unfetter
unfetter copied to clipboard
Add ability to import STIX bundles into analytic exchange
This could not be accomplished with a generic import STIX bundle feature, due to the following:
- Multiple meta properties are mapped to fake extended properties
- Sensors are mapped via fake relationships to abstract away data path complexity
- Sensors don't have data model
- Data path of sensors is not exported
- Possible merge problems with attack patterns
I would recommend ignoring sensors/data path for the time being, and simply focusing on getting the indicators and attack pattern relationships in there.
I think limiting to indicators and attack patterns make sense to start with.
I also don't think it should be based on the whole stix collection being missing.