Repository navigation
misp-stix 2026.6.25: Broader Object Coverage and Sturdier Round-Trips
Bridging MISP and STIX: Try the Extended Conversion Capacity
The conversions shown in the screenshots below from cti-transmute.org are produced by misp-stix, the library that converts threat intelligence in both directions between MISP and STIX 2.x.
The changes described below are already deployed on CTI-Transmute. The newly mapped hashlookup, directory and artifact objects, the broader registry-key coverage, and the Galaxy Cluster and import fixes can all be exercised there directly: visit cti-transmute.org and convert your data in the browser, without installing anything locally.
Changelog - 2026.6.1 → 2026.6.25
Three more MISP objects converted end to end
Three MISP object templates that previously had no dedicated mapping — and therefore
fell through to a generic x-misp-object custom object — are now first-class citizens
with full round-trip support to and from STIX 2.0 and 2.1.
hashlookupnow maps to a STIX File observable, plus an Indicator when its
attributes carry theto_idsflag. Before this change the object was emitted as a
custom object, so no Indicator was produced for its hashes even withto_idsset
(issue #56). On the way back, a File Observable and/or Indicator is reconstructed into
ahashlookupobject.directoryis converted to a STIX Directory observable and/or Indicator (path,
path-encoding), with the reverse path rebuilding the object on import.artifactis converted to a STIX Artifact observable and/or Indicator, carrying
itsmime_type,url, payload and the full set of supported hash types, and is
imported back into anartifactobject — including correct handling of the
has_encryptionfield.
Each object gained export, import and round-trip tests so the conversion stays stable in
both directions.
- 5e74cab, 6721124, e6f6a92, a9021ca, 9e59e30 —
hashlookupexport, import and tests - dbeb197, fcd74d2, 400f7d3, 7b8237f —
directoryexport, import and tests - 8a72575, 074933d, f4f904e, 1234224, 36b6446, 341910a —
artifactexport, import and tests
Registry keys: single, multiple, and standalone values
Registry key conversion previously assumed exactly one value per key, matching the shape
of the MISP object template. With the External STIX 2.x converter now able to turn a STIX
Registry Key into a registry-key object plus several registry-key-value objects, the
export side was reworked to cover every case: a registry key with a single value, a
registry key with multiple values, and standalone registry-key-value objects on their
own. Pattern handling was improved on the way out, and the import side learned to map the
different key-and-value combinations back to MISP — without processing STIX 2.0 registry
key indicators twice.
- efc09d0, 902ab5d, 763913f — single, multiple and standalone value export handling
- e8aa3d3, 344fa79 — import of the different registry key and value use cases
- 58d05df, 2746596, b50f026, bc1cb13 — tests across the use cases, both directions
Galaxy Cluster export hardening
A series of fixes made Galaxy Cluster conversion robust against clusters that omit fields
the export code used to assume were always present. A missing meta field no longer
raises a KeyError, sector clusters without a timestamp are handled gracefully,
attribute-level location clusters are converted correctly, and ACS marking clusters with
no meta field now export (STIX 2.0) and import back cleanly.
- 7bdfd22, cf43e48, 22561c3 —
meta, sector timestamp and attribute-level location fixes - 1605c31, 9b6c469 — ACS marking clusters with no
metafield, export and import - bc60783, 2a46497 — additional and round-trip tests for the above
Import robustness fixes
Two defensive fixes on the import path:
-
Domain observable reuse assumed a reused observable always carried a
misp_attribute.
In mixed domain / domain-ip flows the observable may instead be stored as a
misp_object, which raisedKeyError('misp_attribute')on reprocessing. Both domain
observable reference parsers now fall back tomisp_objectand only touch the content
when it exists, matching the defensive handling already used elsewhere. (PR #84) -
A duplicated Identity conversion was removed: the reusable conversion method already
produces the MISP object, so the leftover inline block that built a second one is gone. -
2e9bd92 — guard domain observable reuse against a missing
misp_attribute -
88d5041 — remove duplicated identity object conversion calls
Documentation
The few SDOs and use cases that were not yet documented gained descriptions and
additional test coverage, and the mapping documentation was regenerated to reflect all of
the changes above.
Maintenance
Dependency refreshes, including pinning the latest versions of the STIX 1.x related
dependencies. Three releases were cut in this window: 2026.6.3, 2026.6.9 and
2026.6.25.