opencti icon indicating copy to clipboard operation
opencti copied to clipboard

Relationship Phishing attack pattern delivers Cobalt Strike is correct ?

Open JeromeSRT opened this issue 2 years ago • 0 comments

Prerequisites

  • [x] I read the Deployment and Setup section of the OpenCTI documentation as well as the Troubleshooting page and didn't find anything relevant to my problem.
  • [x] I went through old GitHub issues and couldn't find anything relevant
  • [x] I googled the issue and didn't find anything relevant

Description

When I select the courses of action in the attack patterns panel of Cobalt Strike, I have an error (cf. Screenshots)

Environment

  1. OS (where OpenCTI server runs): Monterey 12.4
  2. OpenCTI version: OpenCTI 5.3.7
  3. OpenCTI client: frontend
  4. Other environment details: Firefox 101.0.1

Reproducible Steps

Steps to create the smallest reproducible scenario:

  1. Select attack patterns panel of Cobalt Strike
  2. Click course of action button

Additional information

I noticed in a report the existence of a delivers relationship between an attack pattern and Cobalt Strike. I found other types of this relationship between attack patterns and malwares in some reports, and I have the same error for these malwares. Do you think it is the cause of this error ?

image

image

JeromeSRT avatar Jun 24 '22 07:06 JeromeSRT