<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="iodef2.xsl"?>
<?xml-model href="iodef2.rng" schematypens="http://relaxng.org/ns/structure/1.0" ?>
<registry xmlns="http://www.iana.org/assignments" id="iodef2">
  <title>Incident Object Description Exchange Format v2 (IODEF)</title>
  <created>2016-08-16</created>
  <updated>2016-12-01</updated>

  <registry id="restriction">
    <title>Restriction</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>public</value>
      <description>The information can be freely distributed without
        restriction.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>partner</value>
      <description>The information may be shared within a closed
        community of peers, partners, or affected parties, but cannot be
        openly published.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>need-to-know</value>
      <description>The information may be shared only within the
        organization with individuals that have a need to know.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>private</value>
      <description>The information may not be shared.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>default</value>
      <description>The information can be shared according to an
        information disclosure policy pre-arranged by the communicating
        parties.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>white</value>
      <description>Same as 'public'.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>green</value>
      <description>Same as 'partner'.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>amber</value>
      <description>Same as 'need-to-know'.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>red</value>
      <description>Same as 'private'.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="incident-purpose">
    <title>Incident-purpose</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>traceback</value>
      <description>The incident was sent for trace-back purposes.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mitigation</value>
      <description>The incident was sent to request aid in
        mitigating the described activity.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>reporting</value>
      <description>The incident was sent to comply with reporting
        requirements.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>watch</value>
      <description>The incident was sent to convey indicators that should
        be monitored.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>other</value>
      <description>The incident was sent for purposes specified in the
        Expectation class.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="incident-status">
    <title>Incident-status</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>new</value>
      <description>The incident is newly reported, and no action has
        been taken.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>in-progress</value>
      <description>The contents of this incident are under
        investigation.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>forwarded</value>
      <description>The incident has been forwarded to another party
        for handling.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>resolved</value>
      <description>The investigation into the activity in this
        incident has concluded.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>future</value>
      <description>The described activity has not yet been detected.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="contact-role">
    <title>Contact-role</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>creator</value>
      <description>The entity that generates the document.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>reporter</value>
      <description>The entity that reported the information.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>admin</value>
      <description>An administrative contact or business owner for an
        asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>tech</value>
      <description>An entity responsible for the day-to-day management of
        technical issues for an asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>provider</value>
      <description>An external hosting provider for an asset.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>user</value>
      <description>An end-user of an asset or part of an organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>billing</value>
      <description>An entity responsible for billing issues for an
        asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>legal</value>
      <description>An entity responsible for legal issues related to an
        asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>irt</value>
      <description>An entity responsible for handling security issues for
        an asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>abuse</value>
      <description>An entity responsible for handling abuse originating
        from an asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>cc</value>
      <description>An entity that is to be kept informed about the events
        related to an asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>cc-irt</value>
      <description>A CSIRT or information-sharing organization
        coordinating activity related to an asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>leo</value>
      <description>A law enforcement organization supporting the
        investigation of activity affecting an asset or organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>vendor</value>
      <description>The vendor that produces an asset.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>vendor-support</value>
      <description>A vendor that provides services.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>victim</value>
      <description>A victim in the incident.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>victim-notified</value>
      <description>A victim in the incident who has been
        notified.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="contact-type">
    <title>Contact-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>person</value>
      <description>The information for this contact references an
        individual.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>organization</value>
      <description>The information for this contact references an
        organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="registryhandle-registry">
    <title>RegistryHandle-registry</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>internic</value>
      <description>Internet Network Information Center</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>apnic</value>
      <description>Asia Pacific Network Information Center</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>arin</value>
      <description>American Registry for Internet Numbers</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>lacnic</value>
      <description>Latin-American and Caribbean Internet Addresses Registry</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ripe</value>
      <description>Reseaux IP Europeens</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>afrinic</value>
      <description>African Network Information Center</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>local</value>
      <description>A database local to the CSIRT</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="postalAddress-type">
    <title>PostalAddress-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>street</value>
      <description>An address describing a physical location.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mailing</value>
      <description>An address to which correspondence should be sent.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="telephone-type">
    <title>Telephone-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>wired</value>
      <description>A number of a wire-line (land-line) phone.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mobile</value>
      <description>A number of a mobile phone.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>fax</value>
      <description>A number to a fax machine.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>hotline</value>
      <description>A number to a regularly monitored operational
        hotline.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="email-type">
    <title>Email-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>direct</value>
      <description>An email address of an individual.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>hotline</value>
      <description>An email address regularly monitored for operational
        purposes.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="expectation-action">
    <title>Expectation-action</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>nothing</value>
      <description>No action is requested.  Do nothing with the
        information.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>contact-source-site</value>
      <description>Contact the site(s) identified as the
        source of the activity.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>contact-target-site</value>
      <description>Contact the site(s) identified as the
        target of the activity.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>contact-sender</value>
      <description>Contact the originator of the document.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>investigate</value>
      <description>Investigate the system(s) listed in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>block-host</value>
      <description>Block traffic from the machine(s) listed as
        sources in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>block-network</value>
      <description>Block traffic from the network(s) lists as
        sources in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>block-port</value>
      <description>Block the port listed as sources in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>rate-limit-host</value>
      <description>Rate-limit the traffic from the machine(s)
        listed as sources in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>rate-limit-network</value>
      <description>Rate-limit the traffic from the
        network(s) listed as sources in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>rate-limit-port</value>
      <description>Rate-limit the port(s) listed as sources in
        the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>redirect-traffic</value>
      <description>Redirect traffic from the intended
        recipient for further analysis.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>honeypot</value>
      <description>Redirect traffic from systems listed in the event
        to a honeypot for further analysis.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>upgrade-software</value>
      <description>Upgrade or patch the software or firmware
        on an asset listed in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>rebuild-asset</value>
      <description>Reinstall the operating system or
        applications on an asset listed in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>harden-asset</value>
      <description>Change the configuration of an asset listed in
        the event to reduce the attack surface.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>remediate-other</value>
      <description>Remediate the activity in a way other than
        by rate limiting or blocking.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>status-triage</value>
      <description>Confirm receipt and begin triaging the
        incident.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>status-new-info</value>
      <description>Notify the sender when new information is
        received for this incident.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>watch-and-report</value>
      <description>Watch for the described activity or
        indicators, and notify the sender when seen.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>training</value>
      <description>Train user to identify or mitigate the described
        threat.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>defined-coa</value>
      <description>Perform a predefined course of action (COA).
        The COA is named in the DefinedCOA class.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>other</value>
      <description>Perform a custom action described in the Description
        class.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="discovery-source">
    <title>Discovery-source</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>nidps</value>
      <description>Network Intrusion Detection or Prevention System.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>hips</value>
      <description>Host-based Intrusion Prevention System.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>siem</value>
      <description>Security Information and Event Management System.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>av</value>
      <description>Antivirus or antispam software.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>third-party-monitoring</value>
      <description>Contracted third-party monitoring
        service.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>incident</value>
      <description>The activity was discovered while investigating an
        unrelated incident.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>os-log</value>
      <description>Operating system logs.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>application-log</value>
      <description>Application logs.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>device-log</value>
      <description>Network device logs.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>network-flow</value>
      <description>Network flow analysis.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>passive-dns</value>
      <description>Passive DNS analysis.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>investigation</value>
      <description>Manual investigation initiated based on
        notification of a new vulnerability or exploit.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>audit</value>
      <description>Security audit.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>internal-notification</value>
      <description>A party within the organization
        reported the activity.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>external-notification</value>
      <description>A party outside of the organization
        reported the activity.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>leo</value>
      <description>A law enforcement organization notified the victim
        organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>partner</value>
      <description>A customer or business partner reported the
        activity to the victim organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>actor</value>
      <description>The threat actor directly or indirectly reported this
        activity to the victim organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>Unknown detection approach.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="systemimpact-type">
    <title>SystemImpact-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>takeover-account</value>
      <description>Control was taken of a given account.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>takeover-service</value>
      <description>Control was taken of a given service.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>takeover-system</value>
      <description>Control was taken of a given system.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>cps-manipulation</value>
      <description>A cyber-physical system was manipulated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>cps-damage</value>
      <description>A cyber-physical system was damaged.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>availability-data</value>
      <description>Access to particular data was degraded or
        denied.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>availability-account</value>
      <description>Access to an account was degraded or
        denied.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>availability-service</value>
      <description>Access to a service was degraded or
        denied.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>availability-system</value>
      <description>Access to a system was degraded or
        denied.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>damaged-system</value>
      <description>Hardware on a system was irreparably
        damaged.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>damaged-data</value>
      <description>Data on a system was deleted.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>breach-propietary</value>
      <description>Sensitive or proprietary information was
        accessed or exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>breach-privacy</value>
      <description>Personally identifiable information was
        accessed or exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>breach-credential</value>
      <description>Credential information was accessed or
        exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>breach-configuration</value>
      <description>System configuration or data inventory
        was access or exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>integrity-data</value>
      <description>Data on the system was modified.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>integrity-configuration</value>
      <description>Application or system configuration
        was modified.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>integrity-hardware</value>
      <description>Firmware of a hardware component was
        modified.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>traffic-redirection</value>
      <description>Network traffic on the system was
        redirected.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>monitoring-traffic</value>
      <description>Network traffic emerging from a host or
        enclave was monitored.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>monitoring-host</value>
      <description>System activity (e.g., running processes,
        keystrokes) were monitored.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>policy</value>
      <description>Activity violated the system owner's acceptable use
        policy.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>The impact is unknown.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
    
  <registry id="businessimpact-severity">
    <title>BusinessImpact-severity</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>none</value>
      <description>No effect to the organization's ability to provide all
        services to all users.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>low</value>
      <description>Minimal effect as the organization can still provide all
        critical services to all users but has lost efficiency.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>medium</value>
      <description>The organization has lost the ability to provide a
        critical service to a subset of system users.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>high</value>
      <description>The organization is no longer able to provide some
        critical services to any users.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>The impact is not known.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="businessimpact-type">
    <title>BusinessImpact-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>breach-proprietary</value>
      <description>Sensitive or proprietary information was
        accessed or exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>breach-privacy</value>
      <description>Personally identifiable information was
        accessed or exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>breach-credential</value>
      <description>Credential information was accessed or
        exfiltrated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>loss-of-integrity</value>
      <description>Sensitive or proprietary information was
        changed or deleted.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>loss-of-service</value>
      <description>Service delivery was disrupted.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>theft-financial</value>
      <description>Money was stolen.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>theft-service</value>
      <description>Services were misappropriated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>degraded-reputation</value>
      <description>The reputation of the organization's
        brand was diminished.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>asset-damage</value>
      <description>A cyber-physical system was damaged.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>asset-manipulation</value>
      <description>A cyber-physical system was manipulated.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>legal</value>
      <description>The incident resulted in legal or regulatory action.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>extortion</value>
      <description>The incident resulted in actors extorting the
        victim organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>The impact is unknown.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="timeimpact-metric">
    <title>TimeImpact-metric</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>labor</value>
      <description>Total staff time to recovery from the activity (e.g.,
        2 employees working 4 hours each would be 8 hours).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>elapsed</value>
      <description>Elapsed time from the beginning of the recovery to
        its completion (i.e., wall-clock time).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>downtime</value>
      <description>Duration of time for which some provided service(s)
        was not available.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="timeimpact-duration">
    <title>TimeImpact-duration</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>second</value>
      <description>The unit of the element content is seconds.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>minute</value>
      <description>The unit of the element content is minutes.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>hour</value>
      <description>The unit of the element content is hours.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>day</value>
      <description>The unit of the element content is days.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>month</value>
      <description>The unit of the element content is months.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>quarter</value>
      <description>The unit of the element content is quarters.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>year</value>
      <description>The unit of the element content is years.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="confidence-rating">
    <title>Confidence-rating</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>low</value>
      <description>Low confidence.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>medium</value>
      <description>Medium confidence.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>high</value>
      <description>High confidence.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>numeric</value>
      <description>The element content contains a number that conveys
        the confidence of the data.  The semantics of this number
        is outside the scope of this specification.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>The confidence rating value is not known.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="noderole-category">
    <title>NodeRole-category</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>client</value>
      <description>Client computer.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>client-enterprise</value>
      <description>Client computer on the enterprise
        network.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>client-partner</value>
      <description>Client computer on network of a partner.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>client-remote</value>
      <description>Client computer remotely connected to the
        enterprise network.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>client-kiosk</value>
      <description>Client computer serving as a kiosk.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>client-mobile</value>
      <description>Mobile device.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>server-internal</value>
      <description>Server with internal services.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>server-public</value>
      <description>Server with public services.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>www</value>
      <description>WWW server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mail</value>
      <description>Mail server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>webmail</value>
      <description>Web mail server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>messaging</value>
      <description>Messaging server (e.g., NNTP, IRC, IM).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>streaming</value>
      <description>Streaming-media server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>voice</value>
      <description>Voice server (e.g., SIP, H.323).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file</value>
      <description>File server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ftp</value>
      <description>FTP server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>p2p</value>
      <description>Peer-to-peer node.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>name</value>
      <description>Name server (e.g., DNS, WINS).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>directory</value>
      <description>Directory server (e.g., LDAP, finger, whois).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>credential</value>
      <description>Credential server (e.g., domain controller,
        Kerberos).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>print</value>
      <description>Print server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>application</value>
      <description>Application server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>database</value>
      <description>Database server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>backup</value>
      <description>Backup server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>dhcp</value>
      <description>DHCP server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>assessment</value>
      <description>Assessment server (e.g., vulnerability scanner,
        endpoint assessment).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>source-control</value>
      <description>Source code control server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>config-management</value>
      <description>Configuration management server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>monitoring</value>
      <description>Security monitoring server (e.g., IDS).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>infra</value>
      <description>Infrastructure server (e.g., router, firewall, DHCP).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>infra-firewall</value>
      <description>Firewall.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>infra-router</value>
      <description>Router.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>infra-switch</value>
      <description>Switch.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>camera</value>
      <description>Camera and video system.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>proxy</value>
      <description>Proxy server. </description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>remote-access</value>
      <description>Remote access server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>log</value>
      <description>Log server (e.g., syslog).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>virtualization</value>
      <description>Server running virtual machines.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>pos</value>
      <description>Point-of-sale device.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>scada</value>
      <description>Supervisory control and data acquisition (SCADA)
        system.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>scada-supervisory</value>
      <description>Supervisory system for a SCADA.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>sinkhole</value>
      <description>Traffic sinkhole destination.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>honeypot</value>
      <description>Honeypot server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>anonymization</value>
      <description>Anonymization server (e.g., Tor node).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>c2-server</value>
      <description>Malicious command and control server.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>malware-distribution</value>
      <description>Server that distributes malware.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>drop-server</value>
      <description>Server to which exfiltrated content is
        uploaded.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>hop-point</value>
      <description>Intermediary server used to get to a victim.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>reflector</value>
      <description>A system used in a reflector attack.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>phishing-site</value>
      <description>Site hosting phishing content.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>spear-phishing-site</value>
      <description>Site hosting spear-phishing content.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>recruiting-site</value>
      <description>Site to recruit.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>fraudulent-site</value>
      <description>Fraudulent site.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="system-category">
    <title>System-category</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>source</value>
      <description>The System was the source of the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>target</value>
      <description>The System was the target of the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>intermediate</value>
      <description>The System was an intermediary in the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>sensor</value>
      <description>The System was a sensor monitoring the event.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>infrastructure</value>
      <description>The System was an infrastructure node of the 
        IODEF document exchange.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="system-ownership">
    <title>System-ownership</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>organization</value>
      <description>Corporate or enterprise owned.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>personal</value>
      <description>Personally owned by an employee or affiliate of the
        corporation or enterprise.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>partner</value>
      <description>Owned by a partner of the corporation or enterprise.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>customer</value>
      <description>Owned by a customer of the corporation or
        enterprise.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>no-relationship</value>
      <description>Owned by an entity that has no known
        relationship with the victim organization.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>Ownership is unknown.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="address-category">
    <title>Address-category</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>asn</value>
      <description>Autonomous System Number.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>atm</value>
      <description>Asynchronous Transfer Mode (ATM) address.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>e-mail</value>
      <description>Email address, per the EMAIL data type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-addr</value>
      <description>IPv4 host address in dotted-decimal notation
        (i.e., a.b.c.d).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-net</value>
      <description>IPv4 network address in dotted-decimal notation,
        slash, significant bits (i.e., a.b.c.d/nn).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-net-masked</value>
      <description>A sanitized IPv4 address with significant
        bits per "ipv4-net" but with the character 'x' replacing any
        digit(s) in the address or prefix.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-net-mask</value>
      <description>IPv4 network address in dotted-decimal
        notation, slash, network mask in dotted-decimal notation
        (i.e., a.b.c.d/w.x.y.z).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-addr</value>
      <description>IPv6 host address per Section 4 of <xref type="rfc" data="rfc5952"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-net</value>
      <description>IPv6 network address, slash, prefix per
        Section 2.3 of <xref type="rfc" data="rfc4291"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-net-masked</value>
      <description>A sanitized IPv6 address and prefix per
        "ipv6-net" but with the character 'x' replacing any
        hexadecimal digit(s) in the address or digit(s) in the
        prefix.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mac</value>
      <description>Media Access Control (MAC) address (i.e.,
        aa:bb:cc:dd:ee:ff).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>site-uri</value>
      <description>A URL or URI for a resource, per the URL data
        type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="counter-type">
    <title>Counter-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>count</value>
      <description>The Counter class value is a counter.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>peak</value>
      <description>The Counter class value is a peak value.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>average</value>
      <description>The Counter class value is an average.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="counter-unit">
    <title>Counter-unit</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>byte</value>
      <description>Bytes transferred.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mbit</value>
      <description>Megabits (Mbits) transferred.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>packet</value>
      <description>Packets.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>flow</value>
      <description>Network flow records.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>session</value>
      <description>Sessions.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>alert</value>
      <description>Notifications generated by another system (e.g., IDS
        or SIEM system).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>message</value>
      <description>Messages (e.g., mail messages).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>event</value>
      <description>Events.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>host</value>
      <description>Hosts.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>site</value>
      <description>Site.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>organization</value>
      <description>Organizations.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="domaindata-system-status">
    <title>DomainData-system-status</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>spoofed</value>
      <description>This domain was spoofed.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>fraudulent</value>
      <description>This domain was operated with fraudulent
        intentions.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>innocent-hacked</value>
      <description>This domain was compromised by a third
        party.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>innocent-hijacked</value>
      <description>This domain was deliberately hijacked.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>No categorization for this domain known.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="domaindata-domain-status">
    <title>DomainData-domain-status</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>reservedDelegation</value>
      <description>The domain is permanently inactive.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>assignedAndActive</value>
      <description>The domain is in a normal state.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>assignedAndInactive</value>
      <description>The domain has an assigned registration, 
        but the delegation is inactive.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>assignedAndOnHold</value>
      <description>The domain is in dispute.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>revoked</value>
      <description>The domain is in the process of being purged from
        the database.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>transferPending</value>
      <description>The domain is pending a change in
        authority.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>registryLock</value>
      <description>The domain is on hold by the registry.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>registrarLock</value>
      <description>Same as "registryLock".</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>other</value>
      <description>The domain has a known status, but it is not one of
        the redefined enumerated values.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>unknown</value>
      <description>The domain has an unknown status.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="recordpattern-type">
    <title>RecordPattern-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>regex</value>
      <description>Regular expression as defined by POSIX Extended
        Regular Expressions (ERE) in Chapter 9 of "Information Technology - Portable Operating System
        Interface (POSIX) - Part 1: Base Definitions",
        IEEE 1003.1, June 2001.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>binary</value>
      <description>Binhex-encoded binary pattern, per the HEXBIN data
        type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>xpath</value>
      <description>XML Path (XPath) <xref type="uri" data="https://www.w3.org/TR/xpath-3/">XML Path Language (XPath) 3.1</xref>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="recordpattern-offsetunit">
    <title>RecordPattern-offsetunit</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>line</value>
      <description>Offset is a count of lines.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>byte</value>
      <description>Offset is a count of bytes.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="key-registryaction">
    <title>Key-registryaction</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>add-key</value>
      <description>Registry key added.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>add-value</value>
      <description>Value added to a registry key.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>delete-key</value>
      <description>Registry key deleted.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>delete-value</value>
      <description>Value deleted from a registry key.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>modify-key</value>
      <description>Registry key modified.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>modify-value</value>
      <description>Value modified in a registry key.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="hashdata-scope">
    <title>HashData-scope</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>file-contents</value>
      <description>A hash computed over the entire contents of a
        file.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file-pe-section</value>
      <description>A hash computed on a given section of a
        Windows Portable Executable (PE) file.  If set to this value,
        the HashTargetID class MUST identify the section being hashed.
        A section is identified by an ordinal number (starting at 1)
        corresponding to the order in which the given section
        header was defined in the Section Table of the PE file header.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file-pe-iat</value>
      <description>A hash computed on the Import Address
        Table (IAT) of a PE file.  As IAT hashes are often tool
        dependent, if this value is set, the Application class of
        either the Hash or FuzzyHash classes MUST specify the tool
        used to generate the hash.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file-pe-resource</value>
      <description>A hash computed on a given resource in a PE
        file.  If set to this value, the HashTargetID class MUST
        identify the resource being hashed.  A resource is identified
        by an ordinal number (starting at 1) corresponding to the
        order in which the given resource is declared in the Resource
        Directory of the Data Dictionary in the PE file header.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file-pdf-object</value>
      <description>A hash computed on a given object in a
        Portable Document Format (PDF) file.  If set to this value,
        the HashTargetID class MUST identify the object being hashed.
        This object is identified by its offset in the PDF file.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>email-hash</value>
      <description>A hash computed over the headers and body of an
        email message.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>email-headers-hash</value>
      <description>A hash computed over all of the headers
        of an email message.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>email-body-hash</value>
      <description>A hash computed over the body of an email
        message.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="bulkobservable-type">
    <title>BulkObservable-type</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>asn</value>
      <description>Autonomous System Number (per the Address@category
        attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>atm</value>
      <description>Asynchronous Transfer Mode (ATM) address (per the
        Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>e-mail</value>
      <description>Email address (per the Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-addr</value>
      <description>IPv4 host address in dotted-decimal notation, 
        e.g., 192.0.2.1 (per the Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-net</value>
      <description>IPv4 network address in dotted-decimal notation,
        slash, significant bits, e.g., 192.0.2.0/24 (per the
        Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-net-mask</value>
      <description>IPv4 network address in dotted-decimal
        notation, slash, network mask in dotted-decimal notation, 
        i.e., 192.0.2.0/255.255.255.0 (per the Address@category
        attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-addr</value>
      <description>IPv6 host address, e.g., 2001:DB8::3 (per the
        Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-net</value>
      <description>IPv6 network address, slash, significant bits, 
        e.g., 2001:DB8::/32 (per the Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-net-mask</value>
      <description>IPv6 network address, slash, network mask
        (per the Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mac</value>
      <description>Media Access Control (MAC) address, i.e., a:b:c:d:e:f 
        (per the Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>site-uri</value>
      <description>A URL or URI for a resource (per the
        Address@category attribute).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>domain-name</value>
      <description>A fully qualified domain name or part of a
        name (e.g., fqdn.example.com, example.com).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>domain-to-ipv4</value>
      <description>A mapping of FQDN to IPv4 address specified as
        a comma-separated list (e.g., "fqdn.example.com, 192.0.2.1").</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>domain-to-ipv6</value>
      <description>A mapping of FQDN to IPv6 address specified as
        a comma separated list (e.g., "fqdn.example.com,
        2001:DB8::3").</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>domain-to-ipv4-timestamp</value>
      <description>Same as domain-to-ipv4 but with a
        timestamp (in the DATETIME format) of the resolution (e.g.,
        "fqdn.example.com, 192.0.2.1, 2015-06-11T00:38:31-06:00").</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>domain-to-ipv6-timestamp</value>
      <description>Same as domain-to-ipv6 but with a
        timestamp (in the DATETIME format) of the resolution (e.g.,
        "fqdn.example.com, 2001:DB8::3, 2015-06-11T00:38:31-06:00").</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-port</value>
      <description>An IPv4 address, port, and protocol tuple (e.g.,
        192.0.2.1, 80, tcp).  The protocol name corresponds to the
        "Keyword" column in the <xref type="registry" data="protocol-numbers"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-port</value>
      <description>An IPv6 address, port, and protocol tuple (e.g.,
        2001:DB8::3, 80, tcp).  The protocol name corresponds to the
        "Keyword" column in the <xref type="registry" data="protocol-numbers"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>windows-reg-key</value>
      <description>A Microsoft Windows registry key.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file-hash</value>
      <description>A file hash.  The format of this hash is
        described in the Hash class that MUST be present in a sibling
        BulkObservableFormat class.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>email-x-mailer</value>
      <description>An X-Mailer field from an email.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>email-subject</value>
      <description>An email subject line.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>http-user-agent</value>
      <description>A User Agent field from an HTTP request
        header (e.g., "Mozilla/5.0 (Windows NT 6.3; WOW64; rv:38.0)
        Gecko/20100101 Firefox/38.0").</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>http-request-uri</value>
      <description>The Request URI from an HTTP request
        header.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>mutex</value>
      <description>The name of a system mutex (mutual exclusion lock).</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file-path</value>
      <description>A file path (e.g., "/tmp/local/file",
        "c:\windows\system32\file.sys").</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>user-name</value>
      <description>A username.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="indicatorexpression-operator">
    <title>IndicatorExpression-operator</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>not</value>
      <description>negation operator.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>and</value>
      <description>conjunction operator.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>or</value>
      <description>disjunction operator.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>xor</value>
      <description>exclusive disjunction operator.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="extensiontype-dtype">
    <title>ExtensionType-dtype</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>boolean</value>
      <description>The element content is of type BOOLEAN.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>byte</value>
      <description>The element content is of type BYTE.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>bytes</value>
      <description>The element content is of type HEXBIN.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>character</value>
      <description>The element content is of type CHARACTER.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>date-time</value>
      <description>The element content is of type DATETIME.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ntp-stamp</value>
      <description>Same as date-time.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>integer</value>
      <description>The element content is of type INTEGER.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>portlist</value>
      <description>The element content is of type PORTLIST.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>real</value>
      <description>The element content is of type REAL.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>string</value>
      <description>The element content is of type STRING.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>file</value>
      <description>The element content is a base64-encoded binary file
        encoded as a BYTE[] type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>path</value>
      <description>The element content is a file-system path encoded as a
        STRING type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>frame</value>
      <description>The element content is a Layer 2 frame encoded as a
        HEXBIN type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>packet</value>
      <description>The element content is a Layer 3 packet encoded as a
        HEXBIN type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv4-packet</value>
      <description>The element content is an IPv4 packet encoded
        as a HEXBIN type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ipv6-packet</value>
      <description>The element content is an IPv6 packet encoded
        as a HEXBIN type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>url</value>
      <description>The element content is of type URL.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>csv</value>
      <description>The element content is a comma-separated value (CSV)
        list per Section 2 of <xref type="rfc" data="rfc4180"/> encoded as a STRING type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>winreg</value>
      <description>The element content is a Microsoft Windows registry key
        encoded as a STRING type.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>xml</value>
      <description>The element content is XML.  See Section 5.2 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <registry id="softwarereference-spec-id">
    <title>SoftwareReference-spec-id</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>custom</value>
      <description>The element content is free-form and of the data type
        specified by the dtype attribute.  If this value is selected,
        then the dtype attribute MUST be set.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>cpe</value>
      <description>The element content describes a Common Platform
        Enumeration (CPE) entry per <xref type="uri" data="https://scap.nist.gov/specifications/cpe/">[NIST.CPE]</xref>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>swid</value>
      <description>The element content describes a software identification
        (SWID) tag per [ISO19770].</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>
  
  <registry id="softwarereference-dtype">
    <title>SoftwareReference-dtype</title>
    <xref type="rfc" data="rfc7970"/>
    <registration_rule>Expert Review</registration_rule>
    <expert>Roman Danyliw, Takeshi Takahashi</expert>
    <record date="2016-08-16">
      <value>bytes</value>
      <description>The element content is of type HEXBIN.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>integer</value>
      <description>The element content is of type INTEGER.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>real</value>
      <description>The element content is of type REAL.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>string</value>
      <description>The element content is of type STRING.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>xml</value>
      <description>The element content is XML.  See Section 5.2 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
    <record date="2016-08-16">
      <value>ext-value</value>
      <description>A value used to indicate that this attribute is
        extended and the actual value is provided using the
        corresponding ext-* attribute.  See Section 5.1.1 of <xref type="rfc" data="rfc7970"/>.</description>
      <xref type="rfc" data="rfc7970"/>
    </record>
  </registry>

  <people/>
</registry>
