CrowdStrike / MISP-tools

Import CrowdStrike Threat Intelligence into your instance of MISP
MIT License
42 stars 10 forks source link

[RFI] Proper Method for adding our custom Tags? #42

Closed packet-rat closed 1 year ago

packet-rat commented 2 years ago

The 'old' method of adding our own tags do not seem to work.

Previously the following entries in the 'ini' file produced the desired outcomes of adding our own internal tags to CrowdStrike Actor, Report, and Indicator Events.

reports_tags = att:source="Crowdstrike.Report"
indicators_tags = att:source="Crowdstrike.Indicators"
actors_tags = att:source="Crowdstrike.Actors"
jshcodes commented 2 years ago

This was impacted by some of the taxonomic updates, and will be resolved as part of the 0.6.3 version.

jshcodes commented 1 year ago

Indicators got missed in this last update, resolved by #77.