Supported Attributes for STIX Entities
You can use this page to reference supported attributes for each STIX threat model entity available in ThreatStream.
Supported Attributes for Actors (Threat Actors)
| STIX 1.2 | STIX 2.0 | STIX 2.1 |
|---|---|---|
| Title | name (required) | name (required) |
| Description | description | description |
| Short_Description | created | created |
| Type | modified | modified |
|
Sophistication |
labels (required) Note: If Threat Actor Types is not set in ThreatStream, STIX 2.0 exports will fail. |
threat_actor_types (required) Note: If Threat Actor Types is not set in ThreatStream, STIX 2.1 exports will fail. |
| Motivation | aliases | aliases |
|
|
roles | roles |
| goals | goals | |
| resource_level | resource_level | |
| primary_motivation | primary_motivation | |
| secondary_motivations | secondary_motivations | |
| personal_motivations | personal_motivations | |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) | |
|
Associations:
|
Relationships:
|
Relationships:
|
Supported Attributes for Attack Patterns
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
| kill_chain_phases | kill_chain_phases |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) |
|
|
aliases |
|
Relationships:
|
Relationships:
|
Supported Attributes for Campaigns
| STIX 1.2 | STIX 2.0 | STIX 2.1 |
|---|---|---|
| Title | name (required) | name (required) |
| Description | description | description |
| Short_Description | created | created |
| Status | modified | modified |
| Intended_Effect | aliases | aliases |
| first_seen | first_seen | |
| last_seen | last_seen | |
| objective | objective | |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) | |
|
Associations:
|
Relationships:
|
Relationships:
|
Supported Attributes for Courses of Action
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) |
| os_execution_envs | |
|
Relationships:
|
Relationships:
|
Supported Attributes for Identities
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
| labels | labels |
|
identity_class (required) Note: If Identity Class is not set in ThreatStream, STIX 2.0 exports will fail. |
identity_class |
| sectors | sectors |
| contact_information | contact_information |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) |
| roles |
Supported Attributes for Indicators
| STIX 1.2 | STIX 2.0 | STIX 2.1 |
|---|---|---|
| Title | created | created |
| Description | modified | modified |
| Observable | name | name |
| Type | description | description |
| Handling (TLP) | pattern (required) | pattern (required) |
| Confidence | valid_from (required) | valid_from (required) |
| Producer | valid_until | valid_until |
|
Cybox:Keywords Note: Tags associated with observables in ThreatStream are exported as Cybox:Keywords. Exports can include up to 250 tags for an observable. |
object_marking_refs (TLP) | object_marking_refs (TLP) |
| pattern_type (required) | pattern_type (required) | |
| labels (required) |
labels Note: Tags associated with observables in ThreatStream are exported and imported as labels. When importing, there is no limit on the number of tags for an observable. However, exports can include up to 250 tags for an observable. |
|
| confidence | ||
| indicator_types |
Supported Attributes for Incidents
| STIX 1.2 | STIX 2.1 |
|---|---|
| Title | name (required) |
| Description | description (optional) |
| Status | type |
| Intended_Effect | spec_version |
|
Relationships:
|
id |
| created | |
| modified |
Supported Attributes for Infrastructure
| STIX 2.1 |
|---|
| name (required) |
| description |
| created |
| modified |
| infrastructure_types |
| aliases |
| kill_chain_phases |
| first_seen |
| last_seen |
|
Relationships:
|
Supported Attributes for Intrusion Sets
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
| aliases | aliases |
| first_seen | first_seen |
| last_seen | last_seen |
| goals | goals |
| resource_level | resource_level |
| primary_motivation | primary_motivation |
| secondary_motivations | secondary_motivations |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) |
|
Relationships:
|
Relationships:
|
Supported Attributes for Malware
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
|
labels (required) Note: If Malware Type is not set in ThreatStream, STIX 2.0 exports will fail. |
malware_types |
| kill_chain_phases | kill_chain_phases |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) |
| is_family (required) | |
| aliases | |
| kill_chain_phases | |
| execution_platforms | |
| first_seen | |
| last_seen | |
| implementation_languages | |
| capabilities | |
|
Relationships:
|
Relationships:
|
Supported Attributes for Notes
| STIX 2.1 |
|---|
| abstract |
| confidence |
| content |
| created |
| modified |
| object_refs |
| object_marking_refs |
Supported Attributes for Threat Bulletins (Reports)
| STIX 1.2 | STIX 2.0 | STIX 2.1 |
|---|---|---|
| Title | name (required) | name (required) |
| Timestamps | description | description |
| TLP | created | created |
| Body | modified | modified |
| Tags | labels | labels |
| Intelligence Source | published | published |
| object_refs | object_refs | |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) | |
|
Associations:
|
Supported Attributes for Tools
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
|
labels (required) If Tool Types is not set in ThreatStream, STIX 2.0 exports will fail.
|
tool_types |
| kill_chain_phases | kill_chain_phases |
| tool_version | tool_version |
| external_references | external_references |
| aliases | |
|
Relationships:
|
Relationships:
|
Supported Attributes for TTPs
| STIX 1.2 |
|---|
| Title |
| Description |
| Short_Description |
|
Behavior > Attack_Patterns > Attack_Pattern > Title, Description |
| Behavior > Malware > Malware_Instance > Type, Title, Description |
| Behavior > Exploits > Exploit > Title, Description |
| Kill_Chain_Phases |
If a CAPEC TTP or a Threat Model entity associated with that TTP
When an XML file containing a TTP with the "Behavior > Attack_Patterns > Attack_Pattern> capec_id" attribute is imported, the TTP content in the XML file is not copied because it refers to an existing CAPEC on ThreatStream. Instead, the references to the TTP are updated to point to the existing CAPEC on ThreatStream.
Supported Attributes for Vulnerabilities
| STIX 2.0 | STIX 2.1 |
|---|---|
| name (required) | name (required) |
| description | description |
| created | created |
| modified | modified |
| external_references (Only URLs are included in exports) | external_references (Only URLs are included in exports) |