Repository navigation
misp-stix 2026.7.8 - Sturdier STIX patterns, fail-loud input validation, and TLP fixes
When Conversion Should Fail Loudly - and When It Shouldn't Fail at All
misp-stix is the library that converts threat intelligence in both directions
between MISP and STIX, and it is the same engine behind the browser-based
conversions on cti-transmute.org. This release is
less about new mappings than about making the conversions you already rely on
behave predictably: objects that used to be silently dropped now export
correctly, input that isn't a MISP event is rejected up front with a clear
error instead of an opaque stack trace, and hash and marking handling was
tightened on both the export and import sides.
The changes below will be brought to CTI-Transmute with the next upcoming
release, landing there soon - so you will be able to put them straight to the
test against your own data in the browser, at
cti-transmute.org, without installing anything
locally.
Changelog - 2026.6.25 → 2026.7.8
STIX patterns no longer silently drop objects
The central pattern-value handling escaped apostrophes but never backslashes, so
any value containing one - Windows filenames, file paths, registry key names -
produced a lexically-invalid STIX pattern. Indicator creation then raised and
the whole object was silently dropped from the output. Escaping is now
centralised in a shared _escape_pattern_value helper (backslash first, then
apostrophe) and reused across the pattern builders, so those objects export to
valid Indicators. The registry-key path was reconciled through the same helper -
_sanitise_registry_key_value now only folds % markers - with no change to its
resulting output.
- a57e3eb - escape backslashes via a shared
_escape_pattern_valuehelper - b658f26 - behaviour tests (file and lnk objects with backslashes plus an
apostrophe) and unit tests covering escape order and the no-op cases
Invalid input now fails loudly instead of confusingly
Feeding the exporters content that isn't a MISP event - or a MISP structure at
the wrong layer - used to fail deep inside the conversion with an opaque error.
A new InvalidMISPInputError is now raised up front: both the STIX 1 and STIX 2
export paths detect the shape of the input (STIX 2's parse_json_content
included) and reject non-MISP or wrong-layer content with a clear message.
Exposing a dedicated exception type also lets consumers such as CTI-Transmute
catch the right error and surface a meaningful message to the user, instead of
having to guess at a generic failure. Key-validation errors were also attached
to their proper context rather than to a generic "misp event" sentinel.
- c45a75c - add the
InvalidMISPInputErrorexception - 17d0c5b, 6f4ba27 - detect input shape and raise on non-MISP input (STIX 2
and STIX 1) - 10c2793 - attach key-validation errors to their context
- d2d1782 - tests covering non-MISP / wrong-layer input across STIX 1, 2.0 and 2.1
One clear error per invalid hash
Invalid hash values used to raise inconsistent, sometimes duplicated errors
during export. InvalidHashValueError is now centralised with context-specific
messages, and each invalid hash produces exactly one consistently-labelled error
instead of several.
- 7b275ae - a single consistently-labelled error per invalid hash
- ee2e928 - centralise
InvalidHashValueErrorwith context-specific messages - 3649905 - tests asserting a single error is raised per invalid hash
TLP and marking handling
A round of fixes around TLP tags and marking definitions. On STIX 1 export, the
TLP-tag check method was declared on the Events parser but used from the shared
parent class, so the Attributes parser could not see it; it is now available to
both (fixes #86). Marking definitions imported back to MISP TLP tags gained test
coverage across internal and external STIX 2.0 and 2.1, and TLP mapping entries
that were never reached (tlp:green, tlp:amber, tlp:red) were removed.
- 014e5ea - make the TLP-tag check method available to both the Attributes and
Events parsers (#86) - f2e6556 - drop unreachable TLP mapping entries
- 3ea88c8 - tests for markings imported back to TLP tags
Import simplification
artifact and hashlookup patterns now go through the standard pattern-parsing
path on the way back to MISP, removing the special-case handling that had
accumulated in the indicator converter.
- a2072fa - use standard pattern parsing for
artifactandhashlookup
conversion back to MISP
Maintenance
Dependency refresh and lock-file bump. Two releases were cut in this window:
2026.6.30 and 2026.7.8.