Skip to content

misp-stix 2026.6.25: Broader Object Coverage and Sturdier Round-Trips

Choose a tag to compare

@chrisr3d chrisr3d released this 25 Jun 12:11
· 198 commits to main since this release
944a5da

Bridging MISP and STIX: Try the Extended Conversion Capacity

The conversions shown in the screenshots below from cti-transmute.org are produced by misp-stix, the library that converts threat intelligence in both directions between MISP and STIX 2.x.

The changes described below are already deployed on CTI-Transmute. The newly mapped hashlookup, directory and artifact objects, the broader registry-key coverage, and the Galaxy Cluster and import fixes can all be exercised there directly: visit cti-transmute.org and convert your data in the browser, without installing anything locally.

Screenshot 2026-06-25 at 12 02 24 Screenshot 2026-06-25 at 12 10 59

Changelog - 2026.6.1 → 2026.6.25

Three more MISP objects converted end to end

Three MISP object templates that previously had no dedicated mapping — and therefore
fell through to a generic x-misp-object custom object — are now first-class citizens
with full round-trip support to and from STIX 2.0 and 2.1.

  • hashlookup now maps to a STIX File observable, plus an Indicator when its
    attributes carry the to_ids flag. Before this change the object was emitted as a
    custom object, so no Indicator was produced for its hashes even with to_ids set
    (issue #56). On the way back, a File Observable and/or Indicator is reconstructed into
    a hashlookup object.
  • directory is converted to a STIX Directory observable and/or Indicator (path,
    path-encoding), with the reverse path rebuilding the object on import.
  • artifact is converted to a STIX Artifact observable and/or Indicator, carrying
    its mime_type, url, payload and the full set of supported hash types, and is
    imported back into an artifact object — including correct handling of the
    has_encryption field.

Each object gained export, import and round-trip tests so the conversion stays stable in
both directions.

Registry keys: single, multiple, and standalone values

Registry key conversion previously assumed exactly one value per key, matching the shape
of the MISP object template. With the External STIX 2.x converter now able to turn a STIX
Registry Key into a registry-key object plus several registry-key-value objects, the
export side was reworked to cover every case: a registry key with a single value, a
registry key with multiple values, and standalone registry-key-value objects on their
own. Pattern handling was improved on the way out, and the import side learned to map the
different key-and-value combinations back to MISP — without processing STIX 2.0 registry
key indicators twice.

Galaxy Cluster export hardening

A series of fixes made Galaxy Cluster conversion robust against clusters that omit fields
the export code used to assume were always present. A missing meta field no longer
raises a KeyError, sector clusters without a timestamp are handled gracefully,
attribute-level location clusters are converted correctly, and ACS marking clusters with
no meta field now export (STIX 2.0) and import back cleanly.

Import robustness fixes

Two defensive fixes on the import path:

  • Domain observable reuse assumed a reused observable always carried a misp_attribute.
    In mixed domain / domain-ip flows the observable may instead be stored as a
    misp_object, which raised KeyError('misp_attribute') on reprocessing. Both domain
    observable reference parsers now fall back to misp_object and only touch the content
    when it exists, matching the defensive handling already used elsewhere. (PR #84)

  • A duplicated Identity conversion was removed: the reusable conversion method already
    produces the MISP object, so the leftover inline block that built a second one is gone.

  • 2e9bd92 — guard domain observable reuse against a missing misp_attribute

  • 88d5041 — remove duplicated identity object conversion calls

Documentation

The few SDOs and use cases that were not yet documented gained descriptions and
additional test coverage, and the mapping documentation was regenerated to reflect all of
the changes above.

Maintenance

Dependency refreshes, including pinning the latest versions of the STIX 1.x related
dependencies. Three releases were cut in this window: 2026.6.3, 2026.6.9 and
2026.6.25.