Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Error when displaying a new kill chain created in Matrix View #8990

Open
lightw1s3 opened this issue Nov 13, 2024 · 0 comments
Open

Error when displaying a new kill chain created in Matrix View #8990

lightw1s3 opened this issue Nov 13, 2024 · 0 comments
Labels
bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team

Comments

@lightw1s3
Copy link

Description

The TTPs associated to a newly created kill chain are not correctly displayed in the section Knowledge > Attack Patterns > in Matrix View.
In addition to having the main ones, MITRE or associated and DISARM, it is necessary to create a new Kill Chain where the Mitre TTPs are reused.
However, when visualizing the matrix, not all the phases of the kill chain created appear.

Environment

  1. OS (where OpenCTI server runs): docker
  2. OpenCTI version: 6.3.11
  3. OpenCTI client: frontend

Reproducible Steps

Steps to create the smallest reproducible scenario:

  1. Go to Settings > Taxonomies > Kill chain phases and create a new kill chain called operator-chain in which 3 phases have been defined

Image

  1. The following TTPs are used as examples to associate them as examples to each of the phases created:
  • T1595.001: Relates to phase1.
  • T1053.002 and T1217: Relates to phase2
  • T1119: Relates to phase3

Image

Image

Image

Image

  1. An example Threat Actor (group) is created, with the TTP section empty and access to its Knowledge > Attack Patterns > Matrix View section.

Image

  1. And as you can see in this last capture, the first phase does not appear.
    Image

Expected Output

It is expected that this image will show the complete new kill chain, i.e. with all the associated TTPs.

@lightw1s3 lightw1s3 added bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team labels Nov 13, 2024
@romain-filigran romain-filigran added needs triage use to identify issue needing triage from Filigran Product team and removed needs triage use to identify issue needing triage from Filigran Product team labels Nov 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team
Projects
None yet
Development

No branches or pull requests

2 participants