mitre / cti

Cyber Threat Intelligence Repository expressed in STIX 2.0
Other
1.71k stars 410 forks source link

Some revoked attack pattern miss the revoked-by relation in mobile domain #208

Closed s920128 closed 10 months ago

s920128 commented 1 year ago

Hi I found some revoked attack pattern, which marked as revoked=true, miss the revoked-by relation in mobile domain. Revoked objects will create a revoked-by relationship, according to working-with-deprecated-and-revoked-objects(In the case of revoked objects, a relationship of type revoked-by is also created targeting the replacing object.). This result is strange to me. Can someone explain this?

The 11 revoked attack pattern:

T1415 (attack-pattern--8f142a25-f6c3-4520-bd50-2ae3ab50ed3e)
T1419 (attack-pattern--89fcd02f-62dc-40b9-a54b-9ac4b1baef05)
T1431 (attack-pattern--6b846ad0-cc20-4db6-aa34-91561397c5e2)
T1434 (attack-pattern--1f96d624-8409-4472-ad8a-30618ee6b2e2)
T1440 (attack-pattern--b765efd1-02e6-4e67-aebf-0fef5c37e54b)
T1441 (attack-pattern--a21a6a79-f9a1-4c87-aed9-ba2d79536881)
T1442 (attack-pattern--e30cc912-7ea1-4683-9219-543b86cbdec9)
T1443 (attack-pattern--831e3269-da49-48ac-94dc-948008e8fd16)
T1445 (attack-pattern--51aedbd6-2837-4d15-aeb0-cb09f2bf22ac)
T1454 (attack-pattern--0bcc4ec1-a897-49a9-a9ff-c00df1d1209d)
T1455 (attack-pattern--c91c304a-975d-4501-9789-0db1c57afd3f)

Thanks

jondricek commented 1 year ago

Hey @s920128 - my team is actively looking into this issue starting this week. This is an artifact of us migrating to using ATT&CK Workbench last year for the v11 release, so the revoked-by relationships should still be able to be found in v10, although we are investigating how to best proceed in order to put them back in. Thank you for reaching out to us about the issue though.

jondricek commented 10 months ago

FWIW, we have gone through these STIX Relationships and they will be fully addressed in the upcoming v14 release later this month