← Prev in month
← Prev in thread
Next in thread →
Next in month →
Changes to section 4.6 - Indicator
The editors changed the text, related to the pattern property of the Indicator, to address concerns discussed in emails and working calls. Please review this new text and respond if you have additional concerns. Rich pattern (required) string The detection pattern for this Indicator MAY be expressed as a STIX Pattern as specified in section 9 or another appropriate language such as SNORT, YARA, etc. pattern_type (required) open-vocab The pattern language used in this indicator. The value for this property SHOULD come from the pattern-type-ov open vocabulary.. The value of this property MUST match the type of pattern data included in the pattern property. pattern_version (optional) string The version of the pattern language that is used for the data in the pattern property which MUST match the type of pattern data included in the pattern property. For patterns that do not have a formal specification, the build or code version that the pattern is known to work with SHOULD be used. For the STIX Pattern language the default value is inferred from the specification version of the object. For other languages, the default value SHOULD be the latest version of the patterning language at the time of this object's creation.
← Prev in month
← Prev in thread
Next in thread →
Next in month →