CrowdStrike / MISP-tools

Import CrowdStrike Threat Intelligence into your instance of MISP
MIT License
41 stars 10 forks source link

Events being created for individual indicators #57

Closed jezkerwin closed 2 years ago

jezkerwin commented 2 years ago

I'm curious as to why events are being created in MISP that only have 1 indicator in them? It makes for a very messy MISP instance. It would be nice if there was a way to stop this or group all those individual indicators into a single MISP event for those not related to a CS report of actor.

jshcodes commented 2 years ago

Hi @jezkerwin -

We are in the process of updating this integration to speak to this concern, and will be testing aggregating indicators without these relationships by malware family in our next version. (v0.6.4, in flight now. You should see this branch post early this week.)

As this issue duplicates #45, I'm closing this one. We will use #45 to track this enhancement. 😃