Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support Indicator with STIX patterns #9

Open
misje opened this issue Apr 29, 2024 · 0 comments
Open

Support Indicator with STIX patterns #9

misje opened this issue Apr 29, 2024 · 0 comments
Assignees
Labels
enhancement New feature or request

Comments

@misje
Copy link
Owner

misje commented Apr 29, 2024

By using a translator like STIX-shifter, or a similar project that already implements the grammar, like stix2patterns, STIX patterns could be translated into an OpenSearch DSL query. This requires a translator and a model, since Wazuh doesn't really have a common schema for alerts.

Adding direct indicator support would be incredibly useful. The current implementation depends on relationships between indicators and observables ("based-on"). These are fortunately often provided, but they only make sense when the indicator pattern is trivial. Additionaly, some sources also only provide a STIX pattern, without any references to observables.

@misje misje added the enhancement New feature or request label Apr 29, 2024
@misje misje self-assigned this Apr 29, 2024
@misje misje added this to the 0.2.0 milestone Apr 29, 2024
@misje misje modified the milestones: 0.3.0, 0.4.0, Distant future Jun 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant