Skip to content

Support Shannon Entropy on File / Artifact Objects and not just within Windows™ PE Section Type #334

@animedbz16

Description

@animedbz16

Created an issue over here (oasis-open/cti-documentation#120), but seems more appropriate to track this over here instead:

Looking through Stix 2.1 documentation, it appears that only one section discusses a property of entropy which is located within a Windows™ PE Section Type (See https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html#_ioapwyd8oimw)

Shannon Entropy is a fundamental metric for measuring randomness in any file, not just Windows PE sections. The restriction of the entropy field to only the Windows PE Section Type in STIX 2.1 (section 6.7.6.3) seems like an arbitrary limitation

It seems more appropriate to move this field to be supported directly under File and/or Artifact objects.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions