Description
The VulnCheck connector's advisory sources (threat actors, ransomware families, botnets)
produce STIX objects but don't wrap them in a stix2.Report. This means the intelligence
can't be browsed as a coherent unit in OpenCTI's Reports view — a threat actor and its
associated vulnerabilities and relationships are visible individually but not grouped.
Expected behaviour
Each threat actor, ransomware family, and botnet entity produces a stix2.Report
referencing its associated STIX objects, making the advisory intelligence browsable as a
unit in OpenCTI's Reports view.
Description
The VulnCheck connector's advisory sources (threat actors, ransomware families, botnets)
produce STIX objects but don't wrap them in a
stix2.Report. This means the intelligencecan't be browsed as a coherent unit in OpenCTI's Reports view — a threat actor and its
associated vulnerabilities and relationships are visible individually but not grouped.
Expected behaviour
Each threat actor, ransomware family, and botnet entity produces a
stix2.Reportreferencing its associated STIX objects, making the advisory intelligence browsable as a
unit in OpenCTI's Reports view.