opencti
opencti copied to clipboard
Bulk Search - inconsistent results involving HashedObservable objects
Description
Okay, here's the scenario. I have a list of IOCs I want to search in OpenCTI - domain names, IPs, file hashes, cert hashes, etc. I put them in bulk search. Some of the IOCs are not in the system and are listed as UNKNOW in the bulk search results. If at least one of the hashes is in the system, all of the UNKNOWN results disappear.
Environment
- OS (where OpenCTI server runs): Docker image
- OpenCTI version: 6.2.3
- OpenCTI client: frontend
Reproduced. Seems to be well related to doing research with hashes and other observables of other types.