You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Observable Value gets cleared when changing its type (importing it from an analyser result)
Request Type
Bug
Work Environment
Question
Answer
OS version (server)
Ubuntu 18.04 LTS
OS version (client)
Windows
TheHive version / git hash
3.12
Package Type
VM running the Hive provided at the Hack.lu training
Problem Description
When importing an observable extracted by an analyser, it may happen that the type of observable is wrong. For example filename.zip being treated as a domain instead of a filename. But when correcting this in the "Create new observable(s)" windows (by changing the type in the "Type" dropdown menu), the content of the "Value" field gets cleared. Thus, it's not possible to change correct any mis-parsed obervable type.
Steps to Reproduce
Have a Cortex analyser with "Extract observables" turned on
Analyse an observable with this analyser
Show the extracted observables
Tick one to import
Change the type of data (if the analyser wrongly parses the data)
The "Value" field will be deleted
Possible Solutions
When changing the type of an observable (extracted from an analyser result), keep the value field that is created by the analyser export. This is already done for the fields Descriptions and tags, which are kept even when changing the observable type.
Complementary information
This is done live from the MISP/TheHive hack.lu workshop. I'm discovering this tool and it's pretty awesome. Great job !
The text was updated successfully, but these errors were encountered:
Observable Value gets cleared when changing its type (importing it from an analyser result)
Request Type
Bug
Work Environment
Problem Description
When importing an observable extracted by an analyser, it may happen that the type of observable is wrong. For example
filename.zip
being treated as adomain
instead of afilename
. But when correcting this in the "Create new observable(s)" windows (by changing the type in the "Type" dropdown menu), the content of the "Value" field gets cleared. Thus, it's not possible to change correct any mis-parsed obervable type.Steps to Reproduce
The "Value" field will be deleted
Possible Solutions
When changing the type of an observable (extracted from an analyser result), keep the
value
field that is created by the analyser export. This is already done for the fieldsDescriptions
andtags
, which are kept even when changing the observable type.Complementary information
This is done live from the MISP/TheHive hack.lu workshop. I'm discovering this tool and it's pretty awesome. Great job !
The text was updated successfully, but these errors were encountered: