v0.7 - Structured Event Import
Eighth release of mispSK.
Added
event_import.py: build and import one or more MISP events from structured YAML report filesmispsk/event_builder.py:load_import_file,validate_import_schema,build_event_from_data,add_context_tags_from_data,add_attack_tags_from_data,add_attributes_from_data,build_import_tree_output,import_event- YAML import format:
eventblock (info,distribution,threat_level,analysis,tlp,pap), top-levelattack(full freetext ATT&CK tag strings) andtagslists, andattributeslist (type,value,category,to_ids,comment) tlp/papvalues are normalized to the correct MISP taxonomy casing automatically (tlp:{value}lowercased,PAP:{VALUE}uppercased)- Structural validation (
validate_import_schema) catches malformed import files before any MISP write; actual MISP attribute type validation is left to PyMISP itself, for more precise error messages - Attributes rejected by PyMISP (unknown type) are skipped individually with a warning rather than failing the whole import
- Post-build compliance check reusing
mispsk.taxonomy.check_event(TLP/PAP/ATT&CK), computed on the local event before writing, shown in the tree summary even in--dry-run --file/--files(mutually exclusive) for single or batch import, one MISP event per YAML file--dry-run: preview the constructed event(s) without writing to MISP- Tree-style terminal output, same visual style as
ioc_enrich.py - A file that fails to load/parse/validate is skipped individually; the batch continues. Exit code 1 only if every file in the batch failed
tests/test_event_builder.py: unit test coverage for YAML loading, schema validation, event construction, tag/attribute assembly, tree output, and the dry-run/write-mode import paths
Fixed
mispsk/taxonomy.py:check_event()usedevent.iddirectly, which raisedAttributeErroron a MISPEvent built locally viaevent_builder.pyand never written to MISP (i.e. duringevent_import.py --dry-run). Now usesevent.get("id"), returningNonegracefully instead.
Known limitations
- Create-only:
event_import.pyalways creates a new MISP event, it cannot update an existing one - ATT&CK tags must be supplied as full freetext tag strings, not as bare technique IDs - mispSK does not embed a MITRE ATT&CK ID-to-name mapping table
See CHANGELOG.md and ROADMAP.md for full details.