Skip to content

v0.7 - Structured Event Import

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 15 Aug 19:11
· 5 commits to main since this release

Eighth release of mispSK.

Added

  • event_import.py: build and import one or more MISP events from structured YAML report files
  • mispsk/event_builder.py: load_import_file, validate_import_schema, build_event_from_data, add_context_tags_from_data, add_attack_tags_from_data, add_attributes_from_data, build_import_tree_output, import_event
  • YAML import format: event block (info, distribution, threat_level, analysis, tlp, pap), top-level attack (full freetext ATT&CK tag strings) and tags lists, and attributes list (type, value, category, to_ids, comment)
  • tlp/pap values are normalized to the correct MISP taxonomy casing automatically (tlp:{value} lowercased, PAP:{VALUE} uppercased)
  • Structural validation (validate_import_schema) catches malformed import files before any MISP write; actual MISP attribute type validation is left to PyMISP itself, for more precise error messages
  • Attributes rejected by PyMISP (unknown type) are skipped individually with a warning rather than failing the whole import
  • Post-build compliance check reusing mispsk.taxonomy.check_event (TLP/PAP/ATT&CK), computed on the local event before writing, shown in the tree summary even in --dry-run
  • --file / --files (mutually exclusive) for single or batch import, one MISP event per YAML file
  • --dry-run: preview the constructed event(s) without writing to MISP
  • Tree-style terminal output, same visual style as ioc_enrich.py
  • A file that fails to load/parse/validate is skipped individually; the batch continues. Exit code 1 only if every file in the batch failed
  • tests/test_event_builder.py: unit test coverage for YAML loading, schema validation, event construction, tag/attribute assembly, tree output, and the dry-run/write-mode import paths

Fixed

  • mispsk/taxonomy.py: check_event() used event.id directly, which raised AttributeError on a MISPEvent built locally via event_builder.py and never written to MISP (i.e. during event_import.py --dry-run). Now uses event.get("id"), returning None gracefully instead.

Known limitations

  • Create-only: event_import.py always creates a new MISP event, it cannot update an existing one
  • ATT&CK tags must be supplied as full freetext tag strings, not as bare technique IDs - mispSK does not embed a MITRE ATT&CK ID-to-name mapping table

See CHANGELOG.md and ROADMAP.md for full details.