Skip to content

v0.4.0 - ATT&CK Navigator layer export

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 17 Jul 23:26
· 33 commits to main since this release

Fourth release of mispSK.

Added

  • export_attack_layer.py: export one or more MISP events' ATT&CK tags to an ATT&CK Navigator layer JSON file, for interop with attackmap
  • mispsk/attack_layer.py: extract_technique_id, compute_score, aggregate_attack_tags, build_navigator_layer
  • mispsk/client.py: get_events_by_ids for batch event fetching, skipping invalid IDs with a warning
  • tests/test_attack_layer.py: unit tests covering technique ID extraction, score normalization, cross-event aggregation, and layer construction

Changed

  • mispsk/utils.py: _get_attack_tags renamed to get_attack_tags (now shared between event_search.py and attack_layer.py)

Known limitation

  • Technique ID mapping relies on the external_id field in cluster.meta, populated by MISP's official mitre-attack galaxy sync. Clusters missing this field are skipped with a warning rather than failing the whole export.

See CHANGELOG.md for full details and ROADMAP.md.