oasis-tcs / cti-stix2

OASIS CTI TC: Provides issue tracking and wiki pages for the STIX 2.x Work Products
https://github.com/oasis-tcs/cti-stix2
Other
24 stars 9 forks source link

Threat-Actor/Malware renaming/rebranding - New SRO #303

Open sheetlaand opened 1 year ago

sheetlaand commented 1 year ago

Hello, We would like to propose a new SRO (STIX Relationship Object) between two Threat-Actors or between two Malwares. Indeed, we see in the past that some groups shut down its activities, and join new groups. For example, with an high confidence, we saw that Conti members joined other affiliates such as KaraKurt or BlackBasta. But, we can't properly define the relationship between two Actors, based on the existing SROs. Our wish is then to be able to add a "rebrands-as" relationship, to better explain the global threat ecosystem. Does it make sense for you ? Thank you ! Regards,

lpingree commented 1 year ago

Makes total sense and important for actor following IMHOSincerely,Lawrence PingreeOn Jan 24, 2023, at 10:08 AM, sheetlaand @.***> wrote: Hello, We would like to propose a new SRO (STIX Relationship Object) between two Threat-Actors or between two Malwares. Indeed, we see in the past that some groups shut down its activities, and join new groups. For example, with an high confidence, we saw that Conti members joined other affiliates such as KaraKurt or BlackBasta. But, we can't properly define the relationship between two Actors, based on the existing SROs. Our wish is then to be able to add a "rebrands-as" relationship, to better explain the global threat ecosystem. Does it make sense for you ? Thank you ! Regards,

—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you are subscribed to this thread.Message ID: @.***>

srrelitz2 commented 3 months ago

related to #304

jordan2175 commented 3 months ago

You probably do not need a new SRO but rather just a relationship type. The plan all along was that the relationship types would be open vocabularies that could grow and expand outside of updating the specification.