vocabulary1:ActionNameVocab leaf node


URI

https://unifiedcyberontology.org/ontology/uco/vocabulary#ActionNameVocab

Label

Action Name Vocabulary

Description

Defines an open-vocabulary of common specific cyber action names.

Usage

Instances of vocabulary1:ActionNameVocab can have the following properties:

PROPERTYTYPEDESCRIPTIONRANGE
From class owl:Thing
investigation:authorizationIdentifier owl:DatatypeProperty The identifier for a particular authorization (e.g. warrant number) xsd:string
investigation:authorizationType owl:DatatypeProperty A label categorizing a type of authorization (e.g. warrant) xsd:string
investigation:exhibitNumber owl:DatatypeProperty Specifies a unique identifier assigned to a given object at any stage of an investigation to differentiate it from all other objects. xsd:string
investigation:focus owl:DatatypeProperty Specifies the topical focus of an investigation. xsd:string
investigation:investigationForm owl:DatatypeProperty A label categorizing a type of investigation (case, incident, suspicious-activity, etc.) vocab:InvestigationFormVocab
investigation:investigationStatus owl:DatatypeProperty A label characterizing the status of an investigation (open, closed, etc.). xsd:string
investigation:relevantAuthorization owl:ObjectProperty Specifies an authorization relevant to a particular investigation. investigation:Authorization
investigation:rootExhibitNumber owl:DatatypeProperty Specifies a unique identifier assigned to a given object at the start of its treatment as part of an investigation. The first node in a provenance chain, which can be viewed as a heirarchical tree originating from a single root. xsd:string

Implementation

@prefix owl: <http://www.w3.org/2002/07/owl#> .
@prefix rdf: <http://www.w3.org/1999/02/22-rdf-syntax-ns#> .
@prefix rdfs: <http://www.w3.org/2000/01/rdf-schema#> .
@prefix vocabulary1: <https://unifiedcyberontology.org/ontology/uco/vocabulary#> .

vocabulary1:ActionNameVocab a rdfs:Datatype ;
    rdfs:label "Action Name Vocabulary"@en-US ;
    rdfs:comment "Defines an open-vocabulary of common specific cyber action names."@en ;
    rdfs:subClassOf rdfs:Resource ;
    owl:oneOf ( "Accept Socket Connection"^^vocabulary1:ActionNameVocab "Add Connection to Network Share"^^vocabulary1:ActionNameVocab "Add Network Share"^^vocabulary1:ActionNameVocab "Add Scheduled Task"^^vocabulary1:ActionNameVocab "Add System Call Hook"^^vocabulary1:ActionNameVocab "Add User"^^vocabulary1:ActionNameVocab "Add Windows Hook"^^vocabulary1:ActionNameVocab "Allocate Virtual Memory in Process"^^vocabulary1:ActionNameVocab "Bind Address to Socket"^^vocabulary1:ActionNameVocab "Change Service Configuration"^^vocabulary1:ActionNameVocab "Check for Remote Debugger"^^vocabulary1:ActionNameVocab "Close Port"^^vocabulary1:ActionNameVocab "Close Registry Key"^^vocabulary1:ActionNameVocab "Close Socket"^^vocabulary1:ActionNameVocab "Configure Service"^^vocabulary1:ActionNameVocab "Connect to IP"^^vocabulary1:ActionNameVocab "Connect to Named Pipe"^^vocabulary1:ActionNameVocab "Connect to Network Share"^^vocabulary1:ActionNameVocab "Connect to Socket"^^vocabulary1:ActionNameVocab "Connect to URL"^^vocabulary1:ActionNameVocab "Control Driver"^^vocabulary1:ActionNameVocab "Control Service"^^vocabulary1:ActionNameVocab "Copy File"^^vocabulary1:ActionNameVocab "Create Dialog Box"^^vocabulary1:ActionNameVocab "Create Directory"^^vocabulary1:ActionNameVocab "Create Event"^^vocabulary1:ActionNameVocab "Create File"^^vocabulary1:ActionNameVocab "Create File Alternate Data Stream"^^vocabulary1:ActionNameVocab "Create File Mapping"^^vocabulary1:ActionNameVocab "Create File Symbolic Link"^^vocabulary1:ActionNameVocab "Create Hidden File"^^vocabulary1:ActionNameVocab "Create Mailslot"^^vocabulary1:ActionNameVocab "Create Module"^^vocabulary1:ActionNameVocab "Create Mutex"^^vocabulary1:ActionNameVocab "Create Named Pipe"^^vocabulary1:ActionNameVocab "Create Process"^^vocabulary1:ActionNameVocab "Create Process as User"^^vocabulary1:ActionNameVocab "Create Registry Key"^^vocabulary1:ActionNameVocab "Create Registry Key Value"^^vocabulary1:ActionNameVocab "Create Remote Thread in Process"^^vocabulary1:ActionNameVocab "Create Service"^^vocabulary1:ActionNameVocab "Create Socket"^^vocabulary1:ActionNameVocab "Create Symbolic Link"^^vocabulary1:ActionNameVocab "Create Thread"^^vocabulary1:ActionNameVocab "Create Window"^^vocabulary1:ActionNameVocab "Delete Directory"^^vocabulary1:ActionNameVocab "Delete File"^^vocabulary1:ActionNameVocab "Delete Named Pipe"^^vocabulary1:ActionNameVocab "Delete Network Share"^^vocabulary1:ActionNameVocab "Delete Registry Key"^^vocabulary1:ActionNameVocab "Delete Registry Key Value"^^vocabulary1:ActionNameVocab "Delete Service"^^vocabulary1:ActionNameVocab "Delete User"^^vocabulary1:ActionNameVocab "Disconnect from Named Pipe"^^vocabulary1:ActionNameVocab "Disconnect from Network Share"^^vocabulary1:ActionNameVocab "Disconnect from Socket"^^vocabulary1:ActionNameVocab "Download File"^^vocabulary1:ActionNameVocab "Enumerate DLLs"^^vocabulary1:ActionNameVocab "Enumerate Network Shares"^^vocabulary1:ActionNameVocab "Enumerate Processes"^^vocabulary1:ActionNameVocab "Enumerate Protocols"^^vocabulary1:ActionNameVocab "Enumerate Registry Key Subkeys"^^vocabulary1:ActionNameVocab "Enumerate Registry Key Values"^^vocabulary1:ActionNameVocab "Enumerate Services"^^vocabulary1:ActionNameVocab "Enumerate System Handles"^^vocabulary1:ActionNameVocab "Enumerate Threads"^^vocabulary1:ActionNameVocab "Enumerate Threads in Process"^^vocabulary1:ActionNameVocab "Enumerate Users"^^vocabulary1:ActionNameVocab "Enumerate Windows"^^vocabulary1:ActionNameVocab "Find File"^^vocabulary1:ActionNameVocab "Find Window"^^vocabulary1:ActionNameVocab "Flush Process Instruction Cache"^^vocabulary1:ActionNameVocab "Free Library"^^vocabulary1:ActionNameVocab "Free Process Virtual Memory"^^vocabulary1:ActionNameVocab "Get Disk Free Space"^^vocabulary1:ActionNameVocab "Get Disk Type"^^vocabulary1:ActionNameVocab "Get Elapsed System Up Time"^^vocabulary1:ActionNameVocab "Get File Attributes"^^vocabulary1:ActionNameVocab "Get Function Address"^^vocabulary1:ActionNameVocab "Get Host By Address"^^vocabulary1:ActionNameVocab "Get Host By Name"^^vocabulary1:ActionNameVocab "Get Host Name"^^vocabulary1:ActionNameVocab "Get Library File Name"^^vocabulary1:ActionNameVocab "Get Library Handle"^^vocabulary1:ActionNameVocab "Get NetBIOS Name"^^vocabulary1:ActionNameVocab "Get Process Current Directory"^^vocabulary1:ActionNameVocab "Get Process Environment Variable"^^vocabulary1:ActionNameVocab "Get Process Startup Information"^^vocabulary1:ActionNameVocab "Get Processes Snapshot"^^vocabulary1:ActionNameVocab "Get Registry Key Attributes"^^vocabulary1:ActionNameVocab "Get Service Status"^^vocabulary1:ActionNameVocab "Get System Global Flags"^^vocabulary1:ActionNameVocab "Get System Host Name"^^vocabulary1:ActionNameVocab "Get System Local Time"^^vocabulary1:ActionNameVocab "Get System NetBIOS Name"^^vocabulary1:ActionNameVocab "Get System Network Parameters"^^vocabulary1:ActionNameVocab "Get System Time"^^vocabulary1:ActionNameVocab "Get Thread Context"^^vocabulary1:ActionNameVocab "Get Thread Username"^^vocabulary1:ActionNameVocab "Get User Attributes"^^vocabulary1:ActionNameVocab "Get Username"^^vocabulary1:ActionNameVocab "Get Windows Directory"^^vocabulary1:ActionNameVocab "Get Windows System Directory"^^vocabulary1:ActionNameVocab "Get Windows Temporary Files Directory"^^vocabulary1:ActionNameVocab "Hide Window"^^vocabulary1:ActionNameVocab "Impersonate Process"^^vocabulary1:ActionNameVocab "Impersonate Thread"^^vocabulary1:ActionNameVocab "Inject Memory Page"^^vocabulary1:ActionNameVocab "Kill Process"^^vocabulary1:ActionNameVocab "Kill Thread"^^vocabulary1:ActionNameVocab "Kill Window"^^vocabulary1:ActionNameVocab "Listen on Port"^^vocabulary1:ActionNameVocab "Listen on Socket"^^vocabulary1:ActionNameVocab "Load Driver"^^vocabulary1:ActionNameVocab "Load Library"^^vocabulary1:ActionNameVocab "Load Module"^^vocabulary1:ActionNameVocab "Load and Call Driver"^^vocabulary1:ActionNameVocab "Lock File"^^vocabulary1:ActionNameVocab "Logon as User"^^vocabulary1:ActionNameVocab "Map File"^^vocabulary1:ActionNameVocab "Map Library"^^vocabulary1:ActionNameVocab "Map View of File"^^vocabulary1:ActionNameVocab "Modify File"^^vocabulary1:ActionNameVocab "Modify Named Pipe"^^vocabulary1:ActionNameVocab "Modify Process"^^vocabulary1:ActionNameVocab "Modify Registry Key"^^vocabulary1:ActionNameVocab "Modify Registry Key Value"^^vocabulary1:ActionNameVocab "Modify Service"^^vocabulary1:ActionNameVocab "Monitor Registry Key"^^vocabulary1:ActionNameVocab "Move File"^^vocabulary1:ActionNameVocab "Open File"^^vocabulary1:ActionNameVocab "Open File Mapping"^^vocabulary1:ActionNameVocab "Open Mutex"^^vocabulary1:ActionNameVocab "Open Port"^^vocabulary1:ActionNameVocab "Open Process"^^vocabulary1:ActionNameVocab "Open Registry Key"^^vocabulary1:ActionNameVocab "Open Service"^^vocabulary1:ActionNameVocab "Open Service Control Manager"^^vocabulary1:ActionNameVocab "Protect Virtual Memory"^^vocabulary1:ActionNameVocab "Query DNS"^^vocabulary1:ActionNameVocab "Query Disk Attributes"^^vocabulary1:ActionNameVocab "Query Process Virtual Memory"^^vocabulary1:ActionNameVocab "Queue APC in Thread"^^vocabulary1:ActionNameVocab "Read File"^^vocabulary1:ActionNameVocab "Read From Named Pipe"^^vocabulary1:ActionNameVocab "Read From Process Memory"^^vocabulary1:ActionNameVocab "Read Registry Key Value"^^vocabulary1:ActionNameVocab "Receive Data on Socket"^^vocabulary1:ActionNameVocab "Receive Email Message"^^vocabulary1:ActionNameVocab "Release Mutex"^^vocabulary1:ActionNameVocab "Rename File"^^vocabulary1:ActionNameVocab "Revert Thread to Self"^^vocabulary1:ActionNameVocab "Send Control Code to File"^^vocabulary1:ActionNameVocab "Send Control Code to Pipe"^^vocabulary1:ActionNameVocab "Send Control Code to Service"^^vocabulary1:ActionNameVocab "Send DNS Query"^^vocabulary1:ActionNameVocab "Send Data on Socket"^^vocabulary1:ActionNameVocab "Send Data to Address on Socket"^^vocabulary1:ActionNameVocab "Send Email Message"^^vocabulary1:ActionNameVocab "Send ICMP Request"^^vocabulary1:ActionNameVocab "Send Reverse DNS Query"^^vocabulary1:ActionNameVocab "Set File Attributes"^^vocabulary1:ActionNameVocab "Set NetBIOS Name"^^vocabulary1:ActionNameVocab "Set Process Current Directory"^^vocabulary1:ActionNameVocab "Set Process Environment Variable"^^vocabulary1:ActionNameVocab "Set System Global Flags"^^vocabulary1:ActionNameVocab "Set System Host Name"^^vocabulary1:ActionNameVocab "Set System Time"^^vocabulary1:ActionNameVocab "Set Thread Context"^^vocabulary1:ActionNameVocab "Show Window"^^vocabulary1:ActionNameVocab "Shutdown System"^^vocabulary1:ActionNameVocab "Sleep Process"^^vocabulary1:ActionNameVocab "Sleep System"^^vocabulary1:ActionNameVocab "Start Service"^^vocabulary1:ActionNameVocab "Unload Driver"^^vocabulary1:ActionNameVocab "Unload Module"^^vocabulary1:ActionNameVocab "Unlock File"^^vocabulary1:ActionNameVocab "Unmap File"^^vocabulary1:ActionNameVocab "Upload File"^^vocabulary1:ActionNameVocab "Write to File"^^vocabulary1:ActionNameVocab "Write to Process Virtual Memory"^^vocabulary1:ActionNameVocab ) .