|
146 | 146 | ".highlight .vm { color: #19177C } /* Name.Variable.Magic */\n", |
147 | 147 | ".highlight .il { color: #666666 } /* Literal.Number.Integer.Long */</style><div class=\"highlight\"><pre><span></span><span class=\"p\">{</span>\n", |
148 | 148 | " <span class=\"nt\">"type"</span><span class=\"p\">:</span> <span class=\"s2\">"indicator"</span><span class=\"p\">,</span>\n", |
149 | | - " <span class=\"nt\">"id"</span><span class=\"p\">:</span> <span class=\"s2\">"indicator--409a0b15-1108-4251-8aee-a08995976561"</span><span class=\"p\">,</span>\n", |
150 | | - " <span class=\"nt\">"created"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-10-04T14:42:54.685Z"</span><span class=\"p\">,</span>\n", |
151 | | - " <span class=\"nt\">"modified"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-10-04T14:42:54.685Z"</span><span class=\"p\">,</span>\n", |
| 149 | + " <span class=\"nt\">"id"</span><span class=\"p\">:</span> <span class=\"s2\">"indicator--65ff0082-bb92-4812-9b74-b144b858297f"</span><span class=\"p\">,</span>\n", |
| 150 | + " <span class=\"nt\">"created"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-11-13T14:42:14.641Z"</span><span class=\"p\">,</span>\n", |
| 151 | + " <span class=\"nt\">"modified"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-11-13T14:42:14.641Z"</span><span class=\"p\">,</span>\n", |
| 152 | + " <span class=\"nt\">"pattern"</span><span class=\"p\">:</span> <span class=\"s2\">"[file:hashes.md5 = 'd41d8cd98f00b204e9800998ecf8427e']"</span><span class=\"p\">,</span>\n", |
| 153 | + " <span class=\"nt\">"valid_from"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-11-13T14:42:14.641818Z"</span><span class=\"p\">,</span>\n", |
152 | 154 | " <span class=\"nt\">"labels"</span><span class=\"p\">:</span> <span class=\"p\">[</span>\n", |
153 | 155 | " <span class=\"s2\">"malicious-activity"</span>\n", |
154 | 156 | " <span class=\"p\">],</span>\n", |
155 | | - " <span class=\"nt\">"pattern"</span><span class=\"p\">:</span> <span class=\"s2\">"[file:hashes.md5 = 'd41d8cd98f00b204e9800998ecf8427e']"</span><span class=\"p\">,</span>\n", |
156 | | - " <span class=\"nt\">"valid_from"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-10-04T14:42:54.685184Z"</span><span class=\"p\">,</span>\n", |
157 | 157 | " <span class=\"nt\">"object_marking_refs"</span><span class=\"p\">:</span> <span class=\"p\">[</span>\n", |
158 | 158 | " <span class=\"s2\">"marking-definition--f88d31f6-486f-44da-b317-01333bde0b82"</span>\n", |
159 | 159 | " <span class=\"p\">]</span>\n", |
|
187 | 187 | }, |
188 | 188 | { |
189 | 189 | "cell_type": "code", |
190 | | - "execution_count": 4, |
| 190 | + "execution_count": 7, |
191 | 191 | "metadata": {}, |
192 | 192 | "outputs": [ |
193 | 193 | { |
|
263 | 263 | ".highlight .vm { color: #19177C } /* Name.Variable.Magic */\n", |
264 | 264 | ".highlight .il { color: #666666 } /* Literal.Number.Integer.Long */</style><div class=\"highlight\"><pre><span></span><span class=\"p\">{</span>\n", |
265 | 265 | " <span class=\"nt\">"type"</span><span class=\"p\">:</span> <span class=\"s2\">"marking-definition"</span><span class=\"p\">,</span>\n", |
266 | | - " <span class=\"nt\">"id"</span><span class=\"p\">:</span> <span class=\"s2\">"marking-definition--030bb5c6-c5eb-4e9c-8e7a-b9aab08ded53"</span><span class=\"p\">,</span>\n", |
267 | | - " <span class=\"nt\">"created"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-10-04T14:43:04.090873Z"</span><span class=\"p\">,</span>\n", |
| 266 | + " <span class=\"nt\">"id"</span><span class=\"p\">:</span> <span class=\"s2\">"marking-definition--d16f0975-c5dd-4b25-a41d-af4afcc5da92"</span><span class=\"p\">,</span>\n", |
| 267 | + " <span class=\"nt\">"created"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-11-13T14:43:30.558058Z"</span><span class=\"p\">,</span>\n", |
268 | 268 | " <span class=\"nt\">"definition_type"</span><span class=\"p\">:</span> <span class=\"s2\">"statement"</span><span class=\"p\">,</span>\n", |
269 | 269 | " <span class=\"nt\">"definition"</span><span class=\"p\">:</span> <span class=\"p\">{</span>\n", |
270 | 270 | " <span class=\"nt\">"statement"</span><span class=\"p\">:</span> <span class=\"s2\">"Copyright 2017, Example Corp"</span>\n", |
|
276 | 276 | "<IPython.core.display.HTML object>" |
277 | 277 | ] |
278 | 278 | }, |
279 | | - "execution_count": 4, |
| 279 | + "execution_count": 7, |
280 | 280 | "metadata": {}, |
281 | 281 | "output_type": "execute_result" |
282 | 282 | } |
|
523 | 523 | }, |
524 | 524 | { |
525 | 525 | "cell_type": "code", |
526 | | - "execution_count": 7, |
| 526 | + "execution_count": 8, |
527 | 527 | "metadata": {}, |
528 | 528 | "outputs": [ |
529 | 529 | { |
|
599 | 599 | ".highlight .vm { color: #19177C } /* Name.Variable.Magic */\n", |
600 | 600 | ".highlight .il { color: #666666 } /* Literal.Number.Integer.Long */</style><div class=\"highlight\"><pre><span></span><span class=\"p\">{</span>\n", |
601 | 601 | " <span class=\"nt\">"type"</span><span class=\"p\">:</span> <span class=\"s2\">"malware"</span><span class=\"p\">,</span>\n", |
602 | | - " <span class=\"nt\">"id"</span><span class=\"p\">:</span> <span class=\"s2\">"malware--9f8970eb-b398-41b6-b8c8-8a607ad3a2c5"</span><span class=\"p\">,</span>\n", |
603 | | - " <span class=\"nt\">"created"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-10-04T14:43:26.129Z"</span><span class=\"p\">,</span>\n", |
604 | | - " <span class=\"nt\">"modified"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-10-04T14:43:26.129Z"</span><span class=\"p\">,</span>\n", |
| 602 | + " <span class=\"nt\">"id"</span><span class=\"p\">:</span> <span class=\"s2\">"malware--f7128008-f6ab-4d43-a8a2-a681651268f8"</span><span class=\"p\">,</span>\n", |
| 603 | + " <span class=\"nt\">"created"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-11-13T14:43:34.857Z"</span><span class=\"p\">,</span>\n", |
| 604 | + " <span class=\"nt\">"modified"</span><span class=\"p\">:</span> <span class=\"s2\">"2017-11-13T14:43:34.857Z"</span><span class=\"p\">,</span>\n", |
605 | 605 | " <span class=\"nt\">"name"</span><span class=\"p\">:</span> <span class=\"s2\">"Poison Ivy"</span><span class=\"p\">,</span>\n", |
606 | 606 | " <span class=\"nt\">"description"</span><span class=\"p\">:</span> <span class=\"s2\">"A ransomware related to ..."</span><span class=\"p\">,</span>\n", |
607 | 607 | " <span class=\"nt\">"labels"</span><span class=\"p\">:</span> <span class=\"p\">[</span>\n", |
608 | 608 | " <span class=\"s2\">"remote-access-trojan"</span>\n", |
609 | 609 | " <span class=\"p\">],</span>\n", |
610 | 610 | " <span class=\"nt\">"granular_markings"</span><span class=\"p\">:</span> <span class=\"p\">[</span>\n", |
611 | 611 | " <span class=\"p\">{</span>\n", |
612 | | - " <span class=\"nt\">"marking_ref"</span><span class=\"p\">:</span> <span class=\"s2\">"marking-definition--030bb5c6-c5eb-4e9c-8e7a-b9aab08ded53"</span><span class=\"p\">,</span>\n", |
| 612 | + " <span class=\"nt\">"marking_ref"</span><span class=\"p\">:</span> <span class=\"s2\">"marking-definition--d16f0975-c5dd-4b25-a41d-af4afcc5da92"</span><span class=\"p\">,</span>\n", |
613 | 613 | " <span class=\"nt\">"selectors"</span><span class=\"p\">:</span> <span class=\"p\">[</span>\n", |
614 | 614 | " <span class=\"s2\">"description"</span>\n", |
615 | 615 | " <span class=\"p\">]</span>\n", |
|
628 | 628 | "<IPython.core.display.HTML object>" |
629 | 629 | ] |
630 | 630 | }, |
631 | | - "execution_count": 7, |
| 631 | + "execution_count": 8, |
632 | 632 | "metadata": {}, |
633 | 633 | "output_type": "execute_result" |
634 | 634 | } |
|
1195 | 1195 | }, |
1196 | 1196 | { |
1197 | 1197 | "cell_type": "code", |
1198 | | - "execution_count": 20, |
| 1198 | + "execution_count": 9, |
1199 | 1199 | "metadata": {}, |
1200 | 1200 | "outputs": [ |
1201 | 1201 | { |
|
1204 | 1204 | "['marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9']" |
1205 | 1205 | ] |
1206 | 1206 | }, |
1207 | | - "execution_count": 20, |
| 1207 | + "execution_count": 9, |
1208 | 1208 | "metadata": {}, |
1209 | 1209 | "output_type": "execute_result" |
1210 | 1210 | } |
1211 | 1211 | ], |
1212 | 1212 | "source": [ |
1213 | | - "malware.get_markings('name')" |
| 1213 | + "from stix2 import get_markings\n", |
| 1214 | + "\n", |
| 1215 | + "get_markings(malware, 'name')" |
1214 | 1216 | ] |
1215 | 1217 | }, |
1216 | 1218 | { |
|
0 commit comments