opencti icon indicating copy to clipboard operation
opencti copied to clipboard

Infrastructure Breaking Investigations

Open explorecti opened this issue 1 year ago • 6 comments

Description

When selecting infrastructure(add only) from a created or existing investigation all targets are shown/expanded.

Environment

  1. OS: Ubuntu
  2. OpenCTI version: 6.0.10
  3. OpenCTI client: Frontend

Reproducible Steps

Steps to create the smallest reproducible scenario:

  1. Create a new investigation
  2. Add entities and select TYPE: INFRASTRUCTURE
  3. Select and click to expand
  4. Under "All types of target" select Infrastructure
  5. click EXPAND
  6. Results show ALL

Expected Output

Should only return Infrastructure target

Actual Output

Returns all targets

Additional information

None

Screenshots (optional)

None

explorecti avatar Apr 24 '24 12:04 explorecti

Can't reproduce it. MalwareA targeting multiple entities. MalwareA targeting Infra1. Creating investigation that contains MalwareA. Expand -> Infrastructure. Only Infra1 appears. image

Do you have any additional information about your situation?

Jipegien avatar Apr 25 '24 07:04 Jipegien

@Jipegien Please select Type "Infrastructure" when adding entities then expand just the "All types of targets" and choose "Infrastructure", then it displays all targets. Don't use Malware as the example because that doesn't expose the issue.

explorecti avatar Apr 25 '24 10:04 explorecti

@explorecti I confirm, I've been able to reproduce, by first adding the entity type = infra in the graph, then choosing to expand only infra, resulting in having not only infrastructures but all other linked entities added to my graph.

nino-filigran avatar Apr 25 '24 12:04 nino-filigran

Is there an update when this will be fixed?

explorecti avatar May 22 '24 19:05 explorecti

Hi @explorecti as you can see @SarahBocognano assigned herself on the ticket. Before, nobody did work on this. Therefore, this will be fixed soon. The ticket will be updated once done.

nino-filigran avatar May 23 '24 07:05 nino-filigran

Update: This issue is applicable to all entities, example :

  • I add a threat Actor in investigation
  • I select this threat actor
  • I select "Threat Actor" to expand only Result : Every other relationships of this entity if expanded too

SarahBocognano avatar May 29 '24 09:05 SarahBocognano