opencti
opencti copied to clipboard
Handling Revoked or Expired Observables
trafficstars
Use case
Currently we are sharing observables. However, if an indicator is revoked or expired, this information is not pushed to an observable. Meaning we are sharing observables that should not be shared as they have been revoked.
Current Workaround
Have an external script query the indicators, then modify the observables.
Proposed Solution
Have a retention policy that allows us to delete observables if the indicator is revoked or expired.
Do you want me to close this if it is marked as duplicate?