-
Notifications
You must be signed in to change notification settings - Fork 230
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ReaQta Use TTP Custom Object #1473
Conversation
stix_shifter_modules/reaqta/stix_translation/json/to_stix_map.json
Outdated
Show resolved
Hide resolved
@@ -109,7 +110,8 @@ | |||
"network_ref.src_ref.value": ["ip"], | |||
"parent_process_ref.pid": ["service.ppid"], | |||
"process_ref.pid": ["wmi.clientPid"], | |||
"user_ref.user_id": [] | |||
"user_ref.user_id": [], |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why is this mapping to an empty list of fields?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is what it was, I just delete the comma at the end to make it valid Json.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It should just be removed, it shouldn't be there because it's not actually mapping to anything.
Codecov ReportPatch coverage:
Additional details and impacted files@@ Coverage Diff @@
## develop #1473 +/- ##
===========================================
- Coverage 85.18% 85.18% -0.01%
===========================================
Files 679 679
Lines 53153 53149 -4
===========================================
- Hits 45279 45275 -4
Misses 7874 7874
☔ View full report in Codecov by Sentry. |
92134e6
to
e99e779
Compare
e99e779
to
beca23f
Compare
@@ -1824,8 +1824,8 @@ | |||
"object": "x-reaqta" | |||
}, | |||
"tactics": { | |||
"key": "x-reaqta-event.tactics", | |||
"object": "x-reaqta" | |||
"key": "x-ibm-finding.ttp_tagging_refs", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You need to also create an x-ibm-ttp-tagging
object when the tactics and technique fields are in the native results. This is the object that the x-ibm-finding.ttp_tagging_refs
will reference. For an example of referencing, take a look at how the x-oca-asset.ip_refs
references the src_ip
in this same file.
"tactics": [ | ||
{ | ||
"key": "x-ibm-finding.ttp_tagging_refs", | ||
"object": "x-ibm-finding" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Since this is a reference key, you also need to include a "references" property that maps to the ttp object. In this case it would be "references": ["x-ibm-ttp-tagging"]
stix_shifter_modules/reaqta/stix_translation/json/stix_2_1/to_stix_map.json
Show resolved
Hide resolved
"tactics": [ | ||
{ | ||
"key": "x-ibm-finding.ttp_tagging_refs", | ||
"object": "x-ibm-finding" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
missing references property
"technique": [ | ||
{ | ||
"key": "x-ibm-finding.ttp_tagging_refs", | ||
"object": "x-ibm-finding" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
missing references property
a43dab7
to
e9e3eef
Compare
No description provided.