Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mandiant connector: valuable Indicator data is not ingested in the platform #3375

Open
fruitcakej opened this issue Jan 31, 2025 · 0 comments
Labels
feature use for describing a new feature to develop needs triage use to identify issue needing triage from Filigran Product team

Comments

@fruitcakej
Copy link

Use case

When I look at the Indicator entities that the mandiant connector is ingesting, the entities are lacking data that should be available in the Mandiant API output

  • mscore (numeric)
  • source (text)
  • osint source (boolean)
  • reference url to Mandiant Advantage

I understand the 'mscore' is mapped to 'score' within the platform already.
The data should be available in the Indicator entity in such a way that we can build playbooks around it.

Current Workaround

Proposed Solution

We understand that this is being replaced with the new Google TI API, but perhaps this could be implemented in the new connector.

Additional Information

@fruitcakej fruitcakej added feature use for describing a new feature to develop needs triage use to identify issue needing triage from Filigran Product team labels Jan 31, 2025
@romain-filigran romain-filigran transferred this issue from OpenCTI-Platform/opencti Jan 31, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature use for describing a new feature to develop needs triage use to identify issue needing triage from Filigran Product team
Projects
None yet
Development

No branches or pull requests

1 participant