MISP 2.4.118 release, malware information sharing platform

MISP 2.4.118 has been released, this version reads as follows:

Exclusive taxonomies

Previously, the introduction of the "exclusive" MISP classification field format, to define exclusionary rules in a given classification predicate. In this version, MISP user interface displays inconsistency between the exclusive event and enforce property level and distribution of labels.

Support SightingDB

SightingDB support includes the following:

  • Add Configuration Tool
  • Add Find the Events view
  • Added includeSightingdb flag restSearch search
  • Added SightingDB search tool
  • Added SightingDB connection test tool

Improvements in the meta search restSearch 

/attributes/restsearch/
{
    "galaxy.cfr-suspected-victims": ["China", "Japan"],
    "galaxy.cfr-target-category" : ["Government"]
}

 

/events/restsearch/
{
    "galaxy.synonyms": "APT29",
    "orgc.nationality": ["Hungary", "Belgium"]
}

MISP modules

Added many new modules, such as event Query Language (EQL) query module, EndGames EQL export module, OSINT.digitalside.it find modules and existing modules (such as CSV import module, IBMX-Force expansion modules, etc.) of a number of improvements .

For details, see the release notes .

Guess you like

Origin www.oschina.net/news/111274/misp-2-4-118-released