muchdogesec / arango_cti_processor

A small script that creates relationships between common CTI knowledge-bases in STIX 2.1 format.
https://www.dogesec.com/
GNU Affero General Public License v3.0
3 stars 0 forks source link

Create new cve-cpe relationships #21

Open himynamesdave opened 1 month ago

himynamesdave commented 1 month ago

given we made some major changes to cve2stix, we need to completely rewrite the cve-cpe mode as follows

https://github.com/muchdogesec/arango_cti_processor/blob/embedded-relationship-tests/docs/cve-cpe.md

himynamesdave commented 1 week ago

@fqrious I've added some tests

In doing so, I realised we could improve the logic

  1. lookup of software objects
  2. arango note

see here: https://github.com/muchdogesec/arango_cti_processor/commit/0f5ed77e07ad36479283b47fb076e08c3231285e

fqrious commented 1 week ago

what makes this new method more efficient? also, I don't think swid is equivalent to matchCriteriaId

979F9EB6-C9F6-49EE-9FED-2ED17E400E86 not found no match