SPARK Version 1.17.0 adds extensive STIXv2 support.

This allows you to easily extend SPARK’s signature bases with IOCs from any sandbox, analysis or threat intel platforms that support STIXv2 export by placing the exported [cci]*.json[/cci] files in the [cci]./custom-signatures[/cci] folder.

For now, the supported observable object types are:

  • [cci]file:name[/cci] with [cci]=[/cci] [cci]!=[/cci] [cci]LIKE[/cci] and [cci]MATCHES[/cci]
  • [cci]file:parent_directory_ref.path[/cci] with [cci]=[/cci] [cci]!=[/cci] [cci]LIKE[/cci] and [cci]MATCHES[/cci]
  • [cci]file:hashes.sha-256[/cci] / [cci]file:hashes.sha256[/cci] with [cci]=[/cci] and [cci]!=[/cci]
  • [cci]file:hashes.sha-1[/cci] / [cci]file:hashes.sha1[/cci] with [cci]=[/cci] and [cci]!=[/cci]
  • [cci]file:hashes.md-5[/cci] / [cci]file:hashes.md5[/cci] with [cci]=[/cci] and [cci]!=[/cci]
  • [cci]file:size[/cci] with [cci]<[/cci] [cci]<=[/cci] [cci]>[/cci] [cci]>=[/cci] [cci]=[/cci] [cci]!=[/cci]
  • [cci]file:created[/cci] with [cci]<[/cci] [cci]<=[/cci] [cci]>[/cci] [cci]>=[/cci] [cci]=[/cci] [cci]!=[/cci]
  • [cci]file:modified[/cci] with [cci]<[/cci] [cci]<=[/cci] [cci]>[/cci] [cci]>=[/cci] [cci]=[/cci] [cci]!=[/cci]
  • [cci]file:accessed[/cci] with [cci]<[/cci] [cci]<=[/cci] [cci]>[/cci] [cci]>=[/cci] [cci]=[/cci] [cci]!=[/cci]
  • [cci]win-registry-key:key[/cci] with [cci]=[/cci] [cci]!=[/cci] [cci]LIKE[/cci] and [cci]MATCHES[/cci]
  • [cci]win-registry-key:values.name[/cci] with [cci]=[/cci] [cci]!=[/cci] [cci]LIKE[/cci] and [cci]MATCHES[/cci]
  • [cci]win-registry-key:values.data[/cci] with [cci]=[/cci] [cci]!=[/cci] [cci]LIKE[/cci] and [cci]MATCHES[/cci]
  • [cci]win-registry-key:values.modified_time[/cci] with [cci]<[/cci] [cci]<=[/cci] [cci]>[/cci] [cci]>=[/cci] [cci]=[/cci] [cci]!=[/cci]

These types are applied in different modules:

  • FileScan: [cci]file:*[/cci]
  • Registry: [cci]win-registry-key:*[/cci] and [cci]file:name[/cci] (applied to data field)
You can find a list of products that support the STIX data exchange format here.
WordPress Cookie Plugin by Real Cookie Banner