Actions ID Property Name Use Case Source 1 scan Symantec: scan>>file 2 locate ATT: locate>>ip_addrSymantec: locate>>processSymantec: locate>>directorySymantec: locate>>fileSymantec: locate>>windows_registry_key 3 query General: query>>propertyPhantom: query>>processsFractalConsulting: query>>openc2General: query>>openc2Symantec: query>>deviceSymantec: query>>fileSymantec: query>>softwareSymantec: query>>url 4 report 5 notify 6 deny ATT: deny>>ip_connectionPhantom: deny>>processSTIX: deny>>ip_connectionsFractalConsulting: deny>>ip_connectionsFractalConsulting: deny>>domain_nameLG: deny>>ip_addrSymantec: deny>>fileSymantec: deny>>processSymantec: deny>>urlSymantec: deny>>email-addrSymantec: deny>>email-message 7 contain ATT: contain>>domain_nameSTIX: contain>>deviceSymantec: contain>>device 8 allow ATT: allow>>domain_nameATT: allow>>ip_connectionsFractalConsulting: allow>>ip_connectionSymantec: allow>>deviceSymantec: allow>>fileSymantec: allow>>url 9 start Symantec: start>>processsFractal: start: vm 10 stop Phantom: stop>>processSymantec: stop>>processsFractal: stop: vm 11 restart Symantec: restart>>deviceSymantec: restart>>process 12 pause 13 resume 14 cancel Symantec: cancel>>command 15 set 16 update sFractalConsulting: update>>softwaresFractalConsulting: update>>softwareSymantec: update>>deviceSymantec: update>>software 17 move 18 redirect STIX: redirect>>ip_connectionLG: redirect>>domain_nameLG: redirect>>url 19 create sFractal: start: vm 20 delete Phantom: delete>>fileSTIX: delete>>artifactsFractalConsulting: delete>>processsFractalConsulting: delete>>email_messagesFractalConsulting: delete>>filePhantom: delete>>fileSymantec: delete>>deviceSymantec: delete>>file 21 snapshot 22 detonate Symantec: detonate>>fileSymantec: detonate>>url 23 restore Symantec: restore>>file 24 save 25 throttle 26 delay 27 substitute 28 copy Symantec: copy>>file 29 sync 30 investigate Symantec: investigate>>device 31 mitigate 32 remediate Symantec: remediate>>file Targets ID Property Name Type Use Case Source 1 artifact Artifact STIX: delete>>artifact 2 command Command Symantec: cancel>>command 3 device Device STIX: contain>>deviceSymantec: allow>>deviceSymantec: delete>>deviceSymantec: query>>deviceSymantec: restart>>deviceSymantec: update>>deviceSymantec: contain>>device 4 directory Directory Symantec: locate>>directory 5 disk Disk 6 disk_partition Disk-Partition 7 domain_name Domain-Name ATT: contain>>domain_nameATT: allow>>domain_namesFractalConsulting: deny>>domain_nameLG: redirect>>domain_name 8 email_addr Email-Addr Symantec: deny>>email-addr 9 email_message Email-Message sFractalConsulting: delete>>email_messageSymantec: deny>>email-message 10 file File Phantom: delete>>filesFractalConsulting: delete>>filePhantom: delete>>fileSymantec: allow>>fileSymantec: copy>>fileSymantec: delete>>fileSymantec: deny>>fileSymantec: remediate>>fileSymantec: locate>>fileSymantec: query>>fileSymantec: restore>>fileSymantec: scan>>fileSymantec: detonate>>file 11 ip_addr IP-Addr ATT: locate>>ip_addrLG: deny>>ip_addr 13 mac_addr Mac-Addr 14 memory Memory 15 ip_connection IP-Connection ATT: deny>>ip_connectionATT: allow>>ip_connectionSTIX: deny>>ip_connectionSTIX: redirect>>ip_connectionsFractalConsulting: allow>>ip_connectionsFractalConsulting: deny>>ip_connection 16 openc2 OpenC2 sFractalConsulting: query>>openc2General: query>>openc2Symantec: cancel>>openc2>>command 17 process Process Phantom: query>>process Phantom: deny>>process Phantom: stop>>processsFractalConsulting: delete>>processSymantec: deny>>processSymantec: locate>>processSymantec: restart>>processSymantec: stop>>processSymantec: start>>process 25 property Property General: query>>property 18 software Software sFractalConsulting: update>>softwaresFractalConsulting: update>>softwareSymantec: query>>softwareSymantec: update>>software 19 url Url LG: redirect>>urlSymantec: query>>urlSymantec: deny>>urlSymantec: allow>>urlSymantec: detonate>>url 20 user_account User-Account 21 user_session User-Session 22 volume Volume 23 windows_registry_key Windows-Registry-Key Symantec: locate>>windows_registry_key 24 x509_certificate X509-Certificate 1024 slpff Slpff-Target