Releases: HalfTimeOfLife/mispSK
Releases · HalfTimeOfLife/mispSK
Release list
v1.0 - Consolidation
Tenth release of mispSK.
Added
- N/A - this is a consolidation release, no new script or feature
Changed
- CLI flag naming standardized across scripts: --output now means "format" (event_search.py, taxonomy_check.py) or "output-file" (export_attack_layer.py), never both
- Dependencies pinned to exact versions in requirements.txt / requirements-dev.txt for reproducible installs
- README corrected (stale project tree, event_import.py status) and fully aligned with the new CLI flags
- Full test suite audit confirmed complete coverage of mispsk/ core modules and dry-run paths, with no gaps requiring new tests
Known Limitations
- No backward-compatibility shim for the renamed --output flags; existing scripts/aliases calling the old flag names must be updated manually
- scripts/ CLI argument parsing has no dedicated tests, by design (orchestration-only, tested indirectly via mispsk/)
See CHANGELOG.md and ROADMAP.md for full details.
v0.7 - Structured Event Import
Eighth release of mispSK.
Added
event_import.py: build and import one or more MISP events from structured YAML report filesmispsk/event_builder.py:load_import_file,validate_import_schema,build_event_from_data,add_context_tags_from_data,add_attack_tags_from_data,add_attributes_from_data,build_import_tree_output,import_event- YAML import format:
eventblock (info,distribution,threat_level,analysis,tlp,pap), top-levelattack(full freetext ATT&CK tag strings) andtagslists, andattributeslist (type,value,category,to_ids,comment) tlp/papvalues are normalized to the correct MISP taxonomy casing automatically (tlp:{value}lowercased,PAP:{VALUE}uppercased)- Structural validation (
validate_import_schema) catches malformed import files before any MISP write; actual MISP attribute type validation is left to PyMISP itself, for more precise error messages - Attributes rejected by PyMISP (unknown type) are skipped individually with a warning rather than failing the whole import
- Post-build compliance check reusing
mispsk.taxonomy.check_event(TLP/PAP/ATT&CK), computed on the local event before writing, shown in the tree summary even in--dry-run --file/--files(mutually exclusive) for single or batch import, one MISP event per YAML file--dry-run: preview the constructed event(s) without writing to MISP- Tree-style terminal output, same visual style as
ioc_enrich.py - A file that fails to load/parse/validate is skipped individually; the batch continues. Exit code 1 only if every file in the batch failed
tests/test_event_builder.py: unit test coverage for YAML loading, schema validation, event construction, tag/attribute assembly, tree output, and the dry-run/write-mode import paths
Fixed
mispsk/taxonomy.py:check_event()usedevent.iddirectly, which raisedAttributeErroron a MISPEvent built locally viaevent_builder.pyand never written to MISP (i.e. duringevent_import.py --dry-run). Now usesevent.get("id"), returningNonegracefully instead.
Known limitations
- Create-only:
event_import.pyalways creates a new MISP event, it cannot update an existing one - ATT&CK tags must be supplied as full freetext tag strings, not as bare technique IDs - mispSK does not embed a MITRE ATT&CK ID-to-name mapping table
See CHANGELOG.md and ROADMAP.md for full details.
v0.6 - Taxonomy & Quality Check
Seventh release of mispSK.
Added
taxonomy_check.py: validate MISP events against a minimal quality baseline (TLP present, PAP present, ATT&CK present)mispsk/taxonomy.py:_check_tlp,_check_pap,_check_attack,check_event,build_taxonomy_report- Per-event score (0–3) and global compliance summary (
X/Y events fully compliant (Z%)) --limit N(default: 100),--days N,--output table|csv,--output-file- Exit code 0 if all events fully compliant, 1 otherwise
tests/test_taxonomy.py
Known limitation
_check_attackdetects ATT&CK via PyMISP galaxy objects andmisp-galaxy:mitre-attack-pattern="..."tags — instances without synchronized MITRE ATT&CK galaxies will score 2/3 at best on this check
See CHANGELOG.md for full details and ROADMAP.md.
v0.5.2 - Splunk CIM CSV export
Sixth release of mispSK.
Added
export_splunk.py: export one or more MISP events' attributes to a Splunk CIM-oriented CSV filemispsk/splunk.py:classify_cim_datamodel,split_composite_value,map_attribute_to_cim_fields,build_csv_row,build_splunk_export- CIM field mapping across six Splunk data models:
Network_Traffic,Web,Malware,Endpoint,Email,Certificates - One CSV row per attribute, with
raw_valueas a generic fallback andcim_datamodelindicating the matched model - Composite types (
ip-src|port,filename|md5,regkey|value, etc.) automatically split across their two CIM columns --id/--idsfor single or batch event export--include-non-idsflag - onlyto_ids=Trueattributes are exported by defaulttests/test_splunk.py
Known limitation
- CIM mapping covers the types most relevant to SOC/CTI analysis; unmapped types are still exported via
raw_value - This is a lightweight standalone CSV export, not a replacement for Splunk's Threat Intelligence Framework or the misp42splunk app
See CHANGELOG.md for full details and ROADMAP.md.
v0.5.1 - YARA rule export
Fifth release of mispSK.
Added
export_yara.py: generate a YARA rule from a MISP event's static IOCs (hashes, filenames, patterns, registry keys, mutexes) plus network indicators as plain string matchesmispsk/yara.py:classify_confidence_tier,filter_yara_candidates,escape_yara_string,build_hash_condition,extract_analyst_rule,build_yara_rulemispsk/export_common.py:filter_attributes_by_type,sanitize_identifier- shared helpers for the upcomingexport_splunk.py(v0.5.2)- Three-tier confidence model: strong (md5/sha1/sha256, any match suffices), medium (filename/pattern-in-file/regkey/mutex/..., any match suffices), weak (network indicators as string matches only, 2+ required)
- Analyst-authored
yara-type attributes are extracted and appended as separate rules rather than folded into the generated one - Optional syntax validation via
yara-pythonbefore any output is produced tests/test_yara.py,tests/test_export_common.py
Changed
- Split
mispsk/utils.pyintoioc.py,dates.py,summary.py, withenrichment.py/feeds.pyabsorbing their remaining helpers, as groundwork for the export scripts introduced in this release
Known limitation
- YARA is a static-only detection format: network-oriented MISP attributes (
ip-src,ip-dst,domain,url, etc.) can only be included as plain string matches, never as real network-level detection - Hash types not computable by YARA's built-in
hashmodule (ssdeep,tlsh,imphash,sha512, etc.) are skipped rather than included in the generated condition
See CHANGELOG.md for full details and ROADMAP.md.
v0.4.0 - ATT&CK Navigator layer export
Fourth release of mispSK.
Added
export_attack_layer.py: export one or more MISP events' ATT&CK tags to an ATT&CK Navigator layer JSON file, for interop with attackmapmispsk/attack_layer.py:extract_technique_id,compute_score,aggregate_attack_tags,build_navigator_layermispsk/client.py:get_events_by_idsfor batch event fetching, skipping invalid IDs with a warningtests/test_attack_layer.py: unit tests covering technique ID extraction, score normalization, cross-event aggregation, and layer construction
Changed
mispsk/utils.py:_get_attack_tagsrenamed toget_attack_tags(now shared betweenevent_search.pyandattack_layer.py)
Known limitation
- Technique ID mapping relies on the
external_idfield incluster.meta, populated by MISP's officialmitre-attackgalaxy sync. Clusters missing this field are skipped with a warning rather than failing the whole export.
See CHANGELOG.md for full details and ROADMAP.md.
v0.3.0 - Feeds health check
Third release of mispSK.
Added
feed_health.py: reports sync status and matched event volume per configured MISP feedmispsk/feeds.py:resolve_last_sync,resolve_recent_volume,build_resultmispsk/utils.py:get_age,build_feed_report--max-age-daysflag to control the staleness threshold forfixed_eventfeeds
Changed
event_search.py: table output now usesrounded_gridformatting for visual consistency withfeed_health.py
Known limitation
- Sync freshness (
last_sync) is only resolvable forfixed_eventfeeds. For all other feeds (misp/csv/freetextwithout a reused event), MISP exposes no reliable "last successful fetch" signal via PyMISP:event.timestampreflects the source's original publish datesearch_logs()does not journal feed fetches
See CHANGELOG.md for full details and ROADMAP.md.
v0.2.1 - Composite Attribute Fix
Patch release for mispSK v0.2.
Fixed
- Composite attribute types (filename|md5, ip-src|port, etc.) had their IOC value extracted from the wrong segment, causing invalid lookups
- Comment and tag updates on MISP attributes are now independent, an unchanged tag is no longer redundantly re-applied when only the comment changes
- Unexpected HTTP errors (5xx) from VirusTotal/AbuseIPDB now stop enrichment gracefully instead of raising an unhandled traceback
- Connection error message translated to English for consistency
Added
- Composite attribute type support: filename|md5, filename|sha1, filename|sha256, ip-src|port, ip-dst|port
- requirements-dev.txt: separated dev-only dependencies from runtime requirements
- Test coverage for composite attribute extraction, caching, and independent comment/tag write behavior
See CHANGELOG.md for full details.
v0.2 - IOC Enrichment
Second release of mispSK.
Added
ioc_enrich.py: enrich MISP hash attributes (md5,sha1,sha256) via VirusTotal and IP attributes (ip-src,ip-dst) via AbuseIPDBmispsk/enrichers.py: reusableVTEnricherandAbuseIPDBEnricherAPI wrappers- Enrichment classification, MISP tags, and attribute comments generation
--dry-runmode to preview changes without modifying MISP--max-age-daysoption to control AbuseIPDB lookup freshness- Tree-style terminal output for enrichment results
- Unit tests covering enrichment logic, API interactions, caching, error handling, and MISP client lookups
Changed
- MISP event lookup methods moved into
MispClientfor reuse across scripts - Enrichment logic extracted from CLI scripts into reusable package modules
- Added VirusTotal rate limiting configuration through
VT_RATE_LIMIT_DELAY
Fixed
- Removed duplicated MISP lookup logic from scripts
- Improved enrichment reliability with IOC lookup caching
See CHANGELOG.md for full details and ROADMAP.md.
v0.1 - Event Search
First release of mispSK.
Added
event_search.py: look up a MISP event by ID or IOC value, with a readable summary (attribute count, attribute type breakdown, source org, TLP, ATT&CK cluster tags)--output table|jsonoutput formatmispsk/client.py: sharedMispClientwrapper for config loading, validation, and MISP connection, reused by all future scriptsmispsk/utils.py: shared summary extraction and formatting logic- Editable install via
pyproject.toml(pip install -e .) - Unit tests covering summary extraction and output formatting
See CHANGELOG.md for full details and ROADMAP.md.