OpenIOC.org has several schemas defining Indicators of Compromise. The Schema is defined here:
http://schemas.mandiant.com/2010/ioc/ioc.xsd
While under IndicatorItemContext/search
says it is xs:string
, the actual list of search terms is listed here:
http://openioc.org/terms/Current.iocterms
Is there something similar for IndicatorItem/condition
?
So far I'm only aware of "contains"
and "is"
but there doesn't seem to be a definitive list.