Skip to content

[VulnCheck] Add STIX Reports to threat actors, ransomware, botnets sources #6148

Description

@maddawik

Description

The VulnCheck connector's advisory sources (threat actors, ransomware families, botnets)
produce STIX objects but don't wrap them in a stix2.Report. This means the intelligence
can't be browsed as a coherent unit in OpenCTI's Reports view — a threat actor and its
associated vulnerabilities and relationships are visible individually but not grouped.

Expected behaviour

Each threat actor, ransomware family, and botnet entity produces a stix2.Report
referencing its associated STIX objects, making the advisory intelligence browsable as a
unit in OpenCTI's Reports view.

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureType: new feature or capability (feat:).

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions