v0.4.0 - ATT&CK Navigator layer export
Fourth release of mispSK.
Added
export_attack_layer.py: export one or more MISP events' ATT&CK tags to an ATT&CK Navigator layer JSON file, for interop with attackmapmispsk/attack_layer.py:extract_technique_id,compute_score,aggregate_attack_tags,build_navigator_layermispsk/client.py:get_events_by_idsfor batch event fetching, skipping invalid IDs with a warningtests/test_attack_layer.py: unit tests covering technique ID extraction, score normalization, cross-event aggregation, and layer construction
Changed
mispsk/utils.py:_get_attack_tagsrenamed toget_attack_tags(now shared betweenevent_search.pyandattack_layer.py)
Known limitation
- Technique ID mapping relies on the
external_idfield incluster.meta, populated by MISP's officialmitre-attackgalaxy sync. Clusters missing this field are skipped with a warning rather than failing the whole export.
See CHANGELOG.md for full details and ROADMAP.md.