Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[threat-actors] Add Alpha Spider #979

Conversation

Mathieu4141
Copy link
Contributor

No description provided.

@adulau
Copy link
Member

adulau commented May 23, 2024

Just a quick question, is there a specific use-case to put the ransomware groups in the threat actor galaxy? compared to use the ransomware group cluster https://github.com/MISP/misp-galaxy/blob/main/clusters/ransomware.json#L24593 ?

@r0ny123
Copy link
Contributor

r0ny123 commented May 23, 2024

For me, yes. From an attribution perspective, It is required for tracking devs and affiliates separately.

@adulau
Copy link
Member

adulau commented May 28, 2024

FYI, We did a major update in the ransomware group galaxy cluster. It's now inline with the ransomlook.io dataset. Maybe in the future, for ransomware group, I would really prefer to use that galaxy cluster. On the other hand, if the TA can be dissociated from the ransomware group then it makes sense to have those as `threat-actor.

@adulau adulau merged commit cd89716 into MISP:main May 28, 2024
4 checks passed
@Mathieu4141
Copy link
Contributor Author

Thanks for the review and context, will definitely take that into account next time!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants