Skip to content

Conversation

ljstella
Copy link
Contributor

Adding the mitre_attack_id field back to the detection tags model so that SSE doesn't break- Their move to support the new API did not include support for the tag.mitre_attack_enrichments[] object, so sometimes our content just doesn't show up as mapped without this.

Also tweaked the regex in mitre_attack_id because I was getting runtime errors on the use of \d to grab digits.

@ljstella ljstella added the bug Something isn't working label Jul 12, 2024
@ljstella ljstella requested a review from pyth0n1c July 12, 2024 18:43
@ljstella ljstella self-assigned this Jul 12, 2024
Copy link
Contributor

@pyth0n1c pyth0n1c left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good, thanks Lou!
I have manually run this and verified the updated, correct output in detections.json.
I also confirmed this does not impact the output in the ESCU App itself.

@pyth0n1c pyth0n1c merged commit 861a475 into main Jul 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants