdgsS0Pp~0wj^s
z^$(ti?~o`i_4k(Wyb(Q9Qd{vQuZCSULhtgW@k<-=W?h+{ElH
zpx7eLDQi>W|luy2`eK@B%x#kGj8gcjO!$1FJS-kE
z=-FFlingXs1hBXhz3J&X%^kQ&R$=5T>WZ>s;?hjMwVm#bTrld(8-`*2j18)nPAga!
za@Dy${oFg95`+MGCsvM$x}XDqJFq9NRzqx9={!wK{*KpT0r*NrTi>uAs2^X3|1rq(7wm@U^x_ht_r
zbMsG#+5m1lW*0>FMjGi>04!UvD9AMcAH8phdm?}{=q_6hkHn>fr-*>dyUxw>h!C9d
zg)vc1;qk4J)6*C(;T~eN!iZ7@2|+?EjbYT;V=*MxO4nWVD`yj2-M%mVt<{CHwmQ5r
z5G&fI94Mhs6hP%aHGf00Kzx;yO|+ay?_Moa>bKEho1UUs;zIC@!SCuY;fk_3ShSVv
zmj`T>CEB-|x-^V#E71qLdTbQ&fu_a&V^6Gp>h=oSMv&(W9l2hR7Frlt?uTo~-Cy0e
zoP%s^e=-?|=Kly|coKV#)E|2lLkw+nZ-_XbmS^G*8l%?7CZ+VyJFDr@);7kF6g#9)
zaR0o8{GK=^(tp!f%m6FTNYiA!=G_DbI!{4`${FU2(5ItmIu?$gUOB2)4@3%y|Cqp5%8|oZ#S4
z@Be!jK(MdHFEH`~tJ{30_BAzcH6WnTkNU(jH&3!XedENP>4&!7GAe)cHn`mZdu8Ol
zn<>)HW2W{N(O==*pkWVbrgp%qs*YbWyDhh@3H<^6>qkq`82W9Nzv!bUc~-EJcwtB9_u?~0;NW%GLLg;=$wI3Mca)9r!o67+)=VuWouvoe4K3yn
z=la`j?cI1*D{7>Hp802sf~A5hi^+!H*@NHIXo`ZC!A%TWtdh(*}I3QXpA
zFumm>pe6!5KHU9YOu;B3vZ0(xetIp9dZL;ZQ}}76{x}v%=*}%~F~;PrIQ?IGD<9
zLjpzW*f=3cfUKp`XZ$&R+IoGmPT!U4LqTA#{jHZXaLy=l3#2oQBU
zSAUFq_t73dwBLmsaHIny#o)}r3JlDi!EsYy$iVm=YC)G;kyQIRN6Y|ohzKfCzfX|3
zqNl^5WZ(}}KJ$3=48uCG#E;DWo_)dUXjLm8GbE_n)}45wNS*UaI8&QTw;y6V@q^|d
zPAPs5PyV}@)FiVg@S;2;?l&^nN
z$oJL;UQq1m1{>GgQpoJzu@fbE)>*V#!D72ZySZ>L
zG{kmfDw&f1rSUm`fRi=TnfE_=rC;m$$K4{!5@rxPh7M>y98A3z0IDY7>2c}@eg;XZ
z(k#d2MXmoZ=79OWlE*NLwq2hUo;EAV^4@xDe218QDfdYjEyO*OFHcpqkX(=-Vd90#
z?IujRLFL@)u6pPteJ&_xbLH%CDeHkoA@ZmFhQ@qWaKe$j-3!^5BZ#*Q>K1PlX!wB`q`#fI3=hlf0&ANvvd=Fax^y){_|MHN)MpPB;m^Q
zXwkgqynhMDLF%Ec#k^y!S#-%}X~W7$Syi~)H80*4EXN~EUrCHblKd0NQ}j(pKJnip
zBLNhI#D<62(qN&yftqtf^WJA7#B6Jc5`IQ_LEcx*)sm=~N{3y&+&?jkon;w`&}>nl
zDQ#m@F@{R+TJudN2gCP(1($5uB}#Udwiw*94macpHbq3NEnK#0awHGR4Q(vYH+#kfyvL0e;tY>gIv)3w`H-p)pi@cJd%=!*MuSP6hrvDsYt<8FWo
z%tn9?qOBzouYMsxY6w>dn?6OPPt;z6C{SXy*d*#YDzwkn7purNi
z&%JrK@u+j?8<#iyD#3eDyDbyknMtlw{KzB@a<7$#+;5{IxmXKsO(4~|v@Kh&GhFCf
zlbdfGH?$SmxV`kxGkQDoef22&^LP9MHRNB+N=|;9{+|;`ax_=Vys534DKqOnB;hzPsG&tY*4N)@e*JEXs
z$0dbHs}=<9{T8LxJtLB#*Ln3!nl{(tBp=$yHQv1W`eT&f!BHHfXF1CL>fE!I@o#_?
zOwf9MYov$i5;_!4W*pEhaLLy?DkdDQ$%B>3H8v^ox8gcyNQ?IbZ_`plGV|C>$ix+G
zL~1NOlFF=LzY}Tv^c++xrYr-M6-;Q!!(rq=x^BwV1&Af0@`|6oY;2lcmHnmT$ldQbHYe
literal 0
HcmV?d00001
diff --git a/doping-substances/README.md b/doping-substances/README.md
new file mode 100644
index 0000000..db4ba68
--- /dev/null
+++ b/doping-substances/README.md
@@ -0,0 +1,44 @@
+# MISP_DopingSubstanceTaxonomy
+
+This project aims to gather information about all the prohibited sports Doping Substances.
+
+We collected all of the information on the [WADA website](https://www.wada-ama.org/en/prohibited-list).
+
+To do that we have created a python script to scrap this website and generate a JSON file (Taxonomy).
+
+This Taxonomy could be add in MISP to help sports organizations to fight against usage of doping substances.
+
+## MISP
+
+![logo](Misp-logo.png)
+
+What is MISP ?
+
+>A threat intelligence platform for sharing, storing and correlating
+Indicators of Compromise of targeted attacks, threat intelligence,
+financial fraud information, vulnerability information or even
+counter-terrorism information. Discover how MISP is used today in
+multiple organisations. Not only to store, share, collaborate on cyber
+security indicators, malware analysis, but also to use the IoCs and
+information to detect and prevent attacks, frauds or threats against ICT
+ infrastructures, organisations or people.
+
+## JSON Generation
+
+In order to build the JSON file, we created a Python script which scrap the WADA (World Anti-Doping Agency) ‘s prohibited list.
+
+Thanks to BeautifulSoup, a useful library that helps a lot when it comes to scrap HTLM documents, the script is able to get all the list of doping substances.
+
+The file is created with PyTaxonomies, a MISP library that help to create valid JSON file according to the [MISP Platform](https://www.misp-project.org/taxonomies.html#_misp_taxonomies).
+
+Finally, the script generates all predicates (doping categories) and the entries associated (the doping substances themselves).
+
+## Installation
+
+If you want to try it out yourself, you need to have both BeautifulSoup & PyTaxonomies installated.
+
+## Authors
+
+DELUS Thibaut : https://github.com/WooZyhh
+
+JACOB Lucas : https://github.com/Chaamoxs
diff --git a/doping-substances/gen_taxonomy.py b/doping-substances/gen_taxonomy.py
new file mode 100644
index 0000000..aa205da
--- /dev/null
+++ b/doping-substances/gen_taxonomy.py
@@ -0,0 +1,63 @@
+import json
+import requests
+from bs4 import BeautifulSoup
+from pathlib import Path
+from pytaxonomies import Entry, Predicate, Taxonomy
+
+CONTENT_URL = 'https://www.wada-ama.org/en/prohibited-list'
+
+TAXONOMY_DESCRIPTION = 'This taxonomy aims to list doping substances'
+TAXONOMY_EXPANDED = 'Doping substances'
+TAXONOMY_NAME = 'doping-substances'
+
+ignore = ('NON-APPROVED SUBSTANCES', )
+
+
+def list_predicates(articles):
+ predicates = {}
+ for article in articles:
+ title = article.find('p', attrs={'class': 'h3 panel-title'}).text
+ if title in ignore:
+ continue
+ predicate = Predicate()
+ predicate.predicate = title
+ div = article.find('div', attrs={'class': 'layout-wysiwyg'})
+ description = div.find('p')
+ predicate.description = description.find_next_sibling().text
+ predicates[title] = predicate
+ return predicates
+
+
+def generate_taxonomy():
+ new_taxonomy = Taxonomy()
+
+ new_taxonomy.name = TAXONOMY_NAME
+ new_taxonomy.expanded = TAXONOMY_EXPANDED
+ new_taxonomy.description = TAXONOMY_DESCRIPTION
+
+ response = requests.get(CONTENT_URL)
+ soup = BeautifulSoup(response.text, 'html.parser')
+ articles = soup.findAll('article', attrs={'class': 'panel hide-reader'})
+
+ new_taxonomy.predicates = list_predicates(articles)
+
+ for article in articles:
+ title = article.find('p', attrs={'class': 'h3 panel-title'}).text
+ if title in ignore:
+ continue
+ products = article.findAll('li')
+ products_list = {}
+ for product in products:
+ entry = Entry()
+ entry.value = product.text
+ products_list[entry.value] = entry
+ new_taxonomy.predicates[title].entries = products_list
+
+ return new_taxonomy
+
+
+if __name__ == '__main__':
+ taxonomy = generate_taxonomy()
+ taxonomy.version = 2
+ with open(Path(__file__).resolve().parent / 'machinetag.json', 'wt', encoding='utf-8') as f:
+ json.dump(taxonomy.to_dict(), f, indent=2, ensure_ascii=False)
diff --git a/doping-substances/machinetag.json b/doping-substances/machinetag.json
new file mode 100644
index 0000000..daf66fc
--- /dev/null
+++ b/doping-substances/machinetag.json
@@ -0,0 +1,1006 @@
+{
+ "namespace": "doping-substances",
+ "description": "This taxonomy aims to list doping substances",
+ "version": 2,
+ "expanded": "Doping substances",
+ "predicates": [
+ {
+ "value": "ANABOLIC AGENTS",
+ "description": "Anabolic agents are prohibited."
+ },
+ {
+ "value": "PEPTIDE HORMONES, GROWTH FACTORS, RELATED SUBSTANCES AND MIMETICS",
+ "description": "The following substances, and other substances with similar chemical structure or similar biological effect(s), are prohibited:"
+ },
+ {
+ "value": "BETA-2 AGONISTS",
+ "description": "All selective and non-selective beta-2 agonists, including all optical isomers, are prohibited."
+ },
+ {
+ "value": "HORMONE AND METABOLIC MODULATORS",
+ "description": "The following hormone and metabolic modulators are prohibited."
+ },
+ {
+ "value": "DIURETICS AND MASKING AGENTS",
+ "description": "All diuretics and masking agents, including all optical isomers, e.g. d- and l- where relevant,\nare prohibited."
+ },
+ {
+ "value": "MANIPULATION OF BLOOD AND BLOOD COMPONENTS",
+ "description": "The following are prohibited:"
+ },
+ {
+ "value": "CHEMICAL AND PHYSICAL MANIPULATION",
+ "description": "The following are prohibited:"
+ },
+ {
+ "value": "GENE AND CELL DOPING",
+ "description": "The following, with the potential to enhance sport performance, are prohibited:"
+ },
+ {
+ "value": "STIMULANTS",
+ "description": "Substances of Abuse in this section: cocaine and methylenedioxymethamphetamine (MDMA / “ecstasy”)."
+ },
+ {
+ "value": "NARCOTICS",
+ "description": "The following narcotics, including all optical isomers, e.g. d- and l- where relevant, are prohibited."
+ },
+ {
+ "value": "CANNABINOIDS",
+ "description": " "
+ },
+ {
+ "value": "GLUCOCORTICOIDS",
+ "description": "\nAll glucocorticoids are prohibited when administered by any injectable, oral [including oromucosal (e.g. buccal, gingival, sublingual)] or rectal route."
+ },
+ {
+ "value": "BETA-BLOCKERS",
+ "description": "Beta-blockers are prohibited In-Competition only, in the following sports, and also prohibited Out-of-Competition where indicated (*)."
+ }
+ ],
+ "values": [
+ {
+ "predicate": "ANABOLIC AGENTS",
+ "entry": [
+ {
+ "value": "1-Androstenediol (5α-androst-1-ene-3β, 17β-diol)"
+ },
+ {
+ "value": "1-Androstenedione (5α-androst-1-ene-3, 17-dione)"
+ },
+ {
+ "value": "1-Androsterone (3α-hydroxy-5α-androst-1- ene-17-one)"
+ },
+ {
+ "value": "1-Epiandrosterone (3β-hydroxy-5α-androst- 1-ene-17-one)"
+ },
+ {
+ "value": "1-Testosterone (17β-hydroxy-5α-androst-1- en-3-one)"
+ },
+ {
+ "value": "4-Androstenediol (androst-4-ene-3β,17β- diol)"
+ },
+ {
+ "value": "4-Hydroxytestosterone (4,17β-dihydroxyandrost-4-en-3-one)"
+ },
+ {
+ "value": "5-Androstenedione (androst-5-ene-3,17- dione)"
+ },
+ {
+ "value": "7α-hydroxy-DHEA"
+ },
+ {
+ "value": "7β-hydroxy-DHEA"
+ },
+ {
+ "value": "7-Keto-DHEA"
+ },
+ {
+ "value": "17α-methylepithiostanol (epistane)"
+ },
+ {
+ "value": "19-Norandrostenediol (estr-4-ene-3,17-diol)"
+ },
+ {
+ "value": "19-Norandrostenedione (estr-4-ene-3,17- dione)"
+ },
+ {
+ "value": "Androst-4-ene-3,11,17-trione (11-ketoandrostenedione, adrenosterone)"
+ },
+ {
+ "value": "Androstanolone (5α-dihydrotestosterone, 17β-hydroxy-5α-androstan-3-one)"
+ },
+ {
+ "value": "Androstenediol (androst-5-ene-3β,17β-diol)"
+ },
+ {
+ "value": "Androstenedione (androst-4-ene-3,17- dione)"
+ },
+ {
+ "value": "Bolasterone"
+ },
+ {
+ "value": "Boldenone"
+ },
+ {
+ "value": "Boldione (androsta-1,4-diene-3,17-dione)"
+ },
+ {
+ "value": "Calusterone"
+ },
+ {
+ "value": "Clostebol"
+ },
+ {
+ "value": "Danazol ([1,2]oxazolo[4’,5’:2,3]pregna-4-en- 20-yn-17α-ol)"
+ },
+ {
+ "value": "Dehydrochlormethyltestosterone (4-chloro- 17β-hydroxy-17α-methylandrosta-1,4-dien- 3-one)"
+ },
+ {
+ "value": "Desoxymethyltestosterone (17α-methyl-5α- androst-2-en-17β-ol and 17α-methyl-5α- androst-3-en-17β-ol)"
+ },
+ {
+ "value": "Drostanolone"
+ },
+ {
+ "value": "Epiandrosterone (3β-hydroxy-5α-androstan- 17-one)"
+ },
+ {
+ "value": "Epi-dihydrotestosterone (17β-hydroxy-5β- androstan-3-one)"
+ },
+ {
+ "value": "Epitestosterone"
+ },
+ {
+ "value": "Ethylestrenol (19-norpregna-4-en-17α-ol)"
+ },
+ {
+ "value": "Fluoxymesterone"
+ },
+ {
+ "value": "Formebolone"
+ },
+ {
+ "value": "Furazabol (17α-methyl [1,2,5] oxadiazolo[3’,4’:2,3]-5α-androstan-17β-ol)"
+ },
+ {
+ "value": "Gestrinone"
+ },
+ {
+ "value": "Mestanolone"
+ },
+ {
+ "value": "Mesterolone"
+ },
+ {
+ "value": "Metandienone (17β-hydroxy-17α- methylandrosta-1,4-dien-3-one)"
+ },
+ {
+ "value": "Metenolone"
+ },
+ {
+ "value": "Methandriol"
+ },
+ {
+ "value": "Methasterone (17β-hydroxy-2α,17α- dimethyl-5α-androstan-3-one)"
+ },
+ {
+ "value": "Methyl-1-testosterone (17β-hydroxy-17α- methyl-5α-androst-1-en-3-one)"
+ },
+ {
+ "value": "Methylclostebol"
+ },
+ {
+ "value": "Methyldienolone (17β-hydroxy-17α- methylestra-4,9-dien-3-one)"
+ },
+ {
+ "value": "Methylnortestosterone (17β-hydroxy-17α- methylestr-4-en-3-one)"
+ },
+ {
+ "value": "Methyltestosterone"
+ },
+ {
+ "value": "Metribolone (methyltrienolone, 17β-hydroxy- 17α-methylestra-4,9,11-trien-3-one)"
+ },
+ {
+ "value": "Mibolerone"
+ },
+ {
+ "value": "Nandrolone (19-nortestosterone)"
+ },
+ {
+ "value": "Norboletone"
+ },
+ {
+ "value": "Norclostebol (4-chloro-17β-ol-estr-4-en-3- one)"
+ },
+ {
+ "value": "Norethandrolone"
+ },
+ {
+ "value": "Oxabolone"
+ },
+ {
+ "value": "Oxandrolone"
+ },
+ {
+ "value": "Oxymesterone"
+ },
+ {
+ "value": "Oxymetholone"
+ },
+ {
+ "value": "Prasterone (dehydroepiandrosterone, DHEA, 3β-hydroxyandrost-5-en-17-one)"
+ },
+ {
+ "value": "Prostanozol (17β-[(tetrahydropyran-2-yl) oxy]-1’H-pyrazolo[3,4:2,3]-5α-androstane)"
+ },
+ {
+ "value": "Quinbolone"
+ },
+ {
+ "value": "Stanozolol"
+ },
+ {
+ "value": "Stenbolone"
+ },
+ {
+ "value": "Testosterone"
+ },
+ {
+ "value": "Tetrahydrogestrinone (17-hydroxy-18a- homo-19-nor-17α-pregna-4,9,11-trien-3- one)"
+ },
+ {
+ "value": "Tibolone"
+ },
+ {
+ "value": "Trenbolone (17β-hydroxyestr-4,9,11-trien-3- one)\n\tand other substances with a similar chemical structure or similar biological effect(s)."
+ },
+ {
+ "value": "Clenbuterol"
+ },
+ {
+ "value": "Osilodrostat"
+ },
+ {
+ "value": "Ractopamine"
+ },
+ {
+ "value": "Selective androgen receptor modulators [SARMs, e.g. andarine, enobosarm (ostarine), LGD-4033 (ligandrol), RAD140, S-23 and YK-11]"
+ },
+ {
+ "value": "Zeranol"
+ },
+ {
+ "value": "Zilpaterol"
+ }
+ ]
+ },
+ {
+ "predicate": "PEPTIDE HORMONES, GROWTH FACTORS, RELATED SUBSTANCES AND MIMETICS",
+ "entry": [
+ {
+ "value": "Darbepoetins (dEPO)"
+ },
+ {
+ "value": "Erythropoietins (EPO)"
+ },
+ {
+ "value": "EPO-based constructs [e.g. EPO-Fc, methoxy polyethylene glycol-epoetin beta (CERA)]"
+ },
+ {
+ "value": "EPO-mimetic agents and their constructs (e.g. CNTO-530, peginesatide)"
+ },
+ {
+ "value": "Cobalt"
+ },
+ {
+ "value": "Daprodustat (GSK1278863)"
+ },
+ {
+ "value": "IOX2"
+ },
+ {
+ "value": "Molidustat (BAY 85-3934)"
+ },
+ {
+ "value": "Roxadustat (FG-4592)"
+ },
+ {
+ "value": "Vadadustat (AKB-6548)"
+ },
+ {
+ "value": "Xenon"
+ },
+ {
+ "value": "K-11706"
+ },
+ {
+ "value": "Luspatercept"
+ },
+ {
+ "value": "Sotatercept"
+ },
+ {
+ "value": "Asialo EPO"
+ },
+ {
+ "value": "Carbamylated EPO (CEPO)"
+ },
+ {
+ "value": "Buserelin "
+ },
+ {
+ "value": "Deslorelin"
+ },
+ {
+ "value": "Gonadorelin"
+ },
+ {
+ "value": "Goserelin"
+ },
+ {
+ "value": "Leuprorelin"
+ },
+ {
+ "value": "Nafarelin"
+ },
+ {
+ "value": "Triptorelin"
+ },
+ {
+ "value": "Corticorelin"
+ },
+ {
+ "value": "growth hormone analogues, e.g. lonapegsomatropin, somapacitan and somatrogon"
+ },
+ {
+ "value": "growth hormone fragments, e.g. AOD-9604 and hGH 176-191"
+ },
+ {
+ "value": "growth hormone-releasing hormone (GHRH) and its analogues (e.g. CJC-1293, CJC-1295, sermorelin and tesamorelin)"
+ },
+ {
+ "value": "growth hormone secretagogues (GHS) and their mimetics [e.g. lenomorelin (ghrelin), anamorelin, ipamorelin, macimorelin and tabimorelin]"
+ },
+ {
+ "value": "GH-releasing peptides (GHRPs) [e.g. alexamorelin, GHRP-1, GHRP-2 (pralmorelin), GHRP-3, GHRP-4, GHRP-5, GHRP-6, and examorelin (hexarelin)]"
+ },
+ {
+ "value": "Fibroblast growth factors (FGFs)"
+ },
+ {
+ "value": "Hepatocyte growth factor (HGF)"
+ },
+ {
+ "value": "Insulin-like growth factor 1 (IGF-1) and its analogues"
+ },
+ {
+ "value": "Mechano growth factors (MGFs)"
+ },
+ {
+ "value": "Platelet-derived growth factor (PDGF)"
+ },
+ {
+ "value": "Thymosin-β4 and its derivatives e.g. TB-500"
+ },
+ {
+ "value": "Vascular endothelial growth factor (VEGF)\n\tand other growth factors or growth factor modulators affecting muscle, tendon or ligament protein synthesis/degradation, vascularisation, energy utilization, regenerative capacity or fibre type switching."
+ }
+ ]
+ },
+ {
+ "predicate": "BETA-2 AGONISTS",
+ "entry": [
+ {
+ "value": "Arformoterol"
+ },
+ {
+ "value": "Fenoterol"
+ },
+ {
+ "value": "Formoterol"
+ },
+ {
+ "value": "Higenamine"
+ },
+ {
+ "value": "Indacaterol"
+ },
+ {
+ "value": "Levosalbutamol"
+ },
+ {
+ "value": "Olodaterol"
+ },
+ {
+ "value": "Procaterol"
+ },
+ {
+ "value": "Reproterol"
+ },
+ {
+ "value": "Salbutamol"
+ },
+ {
+ "value": "Salmeterol"
+ },
+ {
+ "value": "Terbutaline"
+ },
+ {
+ "value": "Tretoquinol (trimetoquinol)"
+ },
+ {
+ "value": "Tulobuterol"
+ },
+ {
+ "value": "Vilanterol"
+ },
+ {
+ "value": "Inhaled salbutamol: maximum 1600 micrograms over 24 hours in divided doses not to exceed 600 micrograms over 8 hours starting from any dose"
+ },
+ {
+ "value": "Inhaled formoterol: maximum delivered dose of 54 micrograms over 24 hours"
+ },
+ {
+ "value": "Inhaled salmeterol: maximum 200 micrograms over 24 hours"
+ },
+ {
+ "value": "Inhaled vilanterol: maximum 25 micrograms over 24 hours"
+ }
+ ]
+ },
+ {
+ "predicate": "HORMONE AND METABOLIC MODULATORS",
+ "entry": [
+ {
+ "value": "2-Androstenol (5α-androst-2-en-17-ol)"
+ },
+ {
+ "value": "2-Androstenone (5α-androst-2-en-17-one)"
+ },
+ {
+ "value": "3-Androstenol (5α-androst-3-en-17-ol)"
+ },
+ {
+ "value": "3-Androstenone (5α-androst-3-en-17-one)"
+ },
+ {
+ "value": "4-Androstene-3,6,17 trione (6-oxo)"
+ },
+ {
+ "value": "Aminoglutethimide"
+ },
+ {
+ "value": "Anastrozole"
+ },
+ {
+ "value": "Androsta-1,4,6-triene-3,17-dione (androstatrienedione)"
+ },
+ {
+ "value": "Androsta-3,5-diene-7,17-dione (arimistane)"
+ },
+ {
+ "value": "Exemestane"
+ },
+ {
+ "value": "Formestane"
+ },
+ {
+ "value": "Letrozole"
+ },
+ {
+ "value": "Testolactone"
+ },
+ {
+ "value": "Bazedoxifene"
+ },
+ {
+ "value": "Clomifene"
+ },
+ {
+ "value": "Cyclofenil"
+ },
+ {
+ "value": "Fulvestrant"
+ },
+ {
+ "value": "Ospemifene"
+ },
+ {
+ "value": "Raloxifene"
+ },
+ {
+ "value": "Tamoxifen"
+ },
+ {
+ "value": "Toremifene"
+ },
+ {
+ "value": "Activin A-neutralizing antibodies"
+ },
+ {
+ "value": "Activin receptor IIB competitors such as: \nDecoy activin receptors (e.g. ACE-031)\n"
+ },
+ {
+ "value": "Decoy activin receptors (e.g. ACE-031)"
+ },
+ {
+ "value": "Anti-activin receptor IIB antibodies (e.g. bimagrumab)"
+ },
+ {
+ "value": "Myostatin inhibitors such as:\nAgents reducing or ablating myostatin expression\nMyostatin-binding proteins (e.g. follistatin, myostatin propeptide)\nMyostatin- or precursor - neutralizing antibodies (e.g. apitegromab, domagrozumab, landogrozumab, stamulumab)\n"
+ },
+ {
+ "value": "Agents reducing or ablating myostatin expression"
+ },
+ {
+ "value": "Myostatin-binding proteins (e.g. follistatin, myostatin propeptide)"
+ },
+ {
+ "value": "Myostatin- or precursor - neutralizing antibodies (e.g. apitegromab, domagrozumab, landogrozumab, stamulumab)"
+ }
+ ]
+ },
+ {
+ "predicate": "DIURETICS AND MASKING AGENTS",
+ "entry": [
+ {
+ "value": "Desmopressin; probenecid; plasma expanders, e.g. intravenous administration of albumin, dextran, hydroxyethyl starch and mannitol."
+ },
+ {
+ "value": "Acetazolamide; amiloride; bumetanide; canrenone; chlortalidone; etacrynic acid; furosemide; indapamide; metolazone; spironolactone; thiazides, e.g. bendroflumethiazide, chlorothiazide and hydrochlorothiazide; torasemide; triamterene and vaptans, e.g. tolvaptan."
+ },
+ {
+ "value": "Drospirenone; pamabrom; and topical ophthalmic administration of carbonic anhydrase inhibitors (e.g. dorzolamide, brinzolamide)"
+ },
+ {
+ "value": "Local administration of felypressin in dental anaesthesia"
+ }
+ ]
+ },
+ {
+ "predicate": "STIMULANTS",
+ "entry": [
+ {
+ "value": "Adrafinil"
+ },
+ {
+ "value": "Amfepramone"
+ },
+ {
+ "value": "Amfetamine"
+ },
+ {
+ "value": "Amfetaminil"
+ },
+ {
+ "value": "Amiphenazole"
+ },
+ {
+ "value": "Benfluorex"
+ },
+ {
+ "value": "Benzylpiperazine"
+ },
+ {
+ "value": "Bromantan"
+ },
+ {
+ "value": "Clobenzorex"
+ },
+ {
+ "value": "Cocaine"
+ },
+ {
+ "value": "Cropropamide"
+ },
+ {
+ "value": "Crotetamide"
+ },
+ {
+ "value": "Fencamine"
+ },
+ {
+ "value": "Fenetylline"
+ },
+ {
+ "value": "Fenfluramine"
+ },
+ {
+ "value": "Fenproporex"
+ },
+ {
+ "value": "Fonturacetam [4-phenylpiracetam (carphedon)]"
+ },
+ {
+ "value": "Furfenorex"
+ },
+ {
+ "value": "Lisdexamfetamine"
+ },
+ {
+ "value": "Mefenorex"
+ },
+ {
+ "value": "Mephentermine"
+ },
+ {
+ "value": "Mesocarb"
+ },
+ {
+ "value": "Metamfetamine(d-)"
+ },
+ {
+ "value": "p-methylamfetamine"
+ },
+ {
+ "value": "Modafinil"
+ },
+ {
+ "value": "Norfenfluramine"
+ },
+ {
+ "value": "Phendimetrazine"
+ },
+ {
+ "value": "Phentermine"
+ },
+ {
+ "value": "Prenylamine"
+ },
+ {
+ "value": "Prolintane"
+ },
+ {
+ "value": "3-Methylhexan-2-amine (1,2-dimethylpentylamine)"
+ },
+ {
+ "value": "4-fluoromethylphenidate"
+ },
+ {
+ "value": "4-Methylhexan-2-amine (methylhexaneamine, 1,3-dimethylamylamine, 1,3 DMAA)"
+ },
+ {
+ "value": "4-Methylpentan-2-amine (1,3-dimethylbutylamine)"
+ },
+ {
+ "value": "5-Methylhexan-2-amine (1,4-dimethylpentylamine, 1,4-dimethylamylamine, 1,4-DMAA)"
+ },
+ {
+ "value": "Benzfetamine"
+ },
+ {
+ "value": "Cathine**"
+ },
+ {
+ "value": "Cathinone and its analogues, e.g. mephedrone, methedrone, and α - pyrrolidinovalerophenone"
+ },
+ {
+ "value": "Dimetamfetamine (dimethylamphetamine)"
+ },
+ {
+ "value": "Ephedrine***"
+ },
+ {
+ "value": "Epinephrine**** (adrenaline)"
+ },
+ {
+ "value": "Etamivan"
+ },
+ {
+ "value": "Ethylphenidate"
+ },
+ {
+ "value": "Etilamfetamine"
+ },
+ {
+ "value": "Etilefrine"
+ },
+ {
+ "value": "Famprofazone"
+ },
+ {
+ "value": "Fenbutrazate"
+ },
+ {
+ "value": "Fencamfamin"
+ },
+ {
+ "value": "Heptaminol"
+ },
+ {
+ "value": "Hydrafinil (fluorenol)"
+ },
+ {
+ "value": "Hydroxyamfetamine (parahydroxyamphetamine)"
+ },
+ {
+ "value": "Isometheptene"
+ },
+ {
+ "value": "Levmetamfetamine"
+ },
+ {
+ "value": "Meclofenoxate"
+ },
+ {
+ "value": "Methylenedioxymetham- phetamine"
+ },
+ {
+ "value": "Methylephedrine***"
+ },
+ {
+ "value": "Methylnaphthidate [((±)-methyl-2-(naphthalen-2-yl)-2-(piperidin-2-yl)acetate]"
+ },
+ {
+ "value": "Methylphenidate"
+ },
+ {
+ "value": "Nikethamide"
+ },
+ {
+ "value": "Norfenefrine"
+ },
+ {
+ "value": "Octodrine (1,5-dimethylhex- ylamine)"
+ },
+ {
+ "value": "Octopamine"
+ },
+ {
+ "value": "Oxilofrine (methylsynephrine)"
+ },
+ {
+ "value": "Pemoline"
+ },
+ {
+ "value": "Pentetrazol"
+ },
+ {
+ "value": "Phenethylamine and its derivatives"
+ },
+ {
+ "value": "Phenmetrazine"
+ },
+ {
+ "value": "Phenpromethamine"
+ },
+ {
+ "value": "Propylhexedrine"
+ },
+ {
+ "value": "Pseudoephedrine*****"
+ },
+ {
+ "value": "Selegiline"
+ },
+ {
+ "value": "Sibutramine"
+ },
+ {
+ "value": "Solriamfetol"
+ },
+ {
+ "value": "Strychnine"
+ },
+ {
+ "value": "Tenamfetamine (methylenedioxyamphet- amine)"
+ },
+ {
+ "value": "Tuaminoheptane"
+ },
+ {
+ "value": "Clonidine"
+ },
+ {
+ "value": "Imidazole derivatives for dermatological, nasal, ophthalmic or otic use (e.g. brimonidine, clonazoline, fenoxazoline, indanazoline, naphazoline, oxymetazoline, tetryzoline, xylometazoline) and those stimulants included in the 2023 Monitoring Program*"
+ }
+ ]
+ },
+ {
+ "predicate": "NARCOTICS",
+ "entry": [
+ {
+ "value": "Buprenorphine"
+ },
+ {
+ "value": "Dextromoramide"
+ },
+ {
+ "value": "Diamorphine (heroin)"
+ },
+ {
+ "value": "Fentanyl and its derivatives"
+ },
+ {
+ "value": "Hydromorphone"
+ },
+ {
+ "value": "Methadone"
+ },
+ {
+ "value": "Morphine"
+ },
+ {
+ "value": "Nicomorphine"
+ },
+ {
+ "value": "Oxycodone"
+ },
+ {
+ "value": "Oxymorphone"
+ },
+ {
+ "value": "Pentazocine"
+ },
+ {
+ "value": "Pethidine"
+ }
+ ]
+ },
+ {
+ "predicate": "CANNABINOIDS",
+ "entry": [
+ {
+ "value": "In cannabis (hashish, marijuana) and cannabis products"
+ },
+ {
+ "value": "Synthetic cannabinoids that mimic the effects of THC"
+ },
+ {
+ "value": "Natural and synthetic tetrahydrocannabinols (THCs)"
+ },
+ {
+ "value": "Cannabidiol"
+ }
+ ]
+ },
+ {
+ "predicate": "GLUCOCORTICOIDS",
+ "entry": [
+ {
+ "value": "Beclometasone"
+ },
+ {
+ "value": "Betamethasone"
+ },
+ {
+ "value": "Budesonide"
+ },
+ {
+ "value": "Ciclesonide"
+ },
+ {
+ "value": "Cortisone"
+ },
+ {
+ "value": "Deflazacort"
+ },
+ {
+ "value": "Dexamethasone"
+ },
+ {
+ "value": "Flucortolone"
+ },
+ {
+ "value": "Flunisolide"
+ },
+ {
+ "value": "Fluticasone"
+ },
+ {
+ "value": "Hydrocortisone"
+ },
+ {
+ "value": "Methylprednisolone"
+ },
+ {
+ "value": "Mometasone"
+ },
+ {
+ "value": "Prednisolone"
+ },
+ {
+ "value": "Prednisone"
+ },
+ {
+ "value": "Triamcinolone acetonide"
+ }
+ ]
+ },
+ {
+ "predicate": "BETA-BLOCKERS",
+ "entry": [
+ {
+ "value": "Archery (WA)*"
+ },
+ {
+ "value": "Automobile (FIA)"
+ },
+ {
+ "value": "Billiards (all disciplines) (WCBS)"
+ },
+ {
+ "value": "Darts (WDF)"
+ },
+ {
+ "value": "Golf (IGF)"
+ },
+ {
+ "value": "Mini-Golf (WMF)"
+ },
+ {
+ "value": "Shooting (ISSF, IPC)*"
+ },
+ {
+ "value": "Skiing/Snowboarding (FIS) in ski jumping, freestyle aerials/halfpipe and snowboard halfpipe/big air"
+ },
+ {
+ "value": "Underwater sports (CMAS)* in all subdisciplines of freediving, spearfishing and target shooting"
+ },
+ {
+ "value": "Acebutolol"
+ },
+ {
+ "value": "Alprenolol"
+ },
+ {
+ "value": "Atenolol"
+ },
+ {
+ "value": "Betaxolol"
+ },
+ {
+ "value": "Bisoprolol"
+ },
+ {
+ "value": "Bunolol"
+ },
+ {
+ "value": "Carteolol"
+ },
+ {
+ "value": "Carvedilol"
+ },
+ {
+ "value": "Celiprolol"
+ },
+ {
+ "value": "Esmolol"
+ },
+ {
+ "value": "Labetalol"
+ },
+ {
+ "value": "Metipranolol"
+ },
+ {
+ "value": "Metoprolol"
+ },
+ {
+ "value": "Nadolol"
+ },
+ {
+ "value": "Nebivolol"
+ },
+ {
+ "value": "Oxprenolol"
+ },
+ {
+ "value": "Pindolol"
+ },
+ {
+ "value": "Propranolol"
+ },
+ {
+ "value": "Sotalol"
+ },
+ {
+ "value": "Timolol"
+ }
+ ]
+ }
+ ]
+}
\ No newline at end of file
From 13951549f371b85c5092af2b7af92deb9eb2e829 Mon Sep 17 00:00:00 2001
From: Christian Studer
Date: Tue, 17 Oct 2023 23:46:09 +0200
Subject: [PATCH 164/181] chg: [doping-substances] Handmade review of the
taxonomy
---
doping-substances/machinetag.json | 810 +++++++++++++++++-------------
1 file changed, 466 insertions(+), 344 deletions(-)
diff --git a/doping-substances/machinetag.json b/doping-substances/machinetag.json
index daf66fc..f700b9e 100644
--- a/doping-substances/machinetag.json
+++ b/doping-substances/machinetag.json
@@ -5,1002 +5,1124 @@
"expanded": "Doping substances",
"predicates": [
{
- "value": "ANABOLIC AGENTS",
+ "value": "anabolic agents",
"description": "Anabolic agents are prohibited."
},
{
- "value": "PEPTIDE HORMONES, GROWTH FACTORS, RELATED SUBSTANCES AND MIMETICS",
- "description": "The following substances, and other substances with similar chemical structure or similar biological effect(s), are prohibited:"
+ "value": "peptide hormones, growth factors, related substances and mimetics",
+ "description": "The following substances, and other substances with similar chemical structure or similar biological effect(s), are prohibited."
},
{
- "value": "BETA-2 AGONISTS",
+ "value": "beta-2 agonists",
"description": "All selective and non-selective beta-2 agonists, including all optical isomers, are prohibited."
},
{
- "value": "HORMONE AND METABOLIC MODULATORS",
+ "value": "hormone and metabolic modulators",
"description": "The following hormone and metabolic modulators are prohibited."
},
{
- "value": "DIURETICS AND MASKING AGENTS",
- "description": "All diuretics and masking agents, including all optical isomers, e.g. d- and l- where relevant,\nare prohibited."
+ "value": "diuretics and masking agents",
+ "description": "All diuretics and masking agents, including all optical isomers, e.g. d- and l- where relevant, are prohibited."
},
{
- "value": "MANIPULATION OF BLOOD AND BLOOD COMPONENTS",
- "description": "The following are prohibited:"
+ "value": "manipulation of blood and blood components",
+ "description": "The following are prohibited"
},
{
- "value": "CHEMICAL AND PHYSICAL MANIPULATION",
- "description": "The following are prohibited:"
+ "value": "chemical and physical manipulation",
+ "description": "The following are prohibited"
},
{
- "value": "GENE AND CELL DOPING",
- "description": "The following, with the potential to enhance sport performance, are prohibited:"
+ "value": "gene and cell doping",
+ "description": "The following, with the potential to enhance sport performance, are prohibited"
},
{
- "value": "STIMULANTS",
+ "value": "stimulants",
"description": "Substances of Abuse in this section: cocaine and methylenedioxymethamphetamine (MDMA / “ecstasy”)."
},
{
- "value": "NARCOTICS",
+ "value": "narcotics",
"description": "The following narcotics, including all optical isomers, e.g. d- and l- where relevant, are prohibited."
},
{
- "value": "CANNABINOIDS",
- "description": " "
+ "value": "cannabinoids"
},
{
- "value": "GLUCOCORTICOIDS",
- "description": "\nAll glucocorticoids are prohibited when administered by any injectable, oral [including oromucosal (e.g. buccal, gingival, sublingual)] or rectal route."
+ "value": "glucocorticoids",
+ "description": "All glucocorticoids are prohibited when administered by any injectable, oral [including oromucosal (e.g. buccal, gingival, sublingual)] or rectal route."
},
{
- "value": "BETA-BLOCKERS",
+ "value": "beta-blockers",
"description": "Beta-blockers are prohibited In-Competition only, in the following sports, and also prohibited Out-of-Competition where indicated (*)."
}
],
"values": [
{
- "predicate": "ANABOLIC AGENTS",
+ "predicate": "anabolic agents",
"entry": [
{
- "value": "1-Androstenediol (5α-androst-1-ene-3β, 17β-diol)"
+ "value": "1-androstenediol",
+ "expanded": "1-androstenediol (5α-androst-1-ene-3β, 17β-diol)"
},
{
- "value": "1-Androstenedione (5α-androst-1-ene-3, 17-dione)"
+ "value": "1-androstenedione",
+ "expanded": "1-androstenedione (5α-androst-1-ene-3, 17-dione)"
},
{
- "value": "1-Androsterone (3α-hydroxy-5α-androst-1- ene-17-one)"
+ "value": "1-androsterone",
+ "expanded": "1-androsterone (3α-hydroxy-5α-androst-1-ene-17-one)"
},
{
- "value": "1-Epiandrosterone (3β-hydroxy-5α-androst- 1-ene-17-one)"
+ "value": "1-epiandrosterone",
+ "expanded": "1-epiandrosterone (3β-hydroxy-5α-androst-1-ene-17-one)"
},
{
- "value": "1-Testosterone (17β-hydroxy-5α-androst-1- en-3-one)"
+ "value": "1-testosterone",
+ "expanded": "1-testosterone (17β-hydroxy-5α-androst-1-en-3-one)"
},
{
- "value": "4-Androstenediol (androst-4-ene-3β,17β- diol)"
+ "value": "4-androstenediol",
+ "expanded": "4-androstenediol (androst-4-ene-3β,17β-diol)"
},
{
- "value": "4-Hydroxytestosterone (4,17β-dihydroxyandrost-4-en-3-one)"
+ "value": "4-hydroxytestosterone",
+ "expanded": "4-hydroxytestosterone (4,17β-dihydroxyandrost-4-en-3-one)"
},
{
- "value": "5-Androstenedione (androst-5-ene-3,17- dione)"
+ "value": "5-androstenedione",
+ "expanded": "5-androstenedione (androst-5-ene-3,17-dione)"
},
{
- "value": "7α-hydroxy-DHEA"
+ "value": "7α-hydroxy-dhea"
},
{
- "value": "7β-hydroxy-DHEA"
+ "value": "7β-hydroxy-dhea"
},
{
- "value": "7-Keto-DHEA"
+ "value": "7-keto-dhea"
},
{
- "value": "17α-methylepithiostanol (epistane)"
+ "value": "17α-methylepithiostanol",
+ "expanded": "17α-methylepithiostanol (epistane)"
},
{
- "value": "19-Norandrostenediol (estr-4-ene-3,17-diol)"
+ "value": "19-norandrostenediol",
+ "expanded": "19-norandrostenediol (estr-4-ene-3,17-diol)"
},
{
- "value": "19-Norandrostenedione (estr-4-ene-3,17- dione)"
+ "value": "19-norandrostenedione",
+ "expanded": "19-norandrostenedione (estr-4-ene-3,17-dione)"
},
{
- "value": "Androst-4-ene-3,11,17-trione (11-ketoandrostenedione, adrenosterone)"
+ "value": "androst-4-ene-3,11,17-trione",
+ "expanded": "androst-4-ene-3,11,17-trione (11-ketoandrostenedione, adrenosterone)"
},
{
- "value": "Androstanolone (5α-dihydrotestosterone, 17β-hydroxy-5α-androstan-3-one)"
+ "value": "androstanolone",
+ "expanded": "androstanolone (5α-dihydrotestosterone, 17β-hydroxy-5α-androstan-3-one)"
},
{
- "value": "Androstenediol (androst-5-ene-3β,17β-diol)"
+ "value": "androstenediol",
+ "expanded": "androstenediol (androst-5-ene-3β,17β-diol)"
},
{
- "value": "Androstenedione (androst-4-ene-3,17- dione)"
+ "value": "androstenedione",
+ "expanded": "androstenedione (androst-4-ene-3,17-dione)"
},
{
- "value": "Bolasterone"
+ "value": "bolasterone"
},
{
- "value": "Boldenone"
+ "value": "boldenone"
},
{
- "value": "Boldione (androsta-1,4-diene-3,17-dione)"
+ "value": "boldione",
+ "expanded": "boldione (androsta-1,4-diene-3,17-dione)"
},
{
- "value": "Calusterone"
+ "value": "calusterone"
},
{
- "value": "Clostebol"
+ "value": "clostebol"
},
{
- "value": "Danazol ([1,2]oxazolo[4’,5’:2,3]pregna-4-en- 20-yn-17α-ol)"
+ "value": "danazol",
+ "expanded": "danazol ([1,2]oxazolo[4’,5’:2,3]pregna-4-en-20-yn-17α-ol)"
},
{
- "value": "Dehydrochlormethyltestosterone (4-chloro- 17β-hydroxy-17α-methylandrosta-1,4-dien- 3-one)"
+ "value": "dehydrochlormethyltestosterone",
+ "expanded": "dehydrochlormethyltestosterone (4-chloro-17β-hydroxy-17α-methylandrosta-1,4-dien-3-one)"
},
{
- "value": "Desoxymethyltestosterone (17α-methyl-5α- androst-2-en-17β-ol and 17α-methyl-5α- androst-3-en-17β-ol)"
+ "value": "desoxymethyltestosterone",
+ "expanded": "desoxymethyltestosterone (17α-methyl-5α-androst-2-en-17β-ol and 17α-methyl-5α-androst-3-en-17β-ol)"
},
{
- "value": "Drostanolone"
+ "value": "drostanolone"
},
{
- "value": "Epiandrosterone (3β-hydroxy-5α-androstan- 17-one)"
+ "value": "epiandrosterone",
+ "expanded": "epiandrosterone (3β-hydroxy-5α-androstan-17-one)"
},
{
- "value": "Epi-dihydrotestosterone (17β-hydroxy-5β- androstan-3-one)"
+ "value": "epi-dihydrotestosterone",
+ "expanded": "epi-dihydrotestosterone (17β-hydroxy-5β-androstan-3-one)"
},
{
- "value": "Epitestosterone"
+ "value": "epitestosterone"
},
{
- "value": "Ethylestrenol (19-norpregna-4-en-17α-ol)"
+ "value": "ethylestrenol",
+ "expanded": "ethylestrenol (19-norpregna-4-en-17α-ol)"
},
{
- "value": "Fluoxymesterone"
+ "value": "fluoxymesterone"
},
{
- "value": "Formebolone"
+ "value": "formebolone"
},
{
- "value": "Furazabol (17α-methyl [1,2,5] oxadiazolo[3’,4’:2,3]-5α-androstan-17β-ol)"
+ "value": "furazabol",
+ "expanded": "furazabol (17α-methyl [1,2,5] oxadiazolo[3’,4’:2,3]-5α-androstan-17β-ol)"
},
{
- "value": "Gestrinone"
+ "value": "gestrinone"
},
{
- "value": "Mestanolone"
+ "value": "mestanolone"
},
{
- "value": "Mesterolone"
+ "value": "mesterolone"
},
{
- "value": "Metandienone (17β-hydroxy-17α- methylandrosta-1,4-dien-3-one)"
+ "value": "metandienone",
+ "expanded": "metandienone (17β-hydroxy-17α- methylandrosta-1,4-dien-3-one)"
},
{
- "value": "Metenolone"
+ "value": "metenolone"
},
{
- "value": "Methandriol"
+ "value": "methandriol"
},
{
- "value": "Methasterone (17β-hydroxy-2α,17α- dimethyl-5α-androstan-3-one)"
+ "value": "methasterone",
+ "expanded": "methasterone (17β-hydroxy-2α,17α- dimethyl-5α-androstan-3-one)"
},
{
- "value": "Methyl-1-testosterone (17β-hydroxy-17α- methyl-5α-androst-1-en-3-one)"
+ "value": "methyl-1-testosterone",
+ "expanded": "methyl-1-testosterone (17β-hydroxy-17α- methyl-5α-androst-1-en-3-one)"
},
{
- "value": "Methylclostebol"
+ "value": "methylclostebol"
},
{
- "value": "Methyldienolone (17β-hydroxy-17α- methylestra-4,9-dien-3-one)"
+ "value": "methyldienolone",
+ "expanded": "methyldienolone (17β-hydroxy-17α- methylestra-4,9-dien-3-one)"
},
{
- "value": "Methylnortestosterone (17β-hydroxy-17α- methylestr-4-en-3-one)"
+ "value": "methylnortestosterone",
+ "expanded": "methylnortestosterone (17β-hydroxy-17α- methylestr-4-en-3-one)"
},
{
- "value": "Methyltestosterone"
+ "value": "methyltestosterone"
},
{
- "value": "Metribolone (methyltrienolone, 17β-hydroxy- 17α-methylestra-4,9,11-trien-3-one)"
+ "value": "metribolone",
+ "expanded": "metribolone (methyltrienolone, 17β-hydroxy- 17α-methylestra-4,9,11-trien-3-one)"
},
{
- "value": "Mibolerone"
+ "value": "mibolerone"
},
{
- "value": "Nandrolone (19-nortestosterone)"
+ "value": "nandrolone",
+ "expanded": "nandrolone (19-nortestosterone)"
},
{
- "value": "Norboletone"
+ "value": "norboletone"
},
{
- "value": "Norclostebol (4-chloro-17β-ol-estr-4-en-3- one)"
+ "value": "norclostebol",
+ "expanded": "norclostebol (4-chloro-17β-ol-estr-4-en-3- one)"
},
{
- "value": "Norethandrolone"
+ "value": "norethandrolone"
},
{
- "value": "Oxabolone"
+ "value": "oxabolone"
},
{
- "value": "Oxandrolone"
+ "value": "oxandrolone"
},
{
- "value": "Oxymesterone"
+ "value": "oxymesterone"
},
{
- "value": "Oxymetholone"
+ "value": "oxymetholone"
},
{
- "value": "Prasterone (dehydroepiandrosterone, DHEA, 3β-hydroxyandrost-5-en-17-one)"
+ "value": "prasterone",
+ "expanded": "prasterone (dehydroepiandrosterone, dhea, 3β-hydroxyandrost-5-en-17-one)"
},
{
- "value": "Prostanozol (17β-[(tetrahydropyran-2-yl) oxy]-1’H-pyrazolo[3,4:2,3]-5α-androstane)"
+ "value": "prostanozol",
+ "expanded": "prostanozol (17β-[(tetrahydropyran-2-yl) oxy]-1’h-pyrazolo[3,4:2,3]-5α-androstane)"
},
{
- "value": "Quinbolone"
+ "value": "quinbolone"
},
{
- "value": "Stanozolol"
+ "value": "stanozolol"
},
{
- "value": "Stenbolone"
+ "value": "stenbolone"
},
{
- "value": "Testosterone"
+ "value": "testosterone"
},
{
- "value": "Tetrahydrogestrinone (17-hydroxy-18a- homo-19-nor-17α-pregna-4,9,11-trien-3- one)"
+ "value": "tetrahydrogestrinone",
+ "expanded": "tetrahydrogestrinone (17-hydroxy-18a- homo-19-nor-17α-pregna-4,9,11-trien-3- one)"
},
{
- "value": "Tibolone"
+ "value": "tibolone"
},
{
- "value": "Trenbolone (17β-hydroxyestr-4,9,11-trien-3- one)\n\tand other substances with a similar chemical structure or similar biological effect(s)."
+ "value": "trenbolone",
+ "expanded": "trenbolone (17β-hydroxyestr-4,9,11-trien-3-one) and other substances with a similar chemical structure or similar biological effect(s)."
},
{
- "value": "Clenbuterol"
+ "value": "clenbuterol"
},
{
- "value": "Osilodrostat"
+ "value": "osilodrostat"
},
{
- "value": "Ractopamine"
+ "value": "ractopamine"
},
{
- "value": "Selective androgen receptor modulators [SARMs, e.g. andarine, enobosarm (ostarine), LGD-4033 (ligandrol), RAD140, S-23 and YK-11]"
+ "value": "selective androgen receptor modulators",
+ "expanded": "selective androgen receptor modulators [sarms, e.g. andarine, enobosarm (ostarine), lgd-4033 (ligandrol), rad140, s-23 and yk-11]"
},
{
- "value": "Zeranol"
+ "value": "zeranol"
},
{
- "value": "Zilpaterol"
+ "value": "zilpaterol"
}
]
},
{
- "predicate": "PEPTIDE HORMONES, GROWTH FACTORS, RELATED SUBSTANCES AND MIMETICS",
+ "predicate": "peptide hormones, growth factors, related substances and mimetics",
"entry": [
{
- "value": "Darbepoetins (dEPO)"
+ "value": "darbepoetins",
+ "expanded": "darbepoetins (depo)"
},
{
- "value": "Erythropoietins (EPO)"
+ "value": "erythropoietins",
+ "expanded": "erythropoietins (epo)"
},
{
- "value": "EPO-based constructs [e.g. EPO-Fc, methoxy polyethylene glycol-epoetin beta (CERA)]"
+ "value": "epo-based constructs",
+ "expanded": "epo-based constructs [e.g. epo-fc, methoxy polyethylene glycol-epoetin beta (cera)]"
},
{
- "value": "EPO-mimetic agents and their constructs (e.g. CNTO-530, peginesatide)"
+ "value": "epo-mimetic agents",
+ "expanded": "epo-mimetic agents and their constructs (e.g. cnto-530, peginesatide)"
},
{
- "value": "Cobalt"
+ "value": "cobalt"
},
{
- "value": "Daprodustat (GSK1278863)"
+ "value": "daprodustat",
+ "expanded": "daprodustat (gsk1278863)"
},
{
- "value": "IOX2"
+ "value": "iox2"
},
{
- "value": "Molidustat (BAY 85-3934)"
+ "value": "molidustat",
+ "expanded": "molidustat (bay 85-3934)"
},
{
- "value": "Roxadustat (FG-4592)"
+ "value": "roxadustat",
+ "expanded": "roxadustat (fg-4592)"
},
{
- "value": "Vadadustat (AKB-6548)"
+ "value": "vadadustat",
+ "expanded": "vadadustat (akb-6548)"
},
{
- "value": "Xenon"
+ "value": "xenon"
},
{
- "value": "K-11706"
+ "value": "k-11706"
},
{
- "value": "Luspatercept"
+ "value": "luspatercept"
},
{
- "value": "Sotatercept"
+ "value": "sotatercept"
},
{
- "value": "Asialo EPO"
+ "value": "asialo epo"
},
{
- "value": "Carbamylated EPO (CEPO)"
+ "value": "carbamylated epo",
+ "expanded": "carbamylated epo (cepo)"
},
{
- "value": "Buserelin "
+ "value": "buserelin"
},
{
- "value": "Deslorelin"
+ "value": "deslorelin"
},
{
- "value": "Gonadorelin"
+ "value": "gonadorelin"
},
{
- "value": "Goserelin"
+ "value": "goserelin"
},
{
- "value": "Leuprorelin"
+ "value": "leuprorelin"
},
{
- "value": "Nafarelin"
+ "value": "nafarelin"
},
{
- "value": "Triptorelin"
+ "value": "triptorelin"
},
{
- "value": "Corticorelin"
+ "value": "corticorelin"
},
{
"value": "growth hormone analogues, e.g. lonapegsomatropin, somapacitan and somatrogon"
},
{
- "value": "growth hormone fragments, e.g. AOD-9604 and hGH 176-191"
+ "value": "growth hormone fragments, e.g. aod-9604 and hgh 176-191"
},
{
- "value": "growth hormone-releasing hormone (GHRH) and its analogues (e.g. CJC-1293, CJC-1295, sermorelin and tesamorelin)"
+ "value": "growth hormone-releasing hormone",
+ "expanded": "growth hormone-releasing hormone (ghrh) and its analogues (e.g. cjc-1293, cjc-1295, sermorelin and tesamorelin)"
},
{
- "value": "growth hormone secretagogues (GHS) and their mimetics [e.g. lenomorelin (ghrelin), anamorelin, ipamorelin, macimorelin and tabimorelin]"
+ "value": "growth hormone secretagogues",
+ "expanded": "growth hormone secretagogues (ghs) and their mimetics [e.g. lenomorelin (ghrelin), anamorelin, ipamorelin, macimorelin and tabimorelin]"
},
{
- "value": "GH-releasing peptides (GHRPs) [e.g. alexamorelin, GHRP-1, GHRP-2 (pralmorelin), GHRP-3, GHRP-4, GHRP-5, GHRP-6, and examorelin (hexarelin)]"
+ "value": "gh-releasing peptides",
+ "expanded": "gh-releasing peptides (ghrps) [e.g. alexamorelin, ghrp-1, ghrp-2 (pralmorelin), ghrp-3, ghrp-4, ghrp-5, ghrp-6, and examorelin (hexarelin)]"
},
{
- "value": "Fibroblast growth factors (FGFs)"
+ "value": "fibroblast growth factors",
+ "expanded": "fibroblast growth factors (fgfs)"
},
{
- "value": "Hepatocyte growth factor (HGF)"
+ "value": "hepatocyte growth factor",
+ "expanded": "hepatocyte growth factor (hgf)"
},
{
- "value": "Insulin-like growth factor 1 (IGF-1) and its analogues"
+ "value": "insulin-like growth factor 1",
+ "expanded": "insulin-like growth factor 1 (igf-1) and its analogues"
},
{
- "value": "Mechano growth factors (MGFs)"
+ "value": "mechano growth factors",
+ "expanded": "mechano growth factors (mgfs)"
},
{
- "value": "Platelet-derived growth factor (PDGF)"
+ "value": "platelet-derived growth factor",
+ "expanded": "platelet-derived growth factor (pdgf)"
},
{
- "value": "Thymosin-β4 and its derivatives e.g. TB-500"
+ "value": "thymosin-β4 and its derivatives e.g. tb-500"
},
{
- "value": "Vascular endothelial growth factor (VEGF)\n\tand other growth factors or growth factor modulators affecting muscle, tendon or ligament protein synthesis/degradation, vascularisation, energy utilization, regenerative capacity or fibre type switching."
+ "value": "vascular endothelial growth factor",
+ "expanded": "vascular endothelial growth factor (vegf) and other growth factors or growth factor modulators affecting muscle, tendon or ligament protein synthesis/degradation, vascularisation, energy utilization, regenerative capacity or fibre type switching."
}
]
},
{
- "predicate": "BETA-2 AGONISTS",
+ "predicate": "beta-2 agonists",
"entry": [
{
- "value": "Arformoterol"
+ "value": "arformoterol"
},
{
- "value": "Fenoterol"
+ "value": "fenoterol"
},
{
- "value": "Formoterol"
+ "value": "formoterol"
},
{
- "value": "Higenamine"
+ "value": "higenamine"
},
{
- "value": "Indacaterol"
+ "value": "indacaterol"
},
{
- "value": "Levosalbutamol"
+ "value": "levosalbutamol"
},
{
- "value": "Olodaterol"
+ "value": "olodaterol"
},
{
- "value": "Procaterol"
+ "value": "procaterol"
},
{
- "value": "Reproterol"
+ "value": "reproterol"
},
{
- "value": "Salbutamol"
+ "value": "salbutamol"
},
{
- "value": "Salmeterol"
+ "value": "salmeterol"
},
{
- "value": "Terbutaline"
+ "value": "terbutaline"
},
{
- "value": "Tretoquinol (trimetoquinol)"
+ "value": "tretoquinol",
+ "expanded": "tretoquinol (trimetoquinol)"
},
{
- "value": "Tulobuterol"
+ "value": "tulobuterol"
},
{
- "value": "Vilanterol"
+ "value": "vilanterol"
},
{
- "value": "Inhaled salbutamol: maximum 1600 micrograms over 24 hours in divided doses not to exceed 600 micrograms over 8 hours starting from any dose"
+ "value": "salbutamol",
+ "expanded": "inhaled salbutamol: maximum 1600 micrograms over 24 hours in divided doses not to exceed 600 micrograms over 8 hours starting from any dose"
},
{
- "value": "Inhaled formoterol: maximum delivered dose of 54 micrograms over 24 hours"
+ "value": "formoterol",
+ "expanded": "inhaled formoterol: maximum delivered dose of 54 micrograms over 24 hours"
},
{
- "value": "Inhaled salmeterol: maximum 200 micrograms over 24 hours"
+ "value": "salmeterol",
+ "expanded": "inhaled salmeterol: maximum 200 micrograms over 24 hours"
},
{
- "value": "Inhaled vilanterol: maximum 25 micrograms over 24 hours"
+ "value": "vilanterol",
+ "expanded": "inhaled vilanterol: maximum 25 micrograms over 24 hours"
}
]
},
{
- "predicate": "HORMONE AND METABOLIC MODULATORS",
+ "predicate": "hormone and metabolic modulators",
"entry": [
{
- "value": "2-Androstenol (5α-androst-2-en-17-ol)"
+ "value": "2-androstenol",
+ "expanded": "2-androstenol (5α-androst-2-en-17-ol)"
},
{
- "value": "2-Androstenone (5α-androst-2-en-17-one)"
+ "value": "2-androstenone",
+ "expanded": "2-androstenone (5α-androst-2-en-17-one)"
},
{
- "value": "3-Androstenol (5α-androst-3-en-17-ol)"
+ "value": "3-androstenol",
+ "expanded": "3-androstenol (5α-androst-3-en-17-ol)"
},
{
- "value": "3-Androstenone (5α-androst-3-en-17-one)"
+ "value": "3-androstenone",
+ "expanded": "3-androstenone (5α-androst-3-en-17-one)"
},
{
- "value": "4-Androstene-3,6,17 trione (6-oxo)"
+ "value": "4-androstene-3,6,17 trione",
+ "expanded": "4-androstene-3,6,17 trione (6-oxo)"
},
{
- "value": "Aminoglutethimide"
+ "value": "aminoglutethimide"
},
{
- "value": "Anastrozole"
+ "value": "anastrozole"
},
{
- "value": "Androsta-1,4,6-triene-3,17-dione (androstatrienedione)"
+ "value": "androsta-1,4,6-triene-3,17-dione",
+ "expanded": "androsta-1,4,6-triene-3,17-dione (androstatrienedione)"
},
{
- "value": "Androsta-3,5-diene-7,17-dione (arimistane)"
+ "value": "androsta-3,5-diene-7,17-dione",
+ "expanded": "androsta-3,5-diene-7,17-dione (arimistane)"
},
{
- "value": "Exemestane"
+ "value": "exemestane"
},
{
- "value": "Formestane"
+ "value": "formestane"
},
{
- "value": "Letrozole"
+ "value": "letrozole"
},
{
- "value": "Testolactone"
+ "value": "testolactone"
},
{
- "value": "Bazedoxifene"
+ "value": "bazedoxifene"
},
{
- "value": "Clomifene"
+ "value": "clomifene"
},
{
- "value": "Cyclofenil"
+ "value": "cyclofenil"
},
{
- "value": "Fulvestrant"
+ "value": "fulvestrant"
},
{
- "value": "Ospemifene"
+ "value": "ospemifene"
},
{
- "value": "Raloxifene"
+ "value": "raloxifene"
},
{
- "value": "Tamoxifen"
+ "value": "tamoxifen"
},
{
- "value": "Toremifene"
+ "value": "toremifene"
},
{
- "value": "Activin A-neutralizing antibodies"
+ "value": "activin a-neutralizing antibodies"
},
{
- "value": "Activin receptor IIB competitors such as: \nDecoy activin receptors (e.g. ACE-031)\n"
+ "value": "activin receptor iib competitors",
+ "expanded": "activin receptor iib competitors such as: decoy activin receptors (e.g. ace-031)"
},
{
- "value": "Decoy activin receptors (e.g. ACE-031)"
+ "value": "decoy activin receptors",
+ "expanded": "decoy activin receptors (e.g. ace-031)"
},
{
- "value": "Anti-activin receptor IIB antibodies (e.g. bimagrumab)"
+ "value": "anti-activin receptor iib antibodies",
+ "expanded": "anti-activin receptor iib antibodies (e.g. bimagrumab)"
},
{
- "value": "Myostatin inhibitors such as:\nAgents reducing or ablating myostatin expression\nMyostatin-binding proteins (e.g. follistatin, myostatin propeptide)\nMyostatin- or precursor - neutralizing antibodies (e.g. apitegromab, domagrozumab, landogrozumab, stamulumab)\n"
+ "value": "myostatin inhibitors",
+ "expanded": "myostatin inhibitors such as: agents reducing or ablating myostatin expression myostatin-binding proteins (e.g. follistatin, myostatin propeptide) myostatin- or precursor - neutralizing antibodies (e.g. apitegromab, domagrozumab, landogrozumab, stamulumab)"
},
{
- "value": "Agents reducing or ablating myostatin expression"
+ "value": "agents reducing or ablating myostatin expression"
},
{
- "value": "Myostatin-binding proteins (e.g. follistatin, myostatin propeptide)"
+ "value": "myostatin-binding proteins",
+ "expanded": "myostatin-binding proteins (e.g. follistatin, myostatin propeptide)"
},
{
- "value": "Myostatin- or precursor - neutralizing antibodies (e.g. apitegromab, domagrozumab, landogrozumab, stamulumab)"
+ "value": "myostatini - or precursor - neutralizing antibodies",
+ "expanded": "myostatin - or precursor - neutralizing antibodies (e.g. apitegromab, domagrozumab, landogrozumab, stamulumab)"
}
]
},
{
- "predicate": "DIURETICS AND MASKING AGENTS",
+ "predicate": "diuretics and masking agents",
"entry": [
{
- "value": "Desmopressin; probenecid; plasma expanders, e.g. intravenous administration of albumin, dextran, hydroxyethyl starch and mannitol."
+ "value": "desmopressin"
},
{
- "value": "Acetazolamide; amiloride; bumetanide; canrenone; chlortalidone; etacrynic acid; furosemide; indapamide; metolazone; spironolactone; thiazides, e.g. bendroflumethiazide, chlorothiazide and hydrochlorothiazide; torasemide; triamterene and vaptans, e.g. tolvaptan."
+ "value": "probenecid"
},
{
- "value": "Drospirenone; pamabrom; and topical ophthalmic administration of carbonic anhydrase inhibitors (e.g. dorzolamide, brinzolamide)"
+ "value": "plasma expanders",
+ "expanded": "plasma expanders, e.g. intravenous administration of albumin, dextran, hydroxyethyl starch and mannitol."
},
{
- "value": "Local administration of felypressin in dental anaesthesia"
- }
- ]
- },
- {
- "predicate": "STIMULANTS",
- "entry": [
+ "value": "acetazolamide"
+ },
{
- "value": "Adrafinil"
+ "value": "amiloride"
},
{
- "value": "Amfepramone"
+ "value": "bumetanide"
},
{
- "value": "Amfetamine"
+ "value": "canrenone"
},
{
- "value": "Amfetaminil"
+ "value": "chlortalidone"
},
{
- "value": "Amiphenazole"
+ "value": "etacrynic acid"
},
{
- "value": "Benfluorex"
+ "value": "furosemide"
},
{
- "value": "Benzylpiperazine"
+ "value": "indapamide"
},
{
- "value": "Bromantan"
+ "value": "metolazone"
},
{
- "value": "Clobenzorex"
+ "value": "spironolactone"
},
{
- "value": "Cocaine"
+ "value": "thiazides",
+ "expanded": "thiazides, e.g. bendroflumethiazide, chlorothiazide and hydrochlorothiazide"
},
{
- "value": "Cropropamide"
+ "value": "torasemide"
},
{
- "value": "Crotetamide"
+ "value": "triamterene"
},
{
- "value": "Fencamine"
+ "value": "vaptans"
},
{
- "value": "Fenetylline"
+ "value": "vaptans, e.g. tolvaptan."
},
{
- "value": "Fenfluramine"
+ "value": "drospirenone"
},
{
- "value": "Fenproporex"
+ "value": "pamabrom"
},
{
- "value": "Fonturacetam [4-phenylpiracetam (carphedon)]"
+ "value": "carbonic anhydrase inhibitors",
+ "expanded": "topical ophthalmic administration of carbonic anhydrase inhibitors (e.g. dorzolamide, brinzolamide)"
},
{
- "value": "Furfenorex"
+ "value": "felypressin",
+ "expanded": "local administration of felypressin in dental anaesthesia"
+ }
+ ]
+ },
+ {
+ "predicate": "stimulants",
+ "entry": [
+ {
+ "value": "adrafinil"
},
{
- "value": "Lisdexamfetamine"
+ "value": "amfepramone"
},
{
- "value": "Mefenorex"
+ "value": "amfetamine"
},
{
- "value": "Mephentermine"
+ "value": "amfetaminil"
},
{
- "value": "Mesocarb"
+ "value": "amiphenazole"
},
{
- "value": "Metamfetamine(d-)"
+ "value": "benfluorex"
},
{
- "value": "p-methylamfetamine"
+ "value": "benzylpiperazine"
},
{
- "value": "Modafinil"
+ "value": "bromantan"
},
{
- "value": "Norfenfluramine"
+ "value": "clobenzorex"
},
{
- "value": "Phendimetrazine"
+ "value": "cocaine"
},
{
- "value": "Phentermine"
+ "value": "cropropamide"
},
{
- "value": "Prenylamine"
+ "value": "crotetamide"
},
{
- "value": "Prolintane"
+ "value": "fencamine"
},
{
- "value": "3-Methylhexan-2-amine (1,2-dimethylpentylamine)"
+ "value": "fenetylline"
},
{
- "value": "4-fluoromethylphenidate"
+ "value": "fenfluramine"
},
{
- "value": "4-Methylhexan-2-amine (methylhexaneamine, 1,3-dimethylamylamine, 1,3 DMAA)"
+ "value": "fenproporex"
},
{
- "value": "4-Methylpentan-2-amine (1,3-dimethylbutylamine)"
+ "value": "fonturacetam",
+ "expanded": "fonturacetam [4-phenylpiracetam (carphedon)]"
},
{
- "value": "5-Methylhexan-2-amine (1,4-dimethylpentylamine, 1,4-dimethylamylamine, 1,4-DMAA)"
+ "value": "furfenorex"
},
{
- "value": "Benzfetamine"
+ "value": "lisdexamfetamine"
},
{
- "value": "Cathine**"
+ "value": "mefenorex"
},
{
- "value": "Cathinone and its analogues, e.g. mephedrone, methedrone, and α - pyrrolidinovalerophenone"
+ "value": "mephentermine"
},
{
- "value": "Dimetamfetamine (dimethylamphetamine)"
+ "value": "mesocarb"
},
{
- "value": "Ephedrine***"
+ "value": "metamfetamine",
+ "expanded": "metamfetamine(d-)"
},
{
- "value": "Epinephrine**** (adrenaline)"
+ "value": "p-methylamfetamine"
},
{
- "value": "Etamivan"
+ "value": "modafinil"
},
{
- "value": "Ethylphenidate"
+ "value": "norfenfluramine"
},
{
- "value": "Etilamfetamine"
+ "value": "phendimetrazine"
},
{
- "value": "Etilefrine"
+ "value": "phentermine"
},
{
- "value": "Famprofazone"
+ "value": "prenylamine"
},
{
- "value": "Fenbutrazate"
+ "value": "prolintane"
},
{
- "value": "Fencamfamin"
+ "value": "3-methylhexan-2-amine",
+ "expanded": "3-methylhexan-2-amine (1,2-dimethylpentylamine)"
},
{
- "value": "Heptaminol"
+ "value": "4-fluoromethylphenidate"
},
{
- "value": "Hydrafinil (fluorenol)"
+ "value": "4-methylhexan-2-amine",
+ "expanded": "4-methylhexan-2-amine (methylhexaneamine, 1,3-dimethylamylamine, 1,3 dmaa)"
},
{
- "value": "Hydroxyamfetamine (parahydroxyamphetamine)"
+ "value": "4-methylpentan-2-amine",
+ "expanded": "4-methylpentan-2-amine (1,3-dimethylbutylamine)"
},
{
- "value": "Isometheptene"
+ "value": "5-methylhexan-2-amine",
+ "expanded": "5-methylhexan-2-amine (1,4-dimethylpentylamine, 1,4-dimethylamylamine, 1,4-dmaa)"
},
{
- "value": "Levmetamfetamine"
+ "value": "benzfetamine"
},
{
- "value": "Meclofenoxate"
+ "value": "cathine**"
},
{
- "value": "Methylenedioxymetham- phetamine"
+ "value": "cathinone and its analogues",
+ "expanded": "cathinone and its analogues, e.g. mephedrone, methedrone, and α - pyrrolidinovalerophenone"
},
{
- "value": "Methylephedrine***"
+ "value": "dimetamfetamine",
+ "expanded": "dimetamfetamine (dimethylamphetamine)"
},
{
- "value": "Methylnaphthidate [((±)-methyl-2-(naphthalen-2-yl)-2-(piperidin-2-yl)acetate]"
+ "value": "ephedrine***"
},
{
- "value": "Methylphenidate"
+ "value": "epinephrine****",
+ "expanded": "epinephrine**** (adrenaline)"
},
{
- "value": "Nikethamide"
+ "value": "etamivan"
},
{
- "value": "Norfenefrine"
+ "value": "ethylphenidate"
},
{
- "value": "Octodrine (1,5-dimethylhex- ylamine)"
+ "value": "etilamfetamine"
},
{
- "value": "Octopamine"
+ "value": "etilefrine"
},
{
- "value": "Oxilofrine (methylsynephrine)"
+ "value": "famprofazone"
},
{
- "value": "Pemoline"
+ "value": "fenbutrazate"
},
{
- "value": "Pentetrazol"
+ "value": "fencamfamin"
},
{
- "value": "Phenethylamine and its derivatives"
+ "value": "heptaminol"
},
{
- "value": "Phenmetrazine"
+ "value": "hydrafinil",
+ "expanded": "hydrafinil (fluorenol)"
},
{
- "value": "Phenpromethamine"
+ "value": "hydroxyamfetamine",
+ "expanded": "hydroxyamfetamine (parahydroxyamphetamine)"
},
{
- "value": "Propylhexedrine"
+ "value": "isometheptene"
},
{
- "value": "Pseudoephedrine*****"
+ "value": "levmetamfetamine"
},
{
- "value": "Selegiline"
+ "value": "meclofenoxate"
},
{
- "value": "Sibutramine"
+ "value": "methylenedioxymetham- phetamine"
},
{
- "value": "Solriamfetol"
+ "value": "methylephedrine***"
},
{
- "value": "Strychnine"
+ "value": "methylnaphthidate",
+ "expanded": "methylnaphthidate [((±)-methyl-2-(naphthalen-2-yl)-2-(piperidin-2-yl)acetate]"
},
{
- "value": "Tenamfetamine (methylenedioxyamphet- amine)"
+ "value": "methylphenidate"
},
{
- "value": "Tuaminoheptane"
+ "value": "nikethamide"
},
{
- "value": "Clonidine"
+ "value": "norfenefrine"
},
{
- "value": "Imidazole derivatives for dermatological, nasal, ophthalmic or otic use (e.g. brimonidine, clonazoline, fenoxazoline, indanazoline, naphazoline, oxymetazoline, tetryzoline, xylometazoline) and those stimulants included in the 2023 Monitoring Program*"
- }
- ]
- },
- {
- "predicate": "NARCOTICS",
- "entry": [
+ "value": "octodrine",
+ "expanded": "octodrine (1,5-dimethylhex- ylamine)"
+ },
{
- "value": "Buprenorphine"
+ "value": "octopamine"
},
{
- "value": "Dextromoramide"
+ "value": "oxilofrine",
+ "expanded": "oxilofrine (methylsynephrine)"
},
{
- "value": "Diamorphine (heroin)"
+ "value": "pemoline"
},
{
- "value": "Fentanyl and its derivatives"
+ "value": "pentetrazol"
},
{
- "value": "Hydromorphone"
+ "value": "phenethylamine and its derivatives"
},
{
- "value": "Methadone"
+ "value": "phenmetrazine"
},
{
- "value": "Morphine"
+ "value": "phenpromethamine"
},
{
- "value": "Nicomorphine"
+ "value": "propylhexedrine"
},
{
- "value": "Oxycodone"
+ "value": "pseudoephedrine*****"
},
{
- "value": "Oxymorphone"
+ "value": "selegiline"
},
{
- "value": "Pentazocine"
+ "value": "sibutramine"
},
{
- "value": "Pethidine"
- }
- ]
- },
- {
- "predicate": "CANNABINOIDS",
- "entry": [
+ "value": "solriamfetol"
+ },
+ {
+ "value": "strychnine"
+ },
{
- "value": "In cannabis (hashish, marijuana) and cannabis products"
+ "value": "tenamfetamine",
+ "expanded": "tenamfetamine (methylenedioxyamphet- amine)"
},
{
- "value": "Synthetic cannabinoids that mimic the effects of THC"
+ "value": "tuaminoheptane"
},
{
- "value": "Natural and synthetic tetrahydrocannabinols (THCs)"
+ "value": "clonidine"
},
{
- "value": "Cannabidiol"
+ "value": "imidazole derivatives",
+ "expanded": "imidazole derivatives for dermatological, nasal, ophthalmic or otic use (e.g. brimonidine, clonazoline, fenoxazoline, indanazoline, naphazoline, oxymetazoline, tetryzoline, xylometazoline) and those stimulants included in the 2023 monitoring program*"
}
]
},
{
- "predicate": "GLUCOCORTICOIDS",
+ "predicate": "narcotics",
"entry": [
{
- "value": "Beclometasone"
+ "value": "buprenorphine"
},
{
- "value": "Betamethasone"
+ "value": "dextromoramide"
},
{
- "value": "Budesonide"
+ "value": "diamorphine",
+ "expanded": "diamorphine (heroin)"
},
{
- "value": "Ciclesonide"
+ "value": "fentanyl",
+ "expanded": "fentanyl and its derivatives"
},
{
- "value": "Cortisone"
+ "value": "hydromorphone"
},
{
- "value": "Deflazacort"
+ "value": "methadone"
},
{
- "value": "Dexamethasone"
+ "value": "morphine"
},
{
- "value": "Flucortolone"
+ "value": "nicomorphine"
},
{
- "value": "Flunisolide"
+ "value": "oxycodone"
},
{
- "value": "Fluticasone"
+ "value": "oxymorphone"
},
{
- "value": "Hydrocortisone"
+ "value": "pentazocine"
},
{
- "value": "Methylprednisolone"
- },
+ "value": "pethidine"
+ }
+ ]
+ },
+ {
+ "predicate": "cannabinoids",
+ "entry": [
{
- "value": "Mometasone"
+ "value": "in cannabis",
+ "expanded": "in cannabis (hashish, marijuana) and cannabis products"
},
{
- "value": "Prednisolone"
+ "value": "synthetic cannabinoids that mimic the effects of thc"
},
{
- "value": "Prednisone"
+ "value": "natural and synthetic tetrahydrocannabinols",
+ "expanded": "natural and synthetic tetrahydrocannabinols (thcs)"
},
{
- "value": "Triamcinolone acetonide"
+ "value": "cannabidiol"
}
]
},
{
- "predicate": "BETA-BLOCKERS",
+ "predicate": "glucocorticoids",
"entry": [
{
- "value": "Archery (WA)*"
+ "value": "beclometasone"
+ },
+ {
+ "value": "betamethasone"
},
{
- "value": "Automobile (FIA)"
+ "value": "budesonide"
},
{
- "value": "Billiards (all disciplines) (WCBS)"
+ "value": "ciclesonide"
},
{
- "value": "Darts (WDF)"
+ "value": "cortisone"
},
{
- "value": "Golf (IGF)"
+ "value": "deflazacort"
},
{
- "value": "Mini-Golf (WMF)"
+ "value": "dexamethasone"
},
{
- "value": "Shooting (ISSF, IPC)*"
+ "value": "flucortolone"
},
{
- "value": "Skiing/Snowboarding (FIS) in ski jumping, freestyle aerials/halfpipe and snowboard halfpipe/big air"
+ "value": "flunisolide"
},
{
- "value": "Underwater sports (CMAS)* in all subdisciplines of freediving, spearfishing and target shooting"
+ "value": "fluticasone"
},
{
- "value": "Acebutolol"
+ "value": "hydrocortisone"
+ },
+ {
+ "value": "methylprednisolone"
+ },
+ {
+ "value": "mometasone"
+ },
+ {
+ "value": "prednisolone"
+ },
+ {
+ "value": "prednisone"
+ },
+ {
+ "value": "triamcinolone acetonide"
+ }
+ ]
+ },
+ {
+ "predicate": "beta-blockers",
+ "entry": [
+ {
+ "value": "acebutolol"
},
{
- "value": "Alprenolol"
+ "value": "alprenolol"
},
{
- "value": "Atenolol"
+ "value": "atenolol"
},
{
- "value": "Betaxolol"
+ "value": "betaxolol"
},
{
- "value": "Bisoprolol"
+ "value": "bisoprolol"
},
{
- "value": "Bunolol"
+ "value": "bunolol"
},
{
- "value": "Carteolol"
+ "value": "carteolol"
},
{
- "value": "Carvedilol"
+ "value": "carvedilol"
},
{
- "value": "Celiprolol"
+ "value": "celiprolol"
},
{
- "value": "Esmolol"
+ "value": "esmolol"
},
{
- "value": "Labetalol"
+ "value": "labetalol"
},
{
- "value": "Metipranolol"
+ "value": "metipranolol"
},
{
- "value": "Metoprolol"
+ "value": "metoprolol"
},
{
- "value": "Nadolol"
+ "value": "nadolol"
},
{
- "value": "Nebivolol"
+ "value": "nebivolol"
},
{
- "value": "Oxprenolol"
+ "value": "oxprenolol"
},
{
- "value": "Pindolol"
+ "value": "pindolol"
},
{
- "value": "Propranolol"
+ "value": "propranolol"
},
{
- "value": "Sotalol"
+ "value": "sotalol"
},
{
- "value": "Timolol"
+ "value": "timolol"
}
]
}
]
-}
\ No newline at end of file
+}
From 65e8a70bb9e8e7cdf551da8db59676dad699af1a Mon Sep 17 00:00:00 2001
From: Christian Studer
Date: Wed, 18 Oct 2023 17:03:46 +0200
Subject: [PATCH 165/181] chg: Updated manifest with the new taxonomy
description
---
MANIFEST.json | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/MANIFEST.json b/MANIFEST.json
index c9dc7ce..17969bc 100644
--- a/MANIFEST.json
+++ b/MANIFEST.json
@@ -742,6 +742,11 @@
"description": "Workflow support language is a common language to support intelligence analysts to perform their analysis on data and information.",
"name": "workflow",
"version": 11
+ },
+ {
+ "description": "This taxonomy aims to list doping substances",
+ "name": "doping-substances",
+ "version": 2
}
],
"url": "https://raw.githubusercontent.com/MISP/misp-taxonomies/main/",
From e8892b6cf91551d93acf94ce52a36a7112e756cc Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Thu, 19 Oct 2023 09:51:45 +0200
Subject: [PATCH 166/181] chg: [adoc] exclude `doping-substances` from adoc
generation
---
tools/machinetag.py | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/machinetag.py b/tools/machinetag.py
index d26252f..66ed96c 100755
--- a/tools/machinetag.py
+++ b/tools/machinetag.py
@@ -32,7 +32,7 @@
import os
import sys
-skip_list = ['death-possibilities', 'poison-taxonomy']
+skip_list = ['death-possibilities', 'poison-taxonomy', 'doping-substances']
taxonomies = []
# Get our current directory from file location
From 9f481f4aee1932c4365b61cdee31f5419147edd4 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 15 Nov 2023 14:09:51 +0100
Subject: [PATCH 167/181] new: [srbcert] New taxonomy for the SRB-CERT
---
MANIFEST.json | 31 ++++---
srbcert/machinetag.json | 191 ++++++++++++++++++++++++++++++++++++++++
2 files changed, 209 insertions(+), 13 deletions(-)
create mode 100644 srbcert/machinetag.json
diff --git a/MANIFEST.json b/MANIFEST.json
index 17969bc..35dd6c7 100644
--- a/MANIFEST.json
+++ b/MANIFEST.json
@@ -89,9 +89,9 @@
"version": 2
},
{
- "description": "CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection",
+ "description": "CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection.",
"name": "circl",
- "version": 5
+ "version": 6
},
{
"description": "La presente taxonomia es la primera versión disponible para el Centro Nacional de Seguridad Digital del Perú.",
@@ -124,7 +124,7 @@
"version": 2
},
{
- "description": "The Crowdsec behaviors and classifications taxonomy is the list of taxonomies used in Crowdsec to describe the behaviors and classifications of an IP address. The behaviors are a list of attack categories for which a given IP address was reported, where the classifications describe a list of categories associated to an IP address and, when applicable, a list of false positive categories.",
+ "description": "Crowdsec IP address classifications and behaviors taxonomy.",
"name": "crowdsec",
"version": 1
},
@@ -238,6 +238,11 @@
"name": "domain-abuse",
"version": 2
},
+ {
+ "description": "This taxonomy aims to list doping substances",
+ "name": "doping-substances",
+ "version": 2
+ },
{
"description": "A taxonomy based on the superclass and class of drugs. Based on https://www.drugbank.ca/releases/latest",
"name": "drugs",
@@ -511,7 +516,7 @@
{
"description": "MISP workflow taxonomy to support result of workflow execution.",
"name": "misp-workflow",
- "version": 2
+ "version": 3
},
{
"description": "MONARC Threats Taxonomy",
@@ -626,7 +631,7 @@
{
"description": "Runtime or software packer used to combine compressed or encrypted data with the decompression or decryption code. This code can add additional obfuscations mechanisms including polymorphic-packer or other obfuscation techniques. This taxonomy lists all the known or official packer used for legitimate use or for packing malicious binaries.",
"name": "runtime-packer",
- "version": 1
+ "version": 2
},
{
"description": "Flags describing the sample",
@@ -658,6 +663,11 @@
"name": "social-engineering-attack-vectors",
"version": 1
},
+ {
+ "description": "SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection",
+ "name": "srbcert",
+ "version": 1
+ },
{
"description": "A spectrum of state responsibility to more directly tie the goals of attribution to the needs of policymakers.",
"name": "state-responsibility",
@@ -696,7 +706,7 @@
{
"description": "The Traffic Light Protocol (TLP) (v2.0) was created to facilitate greater sharing of potentially sensitive information and more effective collaboration. Information sharing happens from an information source, towards one or more recipients. TLP is a set of four standard labels (a fifth label is included in amber to limit the diffusion) used to indicate the sharing boundaries to be applied by the recipients. Only labels listed in this standard are considered valid by FIRST. This taxonomy includes additional labels for backward compatibility which are no more validated by FIRST SIG.",
"name": "tlp",
- "version": 7
+ "version": 9
},
{
"description": "Taxonomy to describe Tor network infrastructure",
@@ -741,14 +751,9 @@
{
"description": "Workflow support language is a common language to support intelligence analysts to perform their analysis on data and information.",
"name": "workflow",
- "version": 11
- },
- {
- "description": "This taxonomy aims to list doping substances",
- "name": "doping-substances",
- "version": 2
+ "version": 12
}
],
"url": "https://raw.githubusercontent.com/MISP/misp-taxonomies/main/",
- "version": "20230514"
+ "version": "20231115"
}
diff --git a/srbcert/machinetag.json b/srbcert/machinetag.json
new file mode 100644
index 0000000..a9904f8
--- /dev/null
+++ b/srbcert/machinetag.json
@@ -0,0 +1,191 @@
+{
+ "namespace": "srbcert",
+ "description": "SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection",
+ "version": 1,
+ "predicates": [
+ {
+ "value": "incident-type",
+ "expanded": "Incident Type"
+ },
+ {
+ "value": "incident-criticality-level",
+ "expanded": "Incident Criticality Level"
+ }
+ ],
+ "values": [
+ {
+ "predicate": "incident-type",
+ "entry": [
+ {
+ "value": "virus",
+ "expanded": "Virus"
+ },
+ {
+ "value": "worm",
+ "expanded": "Worm"
+ },
+ {
+ "value": "ransomware",
+ "expanded": "Ransomware"
+ },
+ {
+ "value": "trojan",
+ "expanded": "Trojan"
+ },
+ {
+ "value": "spyware",
+ "expanded": "Spyware"
+ },
+ {
+ "value": "rootkit",
+ "expanded": "Rootkit"
+ },
+ {
+ "value": "malware",
+ "expanded": "Malware"
+ },
+ {
+ "value": "port-scanning",
+ "expanded": "Port scanning"
+ },
+ {
+ "value": "sniffing",
+ "expanded": "Sniffing"
+ },
+ {
+ "value": "social-engineering",
+ "expanded": "Social engineering"
+ },
+ {
+ "value": "data-breaches",
+ "expanded": "Data breaches"
+ },
+ {
+ "value": "other-type-of-information-gathering",
+ "expanded": "Other type of information gathering"
+ },
+ {
+ "value": "phishing",
+ "expanded": "Phishing"
+ },
+ {
+ "value": "unauthorized-use-of-resources",
+ "expanded": "Unauthorized use of resources"
+ },
+ {
+ "value": "fraud",
+ "expanded": "Fraud"
+ },
+ {
+ "value": "exploiting-known-vulnerabilities",
+ "expanded": "Exploiting known vulnerabilities"
+ },
+ {
+ "value": "brute-force",
+ "expanded": "Brute force"
+ },
+ {
+ "value": "other-type-of-intrusion-attempts",
+ "expanded": "Other type of Intrusion Attempts"
+ },
+ {
+ "value": "privilege-account-compromise",
+ "expanded": "Privilege account compromise"
+ },
+ {
+ "value": "unprivileged-account-compromise",
+ "expanded": "Unprivileged account compromise"
+ },
+ {
+ "value": "application-compromise",
+ "expanded": "Application compromise"
+ },
+ {
+ "value": "botnet",
+ "expanded": "Botnet"
+ },
+ {
+ "value": "other-type-of-intrusions",
+ "expanded": "Other type of intrusions"
+ },
+ {
+ "value": "dos",
+ "expanded": "DoS"
+ },
+ {
+ "value": "ddos",
+ "expanded": "DDoS"
+ },
+ {
+ "value": "sabotage",
+ "expanded": "Sabotage"
+ },
+ {
+ "value": "outage",
+ "expanded": "Outage"
+ },
+ {
+ "value": "other-type-of-availability-incident",
+ "expanded": "Other type of Availability incident"
+ },
+ {
+ "value": "unauthorized-access-to-information",
+ "expanded": "Unauthorized access to information"
+ },
+ {
+ "value": "unauthorized-modification-of-information",
+ "expanded": "Unauthorized modification of information"
+ },
+ {
+ "value": "cryptographic-attack",
+ "expanded": "Cryptographic attack"
+ },
+ {
+ "value": "other-type-of-information-content-security-incident",
+ "expanded": "Other type of Information Content Security incident"
+ },
+ {
+ "value": "hardware-errors",
+ "expanded": "Hardware errors"
+ },
+ {
+ "value": "software-errors",
+ "expanded": "Software errors"
+ },
+ {
+ "value": "software-errors",
+ "expanded": "Software errors"
+ },
+ {
+ "value": "hardware-components-theft",
+ "expanded": "hardware-components-theft"
+ },
+ {
+ "value": "other",
+ "expanded": "Other"
+ }
+ ]
+ },
+ {
+ "predicate": "incident-criticality-level",
+ "entry": [
+ {
+ "value": "low",
+ "expanded": "Low"
+ },
+ {
+ "value": "medium",
+ "expanded": "Medium"
+ },
+ {
+ "value": "high",
+ "expanded": "High"
+ },
+ {
+ "value": "very-high",
+ "expanded": "Very High"
+ }
+ ]
+ }
+ ]
+}
From d4b54e3f63c9181d70474cc4b34da801104472e6 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 15 Nov 2023 14:30:05 +0100
Subject: [PATCH 168/181] fix: [srbcert] various fixes
- Duplicates removed
- Numerical value added
---
srbcert/machinetag.json | 26 ++++++++++++++------------
1 file changed, 14 insertions(+), 12 deletions(-)
diff --git a/srbcert/machinetag.json b/srbcert/machinetag.json
index a9904f8..f0ccbb1 100644
--- a/srbcert/machinetag.json
+++ b/srbcert/machinetag.json
@@ -1,7 +1,7 @@
{
"namespace": "srbcert",
"description": "SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection",
- "version": 1,
+ "version": 3,
"predicates": [
{
"value": "incident-type",
@@ -18,11 +18,13 @@
"entry": [
{
"value": "virus",
- "expanded": "Virus"
+ "expanded": "virus",
+ "description": "Virus is a piece of malicious code that aims to spread from computer to computer by attacking executable files and documents and can cause deliberate deletion of files from the hard drive and similar damage"
},
{
"value": "worm",
- "expanded": "Worm"
+ "expanded": "worm",
+ "description": "Worm is a program that contains malicious code that spreads over a network, in such a way that it can reproduce and transfer , which reproduces and transfers independently, i.e. it does not depend on the files of the infected person device. Worms spread to email addresses from the victim's contact list or exploit the vulnerabilities of network applications and, due to the high speed of propagation, serve for transmission of other types of malicious software "
},
{
"value": "ransomware",
@@ -42,7 +44,7 @@
},
{
"value": "malware",
- "expanded": "Malware"
+ "expanded": "Malware is a word derived from two words - Malicious Software, and represents any software that is written for malicious purposes, i.e. that aims to cause harm computer systems or networks"
},
{
"value": "port-scanning",
@@ -152,10 +154,6 @@
"value": "software-errors",
"expanded": "Software errors"
},
- {
- "value": "software-errors",
- "expanded": "Software errors"
- },
{
"value": "hardware-components-theft",
"expanded": "hardware-components-theft"
@@ -171,19 +169,23 @@
"entry": [
{
"value": "low",
- "expanded": "Low"
+ "expanded": "Low",
+ "numerical_value": 25
},
{
"value": "medium",
- "expanded": "Medium"
+ "expanded": "Medium",
+ "numerical_value": 50
},
{
"value": "high",
- "expanded": "High"
+ "expanded": "High",
+ "numerical_value": 75
},
{
"value": "very-high",
- "expanded": "Very High"
+ "expanded": "Very High",
+ "numerical_value": 100
}
]
}
From 873fc6209fd247920635824c755023ab6787ae62 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 22 Nov 2023 11:28:15 +0100
Subject: [PATCH 169/181] fix: [PAP] following pull-request from @vba-anssi
#261
PAP aligned with TLP version 2
---
PAP/machinetag.json | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/PAP/machinetag.json b/PAP/machinetag.json
index c6be37e..8bf3381 100644
--- a/PAP/machinetag.json
+++ b/PAP/machinetag.json
@@ -2,23 +2,28 @@
"namespace": "PAP",
"expanded": "Permissible Actions Protocol",
"description": "The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used.",
- "version": 2,
+ "version": 3,
"exclusive": true,
"predicates": [
{
"value": "RED",
"expanded": "(PAP:RED) Non-detectable actions only. Recipients may not use PAP:RED information on the network. Only passive actions on logs, that are not detectable from the outside.",
- "colour": "#ff0000"
+ "colour": "#ff2b2b"
},
{
"value": "AMBER",
"expanded": "(PAP:AMBER) Passive cross check. Recipients may use PAP:AMBER information for conducting online checks, like using services provided by third parties (e.g. VirusTotal), or set up a monitoring honeypot.",
- "colour": "#ffa800"
+ "colour": "#ffc000"
},
{
"value": "GREEN",
"expanded": "(PAP:GREEN) Active actions allowed. Recipients may use PAP:GREEN information to ping the target, block incoming/outgoing traffic from/to the target or specifically configure honeypots to interact with the target.",
- "colour": "#00ad1c"
+ "colour": "#33ff00"
+ },
+ {
+ "value": "CLEAR",
+ "expanded": "(PAP:CLEAR) No restrictions in using this information.",
+ "colour": "#ffffff"
},
{
"value": "WHITE",
From 6efa8c30757930109fbc96d6f582532882d15bc9 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 22 Nov 2023 11:32:14 +0100
Subject: [PATCH 170/181] fix: [tlp] updated TLP:AMBER+strict description based
on #261 by @vba-anssi
---
tlp/machinetag.json | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/tlp/machinetag.json b/tlp/machinetag.json
index b80e9b1..0861232 100755
--- a/tlp/machinetag.json
+++ b/tlp/machinetag.json
@@ -15,7 +15,7 @@
{
"colour": "#FFC000",
"description": "Limited disclosure, recipients can only spread this on a need-to-know basis within their organization. Sources may use TLP:AMBER+STRICT when information requires support to be effectively acted upon, yet carries risk to privacy, reputation, or operations if shared outside of the organizations involved. Recipients may share TLP:AMBER+STRICT information with members of their own organization.",
- "expanded": "Limited disclosure, recipients can only spread this on a need-to-know basis within their organization.",
+ "expanded": "(TLP:AMBER+STRICT) Limited disclosure, recipients can only spread this on a need-to-know basis within their organization.",
"value": "amber+strict"
},
{
@@ -50,7 +50,7 @@
"refs": [
"https://www.first.org/tlp"
],
- "version": 9,
+ "version": 10,
"description": "The Traffic Light Protocol (TLP) (v2.0) was created to facilitate greater sharing of potentially sensitive information and more effective collaboration. Information sharing happens from an information source, towards one or more recipients. TLP is a set of four standard labels (a fifth label is included in amber to limit the diffusion) used to indicate the sharing boundaries to be applied by the recipients. Only labels listed in this standard are considered valid by FIRST. This taxonomy includes additional labels for backward compatibility which are no more validated by FIRST SIG.",
"expanded": "Traffic Light Protocol",
"exclusive": true,
From 8d957d224ef339303d001167900ee38ce586d22d Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 22 Nov 2023 11:38:45 +0100
Subject: [PATCH 171/181] chg: [MANIFEST] updated
---
MANIFEST.json | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/MANIFEST.json b/MANIFEST.json
index 35dd6c7..754ef76 100644
--- a/MANIFEST.json
+++ b/MANIFEST.json
@@ -26,7 +26,7 @@
{
"description": "The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used.",
"name": "PAP",
- "version": 2
+ "version": 3
},
{
"description": "The access method used to remotely access a system.",
@@ -666,7 +666,7 @@
{
"description": "SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection",
"name": "srbcert",
- "version": 1
+ "version": 3
},
{
"description": "A spectrum of state responsibility to more directly tie the goals of attribution to the needs of policymakers.",
@@ -706,7 +706,7 @@
{
"description": "The Traffic Light Protocol (TLP) (v2.0) was created to facilitate greater sharing of potentially sensitive information and more effective collaboration. Information sharing happens from an information source, towards one or more recipients. TLP is a set of four standard labels (a fifth label is included in amber to limit the diffusion) used to indicate the sharing boundaries to be applied by the recipients. Only labels listed in this standard are considered valid by FIRST. This taxonomy includes additional labels for backward compatibility which are no more validated by FIRST SIG.",
"name": "tlp",
- "version": 9
+ "version": 10
},
{
"description": "Taxonomy to describe Tor network infrastructure",
@@ -755,5 +755,5 @@
}
],
"url": "https://raw.githubusercontent.com/MISP/misp-taxonomies/main/",
- "version": "20231115"
+ "version": "20231122"
}
From 32b2afd795faf42fd1c7e2cd70c9c3f731715032 Mon Sep 17 00:00:00 2001
From: Christian Studer
Date: Thu, 7 Dec 2023 15:57:46 +0100
Subject: [PATCH 172/181] fix: [doping-substances] Deduplicated some entries
---
doping-substances/machinetag.json | 12 ------------
1 file changed, 12 deletions(-)
diff --git a/doping-substances/machinetag.json b/doping-substances/machinetag.json
index f700b9e..cbafb6f 100644
--- a/doping-substances/machinetag.json
+++ b/doping-substances/machinetag.json
@@ -451,9 +451,6 @@
{
"value": "fenoterol"
},
- {
- "value": "formoterol"
- },
{
"value": "higenamine"
},
@@ -472,12 +469,6 @@
{
"value": "reproterol"
},
- {
- "value": "salbutamol"
- },
- {
- "value": "salmeterol"
- },
{
"value": "terbutaline"
},
@@ -488,9 +479,6 @@
{
"value": "tulobuterol"
},
- {
- "value": "vilanterol"
- },
{
"value": "salbutamol",
"expanded": "inhaled salbutamol: maximum 1600 micrograms over 24 hours in divided doses not to exceed 600 micrograms over 8 hours starting from any dose"
From 92948d2cba6e3e4f5fa2975be3da15bf72a3f080 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Sun, 31 Dec 2023 08:38:49 +0100
Subject: [PATCH 173/181] chg: [doc] doc and manifest updated
---
MANIFEST.json | 2 +-
summary.md | 368 +++++++++++++++++++++++++++++++++++++++++++++++---
2 files changed, 351 insertions(+), 19 deletions(-)
diff --git a/MANIFEST.json b/MANIFEST.json
index 754ef76..74fa77f 100644
--- a/MANIFEST.json
+++ b/MANIFEST.json
@@ -755,5 +755,5 @@
}
],
"url": "https://raw.githubusercontent.com/MISP/misp-taxonomies/main/",
- "version": "20231122"
+ "version": "20231231"
}
diff --git a/summary.md b/summary.md
index 6db86fb..998bad3 100644
--- a/summary.md
+++ b/summary.md
@@ -1,5 +1,5 @@
# Taxonomies
-- Generation date: 2022-01-22
+- Generation date: 2023-12-31
- license: CC-0
- description: Manifest file of MISP taxonomies available.
@@ -55,13 +55,29 @@
- 2
- 1
- 0
+### GrayZone
+- description: Gray Zone of Active defense includes all elements which lay between reactive defense elements and offensive operations. It does fill the gray spot between them. Taxo may be used for active defense planning or modeling.
+- version: 3
+- Predicates
+ - Adversary Emulation
+ - Beacons
+ - Deterrence
+ - Deception
+ - Tarpits, Sandboxes and Honeypots
+ - Threat Intelligence
+ - Threat Hunting
+ - Adversary Takedowns
+ - Ransomware
+ - Rescue Missions
+ - Sanctions, Indictments & Trade Remedies
### PAP
- description: The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used.
-- version: 2
+- version: 3
- Predicates
- RED
- AMBER
- GREEN
+ - CLEAR
- WHITE
### access-method
- description: The access method used to remotely access a system.
@@ -154,6 +170,33 @@
- cat4
- cat5
- cat6
+### artificial-satellites
+- description: This taxonomy was designed to describe artificial satellites
+- version: 1
+- Predicates
+ - Meteorological and Earth observation
+ - Indian Space Research
+ - GEO
+ - Tracking
+ - Search & Rescue
+ - Earth Ressources
+ - Disaster Monitoring
+ - GNSS
+ - Space & Earth Science
+ - Geodetic
+ - Engineering
+ - Education
+### aviation
+- description: A taxonomy describing security threats or incidents against the aviation sector.
+- version: 1
+- Predicates
+ - target
+ - target-systems
+ - target-sub-systems
+ - impact
+ - likelihood
+ - criticality
+ - certainty
### binary-class
- description: Custom taxonomy for types of binary file.
- version: 2
@@ -179,11 +222,25 @@
- severity
- threat-vector
### circl
-- description: CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection
-- version: 5
+- description: CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection.
+- version: 6
- Predicates
- incident-classification
- topic
+ - significant
+### cnsd
+- description: La presente taxonomia es la primera versión disponible para el Centro Nacional de Seguridad Digital del Perú.
+- version: 20220513
+- Predicates
+ - Contenido abusivo
+ - Disponibilidad
+ - Fraude
+ - Fuga de información
+ - Intentos de intrusión
+ - Intrusión
+ - Malware
+ - Recopilación de información
+ - Otros
### coa
- description: Course of action taken within organization to discover, detect, deny, disrupt, degrade, deceive and/or destroy an attack.
- version: 2
@@ -234,9 +291,9 @@
- passive
- active
### crowdsec
-- description: The Crowdsec behaviors and classifications taxonomy is the list of taxonomies used in Crowdsec to describe the behaviors and classifications of an IP address. The behaviors are a list of attack categories for which a given IP address was reported, where the classifications describe a list of categories associated to an IP address and, when applicable, a list of false positive categories.
+- description: Crowdsec IP address classifications and behaviors taxonomy.
- version: 1
-- predicates
+- Predicates
- behavior
- false-positive
- classification
@@ -254,6 +311,7 @@
- Decentralized Stable Coins
- Email Extortion and Bomb Threats
- Crypto Robbing Ransomware
+ - Pig Butchering Scam
### csirt-americas
- description: Taxonomía CSIRT Américas.
- version: 1
@@ -323,12 +381,14 @@
- Predicates
- action
### dark-web
-- description: Criminal motivation on the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project
-- version: 4
+- description: Criminal motivation and content detection the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission.
+- version: 5
- Predicates
- topic
- motivation
- structure
+ - service
+ - content
### data-classification
- description: Data classification for data potentially at risk of exfiltration based on table 2.1 of Solving Cyber Risk book.
- version: 1
@@ -354,6 +414,143 @@
- Predicates
- Einstufung
- Schutzwort
+### death-possibilities
+- description: Taxonomy of Death Possibilities
+- version: 1
+- Predicates
+ - (001-009) Intestinal infectious diseases
+ - (010-018) Tuberculosis
+ - (020-027) Zoonotic bacterial diseases
+ - (030-041) Other bacterial diseases
+ - (042-042) Human immunodeficiency virus [HIV] infection
+ - (045-049) Poliomyelitis and other non-arthropod-borne viral diseases of central nervous system
+ - (050-057) Viral diseases accompanied by exanthem
+ - (060-066) Arthropod-borne viral diseases
+ - (070-079) Other diseases due to viruses and Chlamydiae
+ - (080-088) Rickettsioses and other arthropod-borne diseases
+ - (090-099) Syphilis and other venereal diseases
+ - (100-104) Other spirochaetal diseases
+ - (110-118) Mycoses
+ - (120-129) Helminthiases
+ - (130-136) Other infectious and parasitic diseases
+ - (137-139) Late effects of infectious and parasitic diseases
+ - (140-149) Malignant neoplasm of lip, oral cavity and pharynx
+ - (150-159) Malignant neoplasm of digestive organs and peritoneum
+ - (160-165) Malignant neoplasm of respiratory and intrathoracic organs
+ - (170-176) Malignant neoplasm of bone, connective tissue, skin and breast
+ - (179-189) Malignant neoplasm of genito-urinary organs
+ - (190-199) Malignant neoplasm of other and unspecified sites
+ - (200-208) Malignant neoplasm of lymphatic and haematopoietic tissue
+ - (210-229) Benign neoplasms
+ - (230-234) Carcinoma in situ
+ - (235-238) Neoplasms of uncertain behaviour
+ - (239-239) Neoplasms of unspecified nature
+ - (240-246) Disorders of thyroid gland
+ - (250-259) Diseases of other endocrine glands
+ - (260-269) Nutritional deficiencies
+ - (270-279) Other metabolic disorders and immunity disorders
+ - (280-289) Diseases of blood and blood-forming organs
+ - (290-294) Organic psychotic conditions
+ - (295-299) Other psychoses
+ - (300-316) Neurotic disorders, personality disorders and other nonpsychotic mental disorders
+ - (317-319) Mental retardation
+ - (320-326) Inflammatory diseases of the central nervous system
+ - (330-337) Hereditary and degenerative diseases of the central nervous system
+ - (340-349) Other disorders of the central nervous system
+ - (350-359) Disorders of the peripheral nervous system
+ - (360-379) Disorders of the eye and adnexa
+ - (380-389) Diseases of the ear and mastoid process
+ - (390-392) Acute rheumatic fever
+ - (393-398) Chronic rheumatic heart disease
+ - (401-405) Hypertensive disease
+ - (410-414) Ischaemic heart disease
+ - (415-417) Diseases of pulmonary circulation
+ - (420-429) Other forms of heart disease
+ - (430-438) Cerebrovascular disease
+ - (440-448) Diseases of arteries, arterioles and capillaries
+ - (451-459) Diseases of veins and lymphatics, and other diseases of circulatory system
+ - (460-466) Acute respiratory infections
+ - (470-478) Other diseases of upper respiratory tract
+ - (480-487) Pneumonia and influenza
+ - (490-496) Chronic obstructive pulmonary disease and allied conditions
+ - (500-508) Pneumoconioses and other lung diseases due to external agents
+ - (510-519) Other diseases of respiratory system
+ - (520-529) Diseases of oral cavity, salivary glands and jaws
+ - (530-537) Diseases of oesophagus, stomach and duodenum
+ - (540-543) Appendicitis
+ - (550-553) Hernia of abdominal cavity
+ - (555-558) Non-infective enteritis and colitis
+ - (560-569) Other diseases of intestines and peritoneum
+ - (570-579) Other diseases of digestive system
+ - (580-589) Nephritis, nephrotic syndrome and nephrosis
+ - (590-599) Other diseases of urinary system
+ - (600-608) Diseases of male genital organs
+ - (610-611) Disorders of breast
+ - (614-616) Inflammatory disease of female pelvic organs
+ - (617-629) Other disorders of female genital tract
+ - (630-633) Ectopic and molar pregnancy
+ - (634-639) Other pregnancy with abortive outcome
+ - (640-648) Complications mainly related to pregnancy
+ - (650-659) Normal delivery and other indications for care in pregnancy, labour and delivery
+ - (660-669) Complications occurring mainly in the course of labour and delivery
+ - (670-677) Complications of the puerperium
+ - (680-686) Infections of skin and subcutaneous tissue
+ - (690-698) Other inflammatory conditions of skin and subcutaneous tissue
+ - (700-709) Other diseases of skin and subcutaneous tissue
+ - (710-719) Arthropathies and related disorders
+ - (720-724) Dorsopathies
+ - (725-729) Rheumatism, excluding the back
+ - (730-739) Osteopathies, chondropathies and acquired musculoskeletal deformities
+ - (740-759) Congenital anomalies
+ - (760-763) Maternal causes of perinatal morbidity and mortality
+ - (764-779) Other conditions originating in the perinatal period
+ - (780-789) Symptoms
+ - (790-796) Nonspecific abnormal findings
+ - (797-799) Ill-defined and unknown causes of morbidity and mortality
+ - (800-804) Fracture of skull
+ - (805-809) Fracture of neck and trunk
+ - (810-819) Fracture of upper limb
+ - (820-829) Fracture of lower limb
+ - (830-839) Dislocation
+ - (840-848) Sprains and strains of joints and adjacent muscles
+ - (850-854) Intracranial injury, excluding those with skull fracture
+ - (860-869) Internal injury of chest, abdomen and pelvis
+ - (870-879) Open wound of head, neck and trunk
+ - (880-887) Open wound of upper limb
+ - (890-897) Open wound of lower limb
+ - (900-904) Injury to blood vessels
+ - (905-909) Late effects of injuries, poisonings, toxic effects and other external causes
+ - (910-919) Superficial injury
+ - (920-924) Contusion with intact skin surface
+ - (925-929) Crushing injury
+ - (930-939) Effects of foreign body entering through orifice
+ - (940-949) Burns
+ - (950-957) Injury to nerves and spinal cord
+ - (958-959) Certain traumatic complications and unspecified injuries
+ - (960-979) Poisoning by drugs, medicaments and biological substances
+ - (980-989) Toxic effects of substances chiefly nonmedicinal as to source
+ - (990-995) Other and unspecified effects of external causes
+ - (996-999) Complications of surgical and medical care, not elsewhere classified
+ - (E800-E807) Railway accidents
+ - (E810-E819) Motor vehicle traffic accidents
+ - (E820-E825) Motor vehicle nontraffic accidents
+ - (E826-E829) Other road vehicle accidents
+ - (E830-E838) Water transport accidents
+ - (E840-E845) Air and space transport accidents
+ - (E846-E848) Vehicle accidents not elsewhere classifiable
+ - (E849-E858) Accidental poisoning by drugs, medicaments and biologicals
+ - (E860-E869) Accidental poisoning by other solid and liquid substances, gases and vapours
+ - (E870-E876) Misadventures to patients during surgical and medical care
+ - (E878-E879) Surgical and medical procedures as the cause of abnormal reaction of patient or later complication, without mention of misadventure at the time of procedure
+ - (E880-E888) Accidental falls
+ - (E890-E899) Accidents caused by fire and flames
+ - (E900-E909) Accidents due to natural and environmental factors
+ - (E910-E915) Accidents caused by submersion, suffocation and foreign bodies
+ - (E916-E928) Other accidents
+ - (E929-E929) Late effects of accidental injury
+ - (E930-E949) Drugs, medicaments and biological substances causing adverse effects in therapeutic use
+ - (E950-E959) Suicide and self-inflicted injury
+ - (E960-E969) Homicide and injury purposely inflicted by other persons
### deception
- description: Deception is an important component of information operations, valuable for both offense and defense.
- version: 1
@@ -365,6 +562,12 @@
- quality
- essence
- speech-act-theory
+### dga
+- description: A taxonomy to describe domain-generation algorithms often called DGA. Ref: A Comprehensive Measurement Study of Domain Generating Malware Daniel Plohmann and others.
+- version: 2
+- Predicates
+ - generation-scheme
+ - seeding
### dhs-ciip-sectors
- description: DHS critical sectors as in https://www.dhs.gov/critical-infrastructure-sectors
- version: 2
@@ -379,6 +582,15 @@
- Capability
- Infrastructure
- Victim
+### diamond-model-for-influence-operations
+- description: The diamond model for influence operations analysis is a framework that leads analysts and researchers toward a comprehensive understanding of a malign influence campaign by addressing the socio-political, technical, and psychological aspects of the campaign. The diamond model for influence operations analysis consists of 5 components: 4 corners and a core element. The 4 corners are divided into 2 axes: influencer and audience on the socio-political axis, capabilities and infrastructure on the technical axis. Narrative makes up the core of the diamond.
+- version: 1
+- Predicates
+ - Influencer
+ - Capabilities
+ - Infrastructure
+ - Audience
+ - Narrative
### dni-ism
- description: A subset of Information Security Marking Metadata ISM as required by Executive Order (EO) 13526. As described by DNI.gov as Data Encoding Specifications for Information Security Marking Metadata in Controlled Vocabulary Enumeration Values for ISM
- version: 3
@@ -398,6 +610,23 @@
- Predicates
- domain-status
- domain-access-method
+### doping-substances
+- description: This taxonomy aims to list doping substances
+- version: 2
+- Predicates
+ - anabolic agents
+ - peptide hormones, growth factors, related substances and mimetics
+ - beta-2 agonists
+ - hormone and metabolic modulators
+ - diuretics and masking agents
+ - manipulation of blood and blood components
+ - chemical and physical manipulation
+ - gene and cell doping
+ - stimulants
+ - narcotics
+ - cannabinoids
+ - glucocorticoids
+ - beta-blockers
### drugs
- description: A taxonomy based on the superclass and class of drugs. Based on https://www.drugbank.ca/releases/latest
- version: 2
@@ -578,14 +807,15 @@
- cyber-sopex
- generic
### extended-event
-- description: Reasons why an event has been extended.
-- version: 1
+- description: Reasons why an event has been extended. This taxonomy must be used on the extended event. The competitive analysis aspect is from Psychology of Intelligence Analysis by Richard J. Heuer, Jr. ref:http://www.foo.be/docs/intelligence/PsychofIntelNew.pdf
+- version: 2
- Predicates
- competitive-analysis
- extended-analysis
- human-readable
- chunked-event
- update
+ - counter-analysis
### failure-mode-in-machine-learning
- description: The purpose of this taxonomy is to jointly tabulate both the of these failure modes in a single place. Intentional failures wherein the failure is caused by an active adversary attempting to subvert the system to attain her goals – either to misclassify the result, infer private training data, or to steal the underlying algorithm. Unintentional failures wherein the failure is because an ML system produces a formally correct but completely unsafe outcome.
- version: 1
@@ -594,7 +824,7 @@
- unintended-failures-summary
### false-positive
- description: This taxonomy aims to ballpark the expected amount of false positives.
-- version: 5
+- version: 7
- Predicates
- risk
- confirmed
@@ -603,6 +833,15 @@
- version: 1
- Predicates
- type
+### financial
+- description: Financial taxonomy to describe financial services, infrastructure and financial scope.
+- version: 7
+- Predicates
+ - categories-and-types-of-services
+ - geographical-footprint
+ - online-exposition
+ - physical-presence
+ - services
### flesch-reading-ease
- description: Flesch Reading Ease is a revised system for determining the comprehension difficulty of written material. The scoring of the flesh score can have a maximum of 121.22 and there is no limit on how low a score can be (negative score are valid).
- version: 2
@@ -827,6 +1066,13 @@
- submission
- output-format
- certainty
+### information-origin
+- description: Taxonomy for tagging information by its origin: human-generated or AI-generated.
+- version: 2
+- Predicates
+ - human-generated
+ - AI-generated
+ - uncertain-origin
### information-security-data-source
- description: Taxonomy to classify the information security data sources.
- version: 1
@@ -978,6 +1224,14 @@
- misp2yara
- event-type
- ids
+### misp-workflow
+- description: MISP workflow taxonomy to support result of workflow execution.
+- version: 3
+- Predicates
+ - action-taken
+ - analysis
+ - mutability
+ - run
### monarc-threat
- description: MONARC Threats Taxonomy
- version: 1
@@ -1022,6 +1276,19 @@
- nature-root-cause
- nature-severity
- test
+### nis2
+- description: The taxonomy is meant for large scale cybersecurity incidents, as mentioned in the Commission Recommendation of 13 May 2022, also known as the provisional agreement. It has two core parts: The nature of the incident, i.e. the underlying cause, that triggered the incident, and the impact of the incident, i.e. the impact on services, in which sector(s) of economy and society.
+- version: 3
+- Predicates
+ - impact-sectors-impacted
+ - impact-subsectors-impacted
+ - important-entities
+ - impact-subsectors-important-entities
+ - impact-severity
+ - impact-outlook
+ - nature-root-cause
+ - nature-severity
+ - test
### open_threat
- description: Open Threat Taxonomy v1.1 base on James Tarala of SANS http://www.auditscripts.com/resources/open_threat_taxonomy_v1.1a.pdf, https://files.sans.org/summit/Threat_Hunting_Incident_Response_Summit_2016/PDFs/Using-Open-Tools-to-Convert-Threat-Intelligence-into-Practical-Defenses-James-Tarala-SANS-Institute.pdf, https://www.youtube.com/watch?v=5rdGOOFC_yE, and https://www.rsaconference.com/writable/presentations/file_upload/str-r04_using-an-open-source-threat-model-for-prioritized-defense-final.pdf
- version: 1
@@ -1072,6 +1339,12 @@
- state
- psychological-acceptability
- principle-of-persuasion
+### poison-taxonomy
+- description: Non-exhaustive taxonomy of natural poison
+- version: 1
+- Predicates
+ - Poisonous plant
+ - Poisonous fungus
### political-spectrum
- description: A political spectrum is a system to characterize and classify different political positions in relation to one another.
- version: 1
@@ -1089,6 +1362,20 @@
- low
- baseline-minor
- baseline-negligible
+### pyoti
+- description: PyOTI automated enrichment schemes for point in time classification of indicators.
+- version: 3
+- Predicates
+ - checkdmarc
+ - disposable-email
+ - emailrepio
+ - iris-investigate
+ - virustotal
+ - circl-hashlookup
+ - reputation-block-list
+ - abuseipdb
+ - greynoise-riot
+ - googlesafebrowsing
### ransomware
- description: Ransomware is used to define ransomware types and the elements that compose them.
- version: 6
@@ -1101,6 +1388,17 @@
- infection
- communication
- malicious-action
+### ransomware-roles
+- description: The seven roles seen in most ransomware incidents.
+- version: 1
+- Predicates
+ - 1 - Initial Access Broker
+ - 2 - Ransomware Affiliate
+ - 3 - Data Manager
+ - 4 - Ransomware Operator
+ - 5 - Negotiator
+ - 6 - Chaser
+ - 7 - Accountant
### retention
- description: Add a retenion time to events to automatically remove the IDS-flag on ip-dst or ip-src attributes. We calculate the time elapsed based on the date of the event. Supported time units are: d(ays), w(eeks), m(onths), y(ears). The numerical_value is just for sorting in the web-interface and is not used for calculations.
- version: 3
@@ -1137,11 +1435,13 @@
- Predicates
- event-status
### runtime-packer
-- description: Runtime or software packer used to combine compressed data with the decompression code. The decompression code can add additional obfuscations mechanisms including polymorphic-packer or other obfuscation techniques. This taxonomy lists all the known or official packer used for legitimate use or for packing malicious binaries.
-- version: 1
+- description: Runtime or software packer used to combine compressed or encrypted data with the decompression or decryption code. This code can add additional obfuscations mechanisms including polymorphic-packer or other obfuscation techniques. This taxonomy lists all the known or official packer used for legitimate use or for packing malicious binaries.
+- version: 2
- Predicates
- - portable-executable
+ - dex
- elf
+ - macho
+ - pe
- cli-assembly
### scrippsco2-fgc
- description: Flags describing the sample
@@ -1187,6 +1487,21 @@
- NZD
- PSA
- SPO
+### sentinel-threattype
+- description: Sentinel indicator threat types.
+- version: 1
+- Predicates
+ - Botnet
+ - C2
+ - CryptoMining
+ - Darknet
+ - DDoS
+ - MaliciousUrl
+ - Malware
+ - Phishing
+ - Proxy
+ - PUA
+ - WatchList
### smart-airports-threats
- description: Threat taxonomy in the scope of securing smart airports by ENISA. https://www.enisa.europa.eu/publications/securing-smart-airports
- version: 1
@@ -1196,6 +1511,18 @@
- natural-and-social-phenomena
- third-party-failures
- malicious-actions
+### social-engineering-attack-vectors
+- description: Attack vectors used in social engineering as described in 'A Taxonomy of Social Engineering Defense Mechanisms' by Dalal Alharthi and others.
+- version: 1
+- Predicates
+ - technical
+ - non-technical
+### srbcert
+- description: SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection
+- version: 3
+- Predicates
+ - incident-type
+ - incident-criticality-level
### state-responsibility
- description: A spectrum of state responsibility to more directly tie the goals of attribution to the needs of policymakers.
- version: 1
@@ -1228,13 +1555,15 @@
- technical-sophistication-multiplier
### thales_group
- description: Thales Group Taxonomy - was designed with the aim of enabling desired sharing and preventing unwanted sharing between Thales Group security communities.
-- version: 2
+- version: 4
- Predicates
- distribution
- to_block
- minarm
- acn
- sigpart
+ - a_isac
+ - intercert_france
- ioc_confidence
- tlp:black
- Watcher
@@ -1254,14 +1583,17 @@
- dns-server-attacks
- dns-abuse-or-misuse
### tlp
-- description: The Traffic Light Protocol - or short: TLP - was designed with the objective to create a favorable classification scheme for sharing sensitive information while keeping the control over its distribution at the same time.
-- version: 5
+- description: The Traffic Light Protocol (TLP) (v2.0) was created to facilitate greater sharing of potentially sensitive information and more effective collaboration. Information sharing happens from an information source, towards one or more recipients. TLP is a set of four standard labels (a fifth label is included in amber to limit the diffusion) used to indicate the sharing boundaries to be applied by the recipients. Only labels listed in this standard are considered valid by FIRST. This taxonomy includes additional labels for backward compatibility which are no more validated by FIRST SIG.
+- version: 10
- Predicates
- red
- amber
+ - amber+strict
- green
- white
+ - clear
- ex:chr
+ - unclear
### tor
- description: Taxonomy to describe Tor network infrastructure
- version: 1
@@ -1385,7 +1717,7 @@
- degré-de-probabilité
### workflow
- description: Workflow support language is a common language to support intelligence analysts to perform their analysis on data and information.
-- version: 11
+- version: 12
- Predicates
- todo
- state
\ No newline at end of file
From 3d61b20e7ee8bca21f9bffe53c0952c54a6b72b0 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Sun, 31 Dec 2023 08:42:44 +0100
Subject: [PATCH 174/181] chg: [doc] list updated
---
README.md | 21 ++++++++++++++++++---
1 file changed, 18 insertions(+), 3 deletions(-)
diff --git a/README.md b/README.md
index acca427..6e362cf 100644
--- a/README.md
+++ b/README.md
@@ -100,7 +100,7 @@ Internal taxonomy for CCCS. [Overview](https://www.misp-project.org/taxonomies.h
### circl
[circl](https://github.com/MISP/misp-taxonomies/tree/main/circl) :
-CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection [Overview](https://www.misp-project.org/taxonomies.html#_circl)
+CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection. [Overview](https://www.misp-project.org/taxonomies.html#_circl)
### cnsd
@@ -135,7 +135,7 @@ A Course Of Action analysis considers six potential courses of action for the de
### crowdsec
[crowdsec](https://github.com/MISP/misp-taxonomies/tree/main/crowdsec) :
-The Crowdsec behaviors and classifications taxonomy is the [list of taxonomies used in Crowdsec](https://doc.crowdsec.net/docs/next/cti_api/taxonomy) to describe the behaviors and classifications of an IP address. The behaviors are a list of attack categories for which a given IP address was reported, where the classifications describe a list of categories associated to an IP address and, when applicable, a list of false positive categories. [Overview](https://www.misp-project.org/taxonomies.html#_crowdsec)
+Crowdsec IP address classifications and behaviors taxonomy. [Overview](https://www.misp-project.org/taxonomies.html#_crowdsec)
### cryptocurrency-threat
@@ -185,7 +185,7 @@ Taxonomy to describe desired actions for Cytomic Orion [Overview](https://www.mi
### dark-web
[dark-web](https://github.com/MISP/misp-taxonomies/tree/main/dark-web) :
-Criminal motivation on the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project [Overview](https://www.misp-project.org/taxonomies.html#_dark_web)
+Criminal motivation and content detection the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission. [Overview](https://www.misp-project.org/taxonomies.html#_dark_web)
### data-classification
@@ -247,6 +247,11 @@ A subset of Information Security Marking Metadata ISM as required by Executive O
[domain-abuse](https://github.com/MISP/misp-taxonomies/tree/main/domain-abuse) :
Domain Name Abuse - taxonomy to tag domain names used for cybercrime. [Overview](https://www.misp-project.org/taxonomies.html#_domain_abuse)
+### doping-substances
+
+[doping-substances](https://github.com/MISP/misp-taxonomies/tree/main/doping-substances) :
+This taxonomy aims to list doping substances [Overview](https://www.misp-project.org/taxonomies.html#_doping_substances)
+
### drugs
[drugs](https://github.com/MISP/misp-taxonomies/tree/main/drugs) :
@@ -427,6 +432,11 @@ How an incident is classified in its process to be resolved. The taxonomy is ins
[infoleak](https://github.com/MISP/misp-taxonomies/tree/main/infoleak) :
A taxonomy describing information leaks and especially information classified as being potentially leaked. The taxonomy is based on the work by CIRCL on the AIL framework. The taxonomy aim is to be used at large to improve classification of leaked information. [Overview](https://www.misp-project.org/taxonomies.html#_infoleak)
+### information-origin
+
+[information-origin](https://github.com/MISP/misp-taxonomies/tree/main/information-origin) :
+Taxonomy for tagging information by its origin: human-generated or AI-generated. [Overview](https://www.misp-project.org/taxonomies.html#_information_origin)
+
### information-security-data-source
[information-security-data-source](https://github.com/MISP/misp-taxonomies/tree/main/information-security-data-source) :
@@ -662,6 +672,11 @@ Threat taxonomy in the scope of securing smart airports by ENISA. https://www.en
[social-engineering-attack-vectors](https://github.com/MISP/misp-taxonomies/tree/main/social-engineering-attack-vectors) :
Attack vectors used in social engineering as described in 'A Taxonomy of Social Engineering Defense Mechanisms' by Dalal Alharthi and others. [Overview](https://www.misp-project.org/taxonomies.html#_social_engineering_attack_vectors)
+### srbcert
+
+[srbcert](https://github.com/MISP/misp-taxonomies/tree/main/srbcert) :
+SRB-CERT Taxonomy - Schemes of Classification in Incident Response and Detection [Overview](https://www.misp-project.org/taxonomies.html#_srbcert)
+
### state-responsibility
[state-responsibility](https://github.com/MISP/misp-taxonomies/tree/main/state-responsibility) :
From 41e8bdc4f3e5a4793c163ba4d49b3edb5516a834 Mon Sep 17 00:00:00 2001
From: Hendrik Baecker
Date: Tue, 6 Feb 2024 14:28:16 +0100
Subject: [PATCH 175/181] Added 'course-of-action:passive=nodiscover'
---
course-of-action/machinetag.json | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/course-of-action/machinetag.json b/course-of-action/machinetag.json
index f302bae..5750e42 100644
--- a/course-of-action/machinetag.json
+++ b/course-of-action/machinetag.json
@@ -2,7 +2,7 @@
"namespace": "course-of-action",
"expanded": "Courses of Action",
"description": "A Course Of Action analysis considers six potential courses of action for the development of a cyber security capability.",
- "version": 2,
+ "version": 3,
"predicates": [
{
"value": "passive",
@@ -21,6 +21,10 @@
"value": "discover",
"expanded": "The discover action is a 'historical look at the data'. This action heavily relies on your capability to store logs for a reasonable amount of time and have them accessible for searching. Typically, this type of action is applied against security information and event management (SIEM) or stored network data. The goal is to determine whether you have seen a specific indicator in the past."
},
+ {
+ "value": "nodiscover",
+ "expanded": "The no-discover action is a negation of discover in case you want to explicit prohibit 'historical look at the data'. The goal is to exclude a specific indicator from searches of historical data."
+ },
{
"value": "detect",
"expanded": "The passive action is setting up detection rules of an indicator for future traffic. These actions are most often executed via an intrusion detection system (IDS) or a specific logging rule on your firewall or application. It can also be configured as an alert in a SIEM when a specific condition is triggered."
From 8cd705ba6200bdd42c0b9565e108b7aaf88db6ac Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Fri, 16 Feb 2024 16:18:09 +0100
Subject: [PATCH 176/181] chg: [exercise] updated
---
exercise/machinetag.json | 17 ++++++++++++++++-
1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/exercise/machinetag.json b/exercise/machinetag.json
index ac88e77..e296bc7 100644
--- a/exercise/machinetag.json
+++ b/exercise/machinetag.json
@@ -45,6 +45,11 @@
{
"predicate": "cyber-europe",
"entry": [
+ {
+ "value": "2024",
+ "expanded": "2024",
+ "description": "7th pan European cyber crisis exercise: Cyber Europe 2024 (CE2024)"
+ },
{
"value": "2022",
"expanded": "2022",
@@ -104,6 +109,16 @@
"value": "2022",
"expanded": "2022",
"description": "Locked Shields 2022"
+ },
+ {
+ "value": "2023",
+ "expanded": "2023",
+ "description": "Locked Shields 2023"
+ },
+ {
+ "value": "2024",
+ "expanded": "2024",
+ "description": "Locked Shields 2024"
}
]
},
@@ -193,7 +208,7 @@
]
}
],
- "version": 10,
+ "version": 11,
"description": "Exercise is a taxonomy to describe if the information is part of one or more cyber or crisis exercise.",
"expanded": "Exercise",
"namespace": "exercise"
From 08cab31a896accc8e4785913c92a39b35a3268d5 Mon Sep 17 00:00:00 2001
From: JRC-T2 <129943580+JRC-T2@users.noreply.github.com>
Date: Mon, 4 Mar 2024 09:46:03 +0100
Subject: [PATCH 177/181] Update machinetag.json
Added darknet ransomware activity support
---
dark-web/machinetag.json | 32 +++++++++++++++++++++++++++++++-
1 file changed, 31 insertions(+), 1 deletion(-)
diff --git a/dark-web/machinetag.json b/dark-web/machinetag.json
index a67ab08..7abb13a 100644
--- a/dark-web/machinetag.json
+++ b/dark-web/machinetag.json
@@ -2,7 +2,7 @@
"namespace": "dark-web",
"expanded": "Dark Web",
"description": "Criminal motivation and content detection the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission.",
- "version": 5,
+ "version": 6,
"predicates": [
{
"value": "topic",
@@ -359,6 +359,11 @@
"expanded": "videos",
"description": "Videos and streaming"
},
+ {
+ "value": "ransomware-post",
+ "expanded": "ransomwarePost",
+ "description": "Ransomware post published by a ransomware group"
+ },
{
"value": "unclear",
"expanded": "unclear",
@@ -473,6 +478,31 @@
"value": "pgp-public-key-block",
"expanded": "pgpPublicKeyBlock",
"description": "PGP public key block identified in the dark-web site"
+ },
+ {
+ "value": "country",
+ "expanded": "country",
+ "description": "Associated country detected on the code of the dark-web site, following ISO 3166-1 alpha-2"
+ },
+ {
+ "value": "company-name",
+ "expanded": "companyName",
+ "description": "Company name identified in a dark-web site"
+ },
+ {
+ "value": "company-link",
+ "expanded": "companyLink",
+ "description": "Company link identified in a dark-web site"
+ },
+ {
+ "value": "victim-address",
+ "expanded": "victimAddress",
+ "description": "Business address identified in a dark-web site"
+ },
+ {
+ "value": "victim-TLD",
+ "expanded": "victimTLD",
+ "description": "Business Top Level Domain (TLD) of a company identified in a dark-web site"
}
]
}
From 5e93071832fe504a51eb8d658ce05bd76958d927 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Mon, 4 Mar 2024 09:57:26 +0100
Subject: [PATCH 178/181] fix: [tools] Fix #273 in markdown generator
---
tools/machinetag.py | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/machinetag.py b/tools/machinetag.py
index 66ed96c..bb253ea 100755
--- a/tools/machinetag.py
+++ b/tools/machinetag.py
@@ -165,7 +165,7 @@ def machineTag(namespace=False, predicate=False, value=None):
if predicate.get('numerical_value'):
doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['numerical_value']), adoc=doc, t='description')
if predicate.get('exclusive'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['exclusive']), adoc=adoc, t='exclusive')
+ doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['exclusive']), adoc=doc, t='exclusive')
else:
print(machineTag(namespace=namespace, predicate=predicate['value']))
if args.e:
From 5fc23d47955d9f8fae251332badfa92c9fcf7969 Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Mon, 4 Mar 2024 10:06:48 +0100
Subject: [PATCH 179/181] chg: [tools] clean-up python script to generate the
asciidoctor files
---
tools/machinetag.py | 290 +++++++++++++++++++++++++++++++-------------
1 file changed, 207 insertions(+), 83 deletions(-)
diff --git a/tools/machinetag.py b/tools/machinetag.py
index bb253ea..4cd42b8 100755
--- a/tools/machinetag.py
+++ b/tools/machinetag.py
@@ -32,25 +32,35 @@
import os
import sys
-skip_list = ['death-possibilities', 'poison-taxonomy', 'doping-substances']
+skip_list = ["death-possibilities", "poison-taxonomy", "doping-substances"]
taxonomies = []
# Get our current directory from file location
thisDir = os.path.dirname(__file__)
-argParser = argparse.ArgumentParser(description='Dump Machine Tags (Triple Tags) from MISP taxonomies', epilog='Available taxonomies are {0}'.format(taxonomies))
-argParser.add_argument('-e', action='store_true', help='Include expanded tags')
-argParser.add_argument('-a', action='store_true', help='Generate asciidoctor document from MISP taxonomies')
-argParser.add_argument('-v', action='store_true', help='Include descriptions')
-argParser.add_argument('-n', default=False, help='Show only the specified namespace')
-argParser.add_argument('--disable-skip-list', default=False, action='store_true', help='disable default skip list')
+argParser = argparse.ArgumentParser(
+ description="Dump Machine Tags (Triple Tags) from MISP taxonomies",
+ epilog="Available taxonomies are {0}".format(taxonomies),
+)
+argParser.add_argument("-e", action="store_true", help="Include expanded tags")
+argParser.add_argument(
+ "-a", action="store_true", help="Generate asciidoctor document from MISP taxonomies"
+)
+argParser.add_argument("-v", action="store_true", help="Include descriptions")
+argParser.add_argument("-n", default=False, help="Show only the specified namespace")
+argParser.add_argument(
+ "--disable-skip-list",
+ default=False,
+ action="store_true",
+ help="disable default skip list",
+)
args = argParser.parse_args()
if args.disable_skip_list:
- skip_list = ''
+ skip_list = ""
-for folder in os.listdir(os.path.join(thisDir, '../')):
- if os.path.isfile(os.path.join(thisDir, '../', folder, 'machinetag.json')):
+for folder in os.listdir(os.path.join(thisDir, "../")):
+ if os.path.isfile(os.path.join(thisDir, "../", folder, "machinetag.json")):
if folder in skip_list:
continue
taxonomies.append(folder)
@@ -58,23 +68,35 @@
taxonomies.sort()
-doc = ''
+doc = ""
if args.a:
dedication = "\n[dedication]\n== Funding and Support\nThe MISP project is financially and resource supported by https://www.circl.lu/[CIRCL Computer Incident Response Center Luxembourg ].\n\nimage:{images-misp}logo.png[CIRCL logo]\n\nA CEF (Connecting Europe Facility) funding under CEF-TC-2016-3 - Cyber Security has been granted from 1st September 2017 until 31th August 2019 as ***Improving MISP as building blocks for next-generation information sharing***.\n\nimage:{images-misp}en_cef.png[CEF funding]\n\nIf you are interested to co-fund projects around MISP, feel free to get in touch with us.\n\n"
doc = doc + ":toc: right\n"
doc = doc + ":toclevels: 1\n"
doc = doc + ":icons: font\n"
- doc = doc + ":images-cdn: https://raw.githubusercontent.com/MISP/MISP/2.4/INSTALL/logos/\n"
+ doc = (
+ doc
+ + ":images-cdn: https://raw.githubusercontent.com/MISP/MISP/2.4/INSTALL/logos/\n"
+ )
doc = doc + ":images-misp: https://www.misp-project.org/assets/images/\n"
doc = doc + "= MISP taxonomies and classification as machine tags\n\n"
doc = doc + "= Introduction\n"
doc = doc + "\nimage::{images-cdn}misp-logo.png[MISP logo]\n"
- doc = doc + "The MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators, financial fraud or counter-terrorism information. The MISP project includes multiple sub-projects to support the operational requirements of analysts and improve the overall quality of information shared.\n\n"
+ doc = (
+ doc
+ + "The MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators, financial fraud or counter-terrorism information. The MISP project includes multiple sub-projects to support the operational requirements of analysts and improve the overall quality of information shared.\n\n"
+ )
doc = doc + ""
- doc = "{} {} {} {}".format(doc, "\nTaxonomies that can be used in MISP (2.4) and other information sharing tool and expressed in Machine Tags (Triple Tags).",
- "A machine tag is composed of a namespace (MUST), a predicate (MUST) and an (OPTIONAL) value.",
- "Machine tags are often called triple tag due to their format.\n")
- doc = doc + "The following document is generated from the machine-readable JSON describing the https://github.com/MISP/misp-taxonomies[MISP taxonomies]."
+ doc = "{} {} {} {}".format(
+ doc,
+ "\nTaxonomies that can be used in MISP (2.4) and other information sharing tool and expressed in Machine Tags (Triple Tags).",
+ "A machine tag is composed of a namespace (MUST), a predicate (MUST) and an (OPTIONAL) value.",
+ "Machine tags are often called triple tag due to their format.\n",
+ )
+ doc = (
+ doc
+ + "The following document is generated from the machine-readable JSON describing the https://github.com/MISP/misp-taxonomies[MISP taxonomies]."
+ )
doc = doc + "\n\n"
doc = doc + "<<<\n"
doc = doc + dedication
@@ -87,31 +109,37 @@
taxonomies.append(args.n)
-def asciidoc(content=False, adoc=doc, t='title', toplevel=False):
+def asciidoc(content=False, adoc=doc, t="title", toplevel=False):
if not args.a:
return False
adoc = adoc + "\n"
- if t == 'title':
- content = '==== ' + content
- elif t == 'predicate':
- content = '=== ' + content
- elif t == 'namespace':
- content = '== ' + content + '\n'
- content = "{}\n{}{} {}{}{} {}".format(content, 'NOTE: ', namespace, 'namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/main/',
- namespace, '/machinetag.json[*this location*]. The JSON format can be freely reused in your application',
- 'or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy.')
- elif t == 'description' and toplevel is True:
+ if t == "title":
+ content = "==== " + content
+ elif t == "predicate":
+ content = "=== " + content
+ elif t == "namespace":
+ content = "== " + content + "\n"
+ content = "{}\n{}{} {}{}{} {}".format(
+ content,
+ "NOTE: ",
+ namespace,
+ "namespace available in JSON format at https://github.com/MISP/misp-taxonomies/blob/main/",
+ namespace,
+ "/machinetag.json[*this location*]. The JSON format can be freely reused in your application",
+ "or automatically enabled in https://www.github.com/MISP/MISP[MISP] taxonomy.",
+ )
+ elif t == "description" and toplevel is True:
content = "\n{} \n".format(content)
- elif t == 'description' and toplevel is False:
+ elif t == "description" and toplevel is False:
try:
(n, value) = content.split(":", 1)
content = "\n{} \n".format(value)
except:
content = "\n{} \n".format(content)
- elif t == 'numerical_value':
+ elif t == "numerical_value":
(n, value) = content.split(":", 1)
- content = "\nAssociated numerical value=\"{}\" \n".format(value)
- elif t == 'exclusive':
+ content = '\nAssociated numerical value="{}" \n'.format(value)
+ elif t == "exclusive":
(n, value) = content.split(":", 1)
if n:
content = "\nIMPORTANT: Exclusive flag set which means the values or predicate below must be set exclusively.\n"
@@ -124,9 +152,9 @@ def machineTag(namespace=False, predicate=False, value=None):
if namespace is False or predicate is False:
return None
if value is None:
- return (u'{0}:{1}'.format(namespace, predicate))
+ return "{0}:{1}".format(namespace, predicate)
else:
- return (u'{0}:{1}=\"{2}\"'.format(namespace, predicate, value))
+ return '{0}:{1}="{2}"'.format(namespace, predicate, value)
for taxonomy in taxonomies:
@@ -136,70 +164,166 @@ def machineTag(namespace=False, predicate=False, value=None):
filename = os.path.join(thisDir, "../", taxonomy, "machinetag.json")
with open(filename) as fp:
t = json.load(fp)
- namespace = t['namespace']
- if t.get('expanded'):
- expanded_namespace = t['expanded']
+ namespace = t["namespace"]
+ if t.get("expanded"):
+ expanded_namespace = t["expanded"]
else:
expanded_namespace = namespace
if args.a:
- doc = asciidoc(content=t['namespace'], adoc=doc, t='namespace')
- doc = asciidoc(content=t['description'], adoc=doc, t='description', toplevel = True)
- if t.get('exclusive'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=t['exclusive']), adoc=doc, t='exclusive')
+ doc = asciidoc(content=t["namespace"], adoc=doc, t="namespace")
+ doc = asciidoc(
+ content=t["description"], adoc=doc, t="description", toplevel=True
+ )
+ if t.get("exclusive"):
+ doc = asciidoc(
+ content=machineTag(namespace=namespace, predicate=t["exclusive"]),
+ adoc=doc,
+ t="exclusive",
+ )
if args.v:
- print('{0}'.format(t['description']))
- for predicate in t['predicates']:
+ print("{0}".format(t["description"]))
+ for predicate in t["predicates"]:
if args.a:
- doc = asciidoc(content=predicate['value'], adoc=doc, t='predicate')
- if predicate.get('description'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['description']), adoc=doc, t='description')
- if predicate.get('exclusive'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['exclusive']), adoc=doc, t='exclusive')
+ doc = asciidoc(content=predicate["value"], adoc=doc, t="predicate")
+ if predicate.get("description"):
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["description"]
+ ),
+ adoc=doc,
+ t="description",
+ )
+ if predicate.get("exclusive"):
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["exclusive"]
+ ),
+ adoc=doc,
+ t="exclusive",
+ )
- if t.get('values') is None:
+ if t.get("values") is None:
if args.a:
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['value']), adoc=doc)
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['expanded']), adoc=doc, t='description')
- if predicate.get('description'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['description']), adoc=doc, t='description')
- if predicate.get('numerical_value'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['numerical_value']), adoc=doc, t='description')
- if predicate.get('exclusive'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=predicate['exclusive']), adoc=doc, t='exclusive')
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["value"]
+ ),
+ adoc=doc,
+ )
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["expanded"]
+ ),
+ adoc=doc,
+ t="description",
+ )
+ if predicate.get("description"):
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["description"]
+ ),
+ adoc=doc,
+ t="description",
+ )
+ if predicate.get("numerical_value"):
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["numerical_value"]
+ ),
+ adoc=doc,
+ t="description",
+ )
+ if predicate.get("exclusive"):
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=predicate["exclusive"]
+ ),
+ adoc=doc,
+ t="exclusive",
+ )
else:
- print(machineTag(namespace=namespace, predicate=predicate['value']))
+ print(machineTag(namespace=namespace, predicate=predicate["value"]))
if args.e:
- print("--> " + machineTag(namespace=expanded_namespace, predicate=predicate['expanded']))
- if predicate.get('description'):
- print("--> " + predicate['description'])
+ print(
+ "--> "
+ + machineTag(
+ namespace=expanded_namespace, predicate=predicate["expanded"]
+ )
+ )
+ if predicate.get("description"):
+ print("--> " + predicate["description"])
else:
- for e in t['values']:
- if e['predicate'] == predicate['value']:
- if 'expanded' in predicate:
- expanded = predicate['expanded']
- for v in e['entry']:
- if args.a and 'expanded' in v:
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=e['predicate'], value=v['value']), adoc=doc)
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=v['expanded']), adoc=doc, t='description')
- if 'description' in v:
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=v['description']), adoc=doc, t='description')
- if v.get('numerical_value'):
- doc = asciidoc(content=machineTag(namespace=namespace, predicate=v['numerical_value']), adoc=doc, t='numerical_value')
+ for e in t["values"]:
+ if e["predicate"] == predicate["value"]:
+ if "expanded" in predicate:
+ expanded = predicate["expanded"]
+ for v in e["entry"]:
+ if args.a and "expanded" in v:
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace,
+ predicate=e["predicate"],
+ value=v["value"],
+ ),
+ adoc=doc,
+ )
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=v["expanded"]
+ ),
+ adoc=doc,
+ t="description",
+ )
+ if "description" in v:
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace, predicate=v["description"]
+ ),
+ adoc=doc,
+ t="description",
+ )
+ if v.get("numerical_value"):
+ doc = asciidoc(
+ content=machineTag(
+ namespace=namespace,
+ predicate=v["numerical_value"],
+ ),
+ adoc=doc,
+ t="numerical_value",
+ )
else:
- print(machineTag(namespace=namespace, predicate=e['predicate'], value=v['value']))
+ print(
+ machineTag(
+ namespace=namespace,
+ predicate=e["predicate"],
+ value=v["value"],
+ )
+ )
if args.e:
- if'expanded' in v:
- print("--> " + machineTag(namespace=namespace, predicate=expanded, value=v['expanded']))
+ if "expanded" in v:
+ print(
+ "--> "
+ + machineTag(
+ namespace=namespace,
+ predicate=expanded,
+ value=v["expanded"],
+ )
+ )
-with open('../mapping/mapping.json') as mapping:
+with open("../mapping/mapping.json") as mapping:
m = json.load(mapping)
- output = '\n= Mapping of taxonomies\n'
- output = '{}{}'.format(output, 'Analysts relying on taxonomies don\'t always know the appropriate namespace to use but know which value to use for classification. The MISP mapping taxonomy allows to map a single classification into a series of machine-tag synonyms.\n')
+ output = "\n= Mapping of taxonomies\n"
+ output = "{}{}".format(
+ output,
+ "Analysts relying on taxonomies don't always know the appropriate namespace to use but know which value to use for classification. The MISP mapping taxonomy allows to map a single classification into a series of machine-tag synonyms.\n",
+ )
for value in sorted(m.keys()):
- output = '{}{} **{}**{}{}\n'.format(output,'\n.Mapping table - ',value,'\n|===\n|',value)
- for mapped in m[value]['values']:
- output = '{}|{}\n'.format(output,mapped)
- output = '{}|===\n'.format(output)
+ output = "{}{} **{}**{}{}\n".format(
+ output, "\n.Mapping table - ", value, "\n|===\n|", value
+ )
+ for mapped in m[value]["values"]:
+ output = "{}|{}\n".format(output, mapped)
+ output = "{}|===\n".format(output)
doc = doc + output
if args.a:
From 5f580a3bb5aec4341787719b4ded294c1bd9321a Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Mon, 4 Mar 2024 10:10:41 +0100
Subject: [PATCH 180/181] chg: [MANIFEST] updated
---
MANIFEST.json | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/MANIFEST.json b/MANIFEST.json
index 74fa77f..129688d 100644
--- a/MANIFEST.json
+++ b/MANIFEST.json
@@ -121,7 +121,7 @@
{
"description": "A Course Of Action analysis considers six potential courses of action for the development of a cyber security capability.",
"name": "course-of-action",
- "version": 2
+ "version": 3
},
{
"description": "Crowdsec IP address classifications and behaviors taxonomy.",
@@ -176,7 +176,7 @@
{
"description": "Criminal motivation and content detection the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project and extended by the JRC (Joint Research Centre) of the European Commission.",
"name": "dark-web",
- "version": 5
+ "version": 6
},
{
"description": "Data classification for data potentially at risk of exfiltration based on table 2.1 of Solving Cyber Risk book.",
@@ -306,7 +306,7 @@
{
"description": "Exercise is a taxonomy to describe if the information is part of one or more cyber or crisis exercise.",
"name": "exercise",
- "version": 10
+ "version": 11
},
{
"description": "Reasons why an event has been extended. This taxonomy must be used on the extended event. The competitive analysis aspect is from Psychology of Intelligence Analysis by Richard J. Heuer, Jr. ref:http://www.foo.be/docs/intelligence/PsychofIntelNew.pdf",
@@ -755,5 +755,5 @@
}
],
"url": "https://raw.githubusercontent.com/MISP/misp-taxonomies/main/",
- "version": "20231231"
+ "version": "20240304"
}
From 6f141c736c919b1c4d50b6b1775943f2dbe5c32f Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Wed, 13 Mar 2024 16:39:04 +0100
Subject: [PATCH 181/181] chg: [malware_classification] add `Stalkerware` from
#275
---
malware_classification/machinetag.json | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/malware_classification/machinetag.json b/malware_classification/machinetag.json
index 64919d1..5853130 100644
--- a/malware_classification/machinetag.json
+++ b/malware_classification/machinetag.json
@@ -1,7 +1,7 @@
{
"namespace": "malware_classification",
"description": "Classification based on different categories. Based on https://www.sans.org/reading-room/whitepapers/incident/malware-101-viruses-32848",
- "version": 2,
+ "version": 3,
"predicates": [
{
"value": "malware-category",
@@ -52,6 +52,10 @@
"value": "Adware",
"expanded": "Adware"
},
+ {
+ "value": "Stalkerware",
+ "expanded": "Stalkerware"
+ },
{
"value": "Spyware",
"expanded": "Spyware"