-
Notifications
You must be signed in to change notification settings - Fork 799
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support "content_ref" for StixFile to Artifact (obs_content ?) relation #2414
Labels
Milestone
Comments
Kedae
added a commit
that referenced
this issue
Oct 19, 2022
Kedae
added a commit
that referenced
this issue
Oct 19, 2022
Kedae
added a commit
that referenced
this issue
Oct 19, 2022
Kedae
added a commit
that referenced
this issue
Oct 21, 2022
Kedae
added a commit
that referenced
this issue
Oct 24, 2022
Kedae
added a commit
that referenced
this issue
Oct 24, 2022
Kedae
added a commit
that referenced
this issue
Oct 24, 2022
Kedae
added a commit
that referenced
this issue
Oct 25, 2022
Kedae
added a commit
that referenced
this issue
Oct 25, 2022
richard-julien
added a commit
that referenced
this issue
Oct 25, 2022
Co-authored-by: Julien Richard <julien.richard@filigran.io>
richard-julien
added
the
solved
use to identify issue that has been solved (must be linked to the solving PR)
label
Oct 25, 2022
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Description
Uncertain if this is a limitation in
client-python
or inopencti
, however I encounter it when trying to use a connector. Trying to import aStixFile
andArtifact
and want to use the STIX 2.1content_ref
field to store the STIX id of the uploaded Artifact, per https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html#_99bl2dibcztv.When the upload for the STIX File is attempted (and the Artifact already does exist at this point in OpenCTI), the following error is displayed in the connector log:
The following is an example bundle that's displayed as the culprit:
If I use the STIX File
contains_refs
field instead, with the same Artifact id, the nested relationship is formed correctly in every case I've tested so far.For an example derived from above, the following bundle doesn't cause the error, and the observables get related:
Reproducible Steps
See description above, not easily reproducible via UI. See the following commit for an explanation of what's missing and the workaround I'm using instead:
Expected Output
When the STIX File is uploaded, it will be linked to the Artifact object that I referenced somehow. My preference would be a link being present on the main Details section of the Observable's overview. It should also still show up as a nested relationship in the Knowledge section, but with some UI marker highlighting it as the "File contents" relationship. The "contains_refs" relationships should continue to only show up on the Knowledge page, as today.
Actual Output
Error with no relationship being created at all:
The text was updated successfully, but these errors were encountered: