diff --git a/objects/shadowserver-malware-url-report/definition.json b/objects/shadowserver-malware-url-report/definition.json index d2f88d2a..28c8a3b2 100644 --- a/objects/shadowserver-malware-url-report/definition.json +++ b/objects/shadowserver-malware-url-report/definition.json @@ -4,6 +4,12 @@ "description": "Application layer protocol where occurrence of the URL was observed. Examples: http, https, ssh, telnet. ", "disable_correlation": true, "misp-attribute": "text", + "sane_default": [ + "http", + "https", + "ssh", + "telnet" + ], "ui-priority": 0 }, "asn": { @@ -105,5 +111,5 @@ "url" ], "uuid": "0211496c-dbcf-465b-a147-3d965da016cc", - "version": 3 + "version": 4 } \ No newline at end of file