Skip to content

Releases: HalfTimeOfLife/mispSK

v1.0 - Consolidation

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 24 Aug 19:45

Tenth release of mispSK.

Added

  • N/A - this is a consolidation release, no new script or feature

Changed

  • CLI flag naming standardized across scripts: --output now means "format" (event_search.py, taxonomy_check.py) or "output-file" (export_attack_layer.py), never both
  • Dependencies pinned to exact versions in requirements.txt / requirements-dev.txt for reproducible installs
  • README corrected (stale project tree, event_import.py status) and fully aligned with the new CLI flags
  • Full test suite audit confirmed complete coverage of mispsk/ core modules and dry-run paths, with no gaps requiring new tests

Known Limitations

  • No backward-compatibility shim for the renamed --output flags; existing scripts/aliases calling the old flag names must be updated manually
  • scripts/ CLI argument parsing has no dedicated tests, by design (orchestration-only, tested indirectly via mispsk/)

See CHANGELOG.md and ROADMAP.md for full details.

v0.7 - Structured Event Import

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 15 Aug 19:11

Eighth release of mispSK.

Added

  • event_import.py: build and import one or more MISP events from structured YAML report files
  • mispsk/event_builder.py: load_import_file, validate_import_schema, build_event_from_data, add_context_tags_from_data, add_attack_tags_from_data, add_attributes_from_data, build_import_tree_output, import_event
  • YAML import format: event block (info, distribution, threat_level, analysis, tlp, pap), top-level attack (full freetext ATT&CK tag strings) and tags lists, and attributes list (type, value, category, to_ids, comment)
  • tlp/pap values are normalized to the correct MISP taxonomy casing automatically (tlp:{value} lowercased, PAP:{VALUE} uppercased)
  • Structural validation (validate_import_schema) catches malformed import files before any MISP write; actual MISP attribute type validation is left to PyMISP itself, for more precise error messages
  • Attributes rejected by PyMISP (unknown type) are skipped individually with a warning rather than failing the whole import
  • Post-build compliance check reusing mispsk.taxonomy.check_event (TLP/PAP/ATT&CK), computed on the local event before writing, shown in the tree summary even in --dry-run
  • --file / --files (mutually exclusive) for single or batch import, one MISP event per YAML file
  • --dry-run: preview the constructed event(s) without writing to MISP
  • Tree-style terminal output, same visual style as ioc_enrich.py
  • A file that fails to load/parse/validate is skipped individually; the batch continues. Exit code 1 only if every file in the batch failed
  • tests/test_event_builder.py: unit test coverage for YAML loading, schema validation, event construction, tag/attribute assembly, tree output, and the dry-run/write-mode import paths

Fixed

  • mispsk/taxonomy.py: check_event() used event.id directly, which raised AttributeError on a MISPEvent built locally via event_builder.py and never written to MISP (i.e. during event_import.py --dry-run). Now uses event.get("id"), returning None gracefully instead.

Known limitations

  • Create-only: event_import.py always creates a new MISP event, it cannot update an existing one
  • ATT&CK tags must be supplied as full freetext tag strings, not as bare technique IDs - mispSK does not embed a MITRE ATT&CK ID-to-name mapping table

See CHANGELOG.md and ROADMAP.md for full details.

v0.6 - Taxonomy & Quality Check

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 08 Aug 13:57

Seventh release of mispSK.

Added

  • taxonomy_check.py: validate MISP events against a minimal quality baseline (TLP present, PAP present, ATT&CK present)
  • mispsk/taxonomy.py: _check_tlp, _check_pap, _check_attack, check_event, build_taxonomy_report
  • Per-event score (0–3) and global compliance summary (X/Y events fully compliant (Z%))
  • --limit N (default: 100), --days N, --output table|csv, --output-file
  • Exit code 0 if all events fully compliant, 1 otherwise
  • tests/test_taxonomy.py

Known limitation

  • _check_attack detects ATT&CK via PyMISP galaxy objects and misp-galaxy:mitre-attack-pattern="..." tags — instances without synchronized MITRE ATT&CK galaxies will score 2/3 at best on this check

See CHANGELOG.md for full details and ROADMAP.md.

v0.5.2 - Splunk CIM CSV export

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 06 Aug 20:17

Sixth release of mispSK.

Added

  • export_splunk.py: export one or more MISP events' attributes to a Splunk CIM-oriented CSV file
  • mispsk/splunk.py: classify_cim_datamodel, split_composite_value, map_attribute_to_cim_fields, build_csv_row, build_splunk_export
  • CIM field mapping across six Splunk data models: Network_Traffic, Web, Malware, Endpoint, Email, Certificates
  • One CSV row per attribute, with raw_value as a generic fallback and cim_datamodel indicating the matched model
  • Composite types (ip-src|port, filename|md5, regkey|value, etc.) automatically split across their two CIM columns
  • --id / --ids for single or batch event export
  • --include-non-ids flag - only to_ids=True attributes are exported by default
  • tests/test_splunk.py

Known limitation

  • CIM mapping covers the types most relevant to SOC/CTI analysis; unmapped types are still exported via raw_value
  • This is a lightweight standalone CSV export, not a replacement for Splunk's Threat Intelligence Framework or the misp42splunk app

See CHANGELOG.md for full details and ROADMAP.md.

v0.5.1 - YARA rule export

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 29 Jul 09:53

Fifth release of mispSK.

Added

  • export_yara.py: generate a YARA rule from a MISP event's static IOCs (hashes, filenames, patterns, registry keys, mutexes) plus network indicators as plain string matches
  • mispsk/yara.py: classify_confidence_tier, filter_yara_candidates, escape_yara_string, build_hash_condition, extract_analyst_rule, build_yara_rule
  • mispsk/export_common.py: filter_attributes_by_type, sanitize_identifier - shared helpers for the upcoming export_splunk.py (v0.5.2)
  • Three-tier confidence model: strong (md5/sha1/sha256, any match suffices), medium (filename/pattern-in-file/regkey/mutex/..., any match suffices), weak (network indicators as string matches only, 2+ required)
  • Analyst-authored yara-type attributes are extracted and appended as separate rules rather than folded into the generated one
  • Optional syntax validation via yara-python before any output is produced
  • tests/test_yara.py, tests/test_export_common.py

Changed

  • Split mispsk/utils.py into ioc.py, dates.py, summary.py, with enrichment.py/feeds.py absorbing their remaining helpers, as groundwork for the export scripts introduced in this release

Known limitation

  • YARA is a static-only detection format: network-oriented MISP attributes (ip-src, ip-dst, domain, url, etc.) can only be included as plain string matches, never as real network-level detection
  • Hash types not computable by YARA's built-in hash module (ssdeep, tlsh, imphash, sha512, etc.) are skipped rather than included in the generated condition

See CHANGELOG.md for full details and ROADMAP.md.

v0.4.0 - ATT&CK Navigator layer export

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 17 Jul 23:26

Fourth release of mispSK.

Added

  • export_attack_layer.py: export one or more MISP events' ATT&CK tags to an ATT&CK Navigator layer JSON file, for interop with attackmap
  • mispsk/attack_layer.py: extract_technique_id, compute_score, aggregate_attack_tags, build_navigator_layer
  • mispsk/client.py: get_events_by_ids for batch event fetching, skipping invalid IDs with a warning
  • tests/test_attack_layer.py: unit tests covering technique ID extraction, score normalization, cross-event aggregation, and layer construction

Changed

  • mispsk/utils.py: _get_attack_tags renamed to get_attack_tags (now shared between event_search.py and attack_layer.py)

Known limitation

  • Technique ID mapping relies on the external_id field in cluster.meta, populated by MISP's official mitre-attack galaxy sync. Clusters missing this field are skipped with a warning rather than failing the whole export.

See CHANGELOG.md for full details and ROADMAP.md.

v0.3.0 - Feeds health check

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 17 Jul 10:31

Third release of mispSK.

Added

  • feed_health.py: reports sync status and matched event volume per configured MISP feed
  • mispsk/feeds.py: resolve_last_sync, resolve_recent_volume, build_result
  • mispsk/utils.py: get_age, build_feed_report
  • --max-age-days flag to control the staleness threshold for fixed_event feeds

Changed

  • event_search.py: table output now uses rounded_grid formatting for visual consistency with feed_health.py

Known limitation

  • Sync freshness (last_sync) is only resolvable for fixed_event feeds. For all other feeds (misp/csv/freetext without a reused event), MISP exposes no reliable "last successful fetch" signal via PyMISP:
    • event.timestamp reflects the source's original publish date
    • search_logs() does not journal feed fetches

See CHANGELOG.md for full details and ROADMAP.md.

v0.2.1 - Composite Attribute Fix

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 15 Jul 21:15

Patch release for mispSK v0.2.

Fixed

  • Composite attribute types (filename|md5, ip-src|port, etc.) had their IOC value extracted from the wrong segment, causing invalid lookups
  • Comment and tag updates on MISP attributes are now independent, an unchanged tag is no longer redundantly re-applied when only the comment changes
  • Unexpected HTTP errors (5xx) from VirusTotal/AbuseIPDB now stop enrichment gracefully instead of raising an unhandled traceback
  • Connection error message translated to English for consistency

Added

  • Composite attribute type support: filename|md5, filename|sha1, filename|sha256, ip-src|port, ip-dst|port
  • requirements-dev.txt: separated dev-only dependencies from runtime requirements
  • Test coverage for composite attribute extraction, caching, and independent comment/tag write behavior

See CHANGELOG.md for full details.

v0.2 - IOC Enrichment

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 15 Jul 13:42

Second release of mispSK.

Added

  • ioc_enrich.py: enrich MISP hash attributes (md5, sha1, sha256) via VirusTotal and IP attributes (ip-src, ip-dst) via AbuseIPDB
  • mispsk/enrichers.py: reusable VTEnricher and AbuseIPDBEnricher API wrappers
  • Enrichment classification, MISP tags, and attribute comments generation
  • --dry-run mode to preview changes without modifying MISP
  • --max-age-days option to control AbuseIPDB lookup freshness
  • Tree-style terminal output for enrichment results
  • Unit tests covering enrichment logic, API interactions, caching, error handling, and MISP client lookups

Changed

  • MISP event lookup methods moved into MispClient for reuse across scripts
  • Enrichment logic extracted from CLI scripts into reusable package modules
  • Added VirusTotal rate limiting configuration through VT_RATE_LIMIT_DELAY

Fixed

  • Removed duplicated MISP lookup logic from scripts
  • Improved enrichment reliability with IOC lookup caching

See CHANGELOG.md for full details and ROADMAP.md.

v0.1 - Event Search

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 12 Jul 23:48

First release of mispSK.

Added

  • event_search.py: look up a MISP event by ID or IOC value, with a readable summary (attribute count, attribute type breakdown, source org, TLP, ATT&CK cluster tags)
  • --output table|json output format
  • mispsk/client.py: shared MispClient wrapper for config loading, validation, and MISP connection, reused by all future scripts
  • mispsk/utils.py: shared summary extraction and formatting logic
  • Editable install via pyproject.toml (pip install -e .)
  • Unit tests covering summary extraction and output formatting

See CHANGELOG.md for full details and ROADMAP.md.