STIX 2 Relationship Objects

Modified on: Wed, 5 May, 2021 at 1:58 AM

STIX2 Sighting

Entity Meta

InformationValue
Display NameSTIX2 Sighting
Entity Namemaltego.STIX2.sighting
Short DescriptionA Sighting denotes the belief that something in CTI (e.g., an indicator, malware, tool, threat actor, etc.) was seen.
Entity CategorySTIX 2 relationship objects
Base Entitiesmaltego.STIX2.core


Entity Properties

Display NameProperty NameData TypeShort DescriptionSample Value
typetypestringThe type of this object, which MUST be the literal sighting.sighting
s pec_versions pec_versionstringThe version of the STIX sp ecification used to represent this object. 
ididstring  
cre ated_by_refcre ated_by_refstringThe ID of the Source object that describes who created this object. 
labelslabelsstring[]The labels property specifies a set of terms used to describe this object. 
createdcreatedstringThe created property represents the time at which the first version of this object was created. The timstamp value MUST be precise to the nearest m illisecond. 
modifiedmodifiedstringThe modified property represents the time that this particular version of the object was modified. The timstamp value MUST be precise to the nearest m illisecond. 
revokedrevokedstringThe revoked property indicates whether the object has been revoked. 
confidenceconfidencestringIdentifies the confidence that the creator has in the correctness of their data. 
langlangstringIdentifies the language of the text content in this object. 
external _referencesexternal _referencesstring[]A list of external references which refers to non-STIX i nformation. 
object_m arking_refsobject_m arking_refsstring[]The list of marking -definition objects to be applied to this object. 
granul ar_markingsgranul ar_markingsstring[]The set of granular markings that apply to this object. 
descriptiondescriptionstringA description that provides more details and context about the Sighting. 
first_seenfirst_seenstringThe beginning of the time window during which the SDO referenced by the sigh ting_of_ref property was sighted. 
last_seenlast_seenstringThe end of the time window during which the SDO referenced by the sigh ting_of_ref property was sighted. 
countcountstringThis is an integer between 0 and 999,999,999 inclusive and represents the number of times the object was sighted. 
sigh ting_of_refsigh ting_of_refstringAn ID reference to the object that has been sighted. 
observe d_data_refsobserve d_data_refsstring[]A list of ID references to the Observed Data objects that contain the raw cyber data for this Sighting. 
where_s ighted_refswhere_s ighted_refsstring[]A list of ID references to the Identity or Location objects describing the entities or types of entities that saw the sighting. 
summarysummarystringThe summary property indicates whether the Sighting should be considered summary data. 
rec overy_prope rty_mappingrec overy_prope rty_mappingstringThe mapping of Maltego internal property names to STIX property names used for this entity.{}


Entity Description

A Sighting denotes the belief that something in CTI (e.g., an indicator, malware, tool, threat actor, etc.) was seen.


STIX2 Relationship

Entity Meta

InformationValue
Display NameSTIX2 Relationship
Entity Namemaltego.STIX2.relationship
Short DescriptionThe Relationship object is used to link together two SDOs in order to describe how they are related to each other.
Entity CategorySTIX 2 relationship objects
Base Entitiesmaltego.STIX2.core


Entity Properties

Display NameProperty NameData TypeShort DescriptionSample Value
typetypestringThe type of this object, which MUST be the literal rela tionship.r elationship
s pec_versions pec_versionstringThe version of the STIX sp ecification used to represent this object. 
ididstring  
cre ated_by_refcre ated_by_refstringThe ID of the Source object that describes who created this object. 
labelslabelsstring[]The labels property specifies a set of terms used to describe this object. 
createdcreatedstringThe created property represents the time at which the first version of this object was created. The timstamp value MUST be precise to the nearest m illisecond. 
modifiedmodifiedstringThe modified property represents the time that this particular version of the object was modified. The timstamp value MUST be precise to the nearest m illisecond. 
revokedrevokedstringThe revoked property indicates whether the object has been revoked. 
confidenceconfidencestringIdentifies the confidence that the creator has in the correctness of their data. 
langlangstringIdentifies the language of the text content in this object. 
external _referencesexternal _referencesstring[]A list of external references which refers to non-STIX i nformation. 
object_m arking_refsobject_m arking_refsstring[]The list of marking -definition objects to be applied to this object. 
granul ar_markingsgranul ar_markingsstring[]The set of granular markings that apply to this object. 
relati onship_typerelati onship_typestringThe name used to identify the type of re lationship. 
descriptiondescriptionstringA description that helps provide context about the re lationship. 
source_refsource_refstringThe ID of the source (from) object. 
target_reftarget_refstringThe ID of the target (to) object. 
start_timestart_timestringThis optional timestamp represents the earliest time at which the R elationship between the objects exists. If this property is a future timestamp, at the time the updated property is defined, then this represents an estimate by the producer of the i ntelligence of the earliest time at which r elationship will be asserted to be true. 
stop_timestop_timestringThe latest time at which the R elationship between the objects exists. If this property is a future timestamp, at the time the updated property is defined, then this represents an estimate by the producer of the i ntelligence of the latest time at which r elationship will be asserted to be true. 
rec overy_prope rty_mappingrec overy_prope rty_mappingstringThe mapping of Maltego internal property names to STIX property names used for this entity.{}


Entity Description

The Relationship object is used to link together two SDOs in order to describe how they are related to each other.

 

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.