Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Version 0.7.0 - Expanded galaxy mappings#124

Merged
jshcodes merged 6 commits into
mainfrom
ver_0.7.0
Apr 28, 2023
Merged

Version 0.7.0 - Expanded galaxy mappings#124
jshcodes merged 6 commits into
mainfrom
ver_0.7.0

Conversation

@jshcodes
Copy link
Copy Markdown
Member

@jshcodes jshcodes commented Apr 28, 2023

This update provides the following new functionality:

  • Maps CrowdStrike adversaries to the MISP Threat Actor galaxy. Existing adversaries are identified within the current galaxy, and new galaxy clusters are create for adversaries that are not present. These threat actors are removed as part of adversary delete operations.
  • Maps target sectors to the MISP Sector galaxy.
  • Maps target regions to the MISP Regions M49 galaxy.
  • Maps target countries to the MISP Countries galaxy.
  • Dramatically expands malware identification by looking up malware in additional MISP galaxies. The galaxy.ini file is still leveraged to override undesired matches by forcing a galaxy mapping.
  • Resolves the publishing issue for Malware / Indicator type events. Closes Publish flag does not work for all Event Types - Malware Events are not Published #123.

@jshcodes jshcodes merged commit d19f41d into main Apr 28, 2023
@jshcodes jshcodes deleted the ver_0.7.0 branch April 28, 2023 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish flag does not work for all Event Types - Malware Events are not Published

1 participant