Conversation
Removed link reference to UNC4841 activity from GhostEmperor value. After research and speaking with authors of the report, these two clusters of activity are unrelated.
|
Ah, that’s on me—thanks for catching it. I initially added that link based on the following observations from Mandiant and to reflect the fact that
However, I overlooked that the blog focuses solely on |
|
But, I really thik we should capture the reference of linking |
|
A relationship ( |
I'm okay with this though I wouldn't normally describe use of the same anonymization services or service provider as an overlap. |
@validhorizon, I think you misinterpreted. Mandiant said
@adulau, I added misp-galaxy/clusters/threat-actor.json Lines 15282 to 15296 in ebb6261 |
|
If it's only similar techniques, then I would go for a new relationship https://misp-project.org/objects.html#_relationships (for your reference existing relationships but we can easily extend it). We could also add relationship |
Yes but as I said, I already added |
|
Sure. Will you make an updated PR? |
|
No need to update, we can close this PR once if @validhorizon is ok with this as we discussed. |
|
After discussion with Rony, this commit is closed |
Hi @adulau, is there any official documentation outlining the properties (both required and optional) that can be assigned to a threat actor? Currently, we use fields like refs, country, synonyms, etc. under meta for our threat actor entities in the MISP galaxy JSON file. |
Removed link reference to UNC4841 activity from GhostEmperor value. After research and speaking with authors of the report, these two clusters of activity are unrelated.