File tree 3 files changed +3
-3
lines changed
TA-opencti-add-on/default/data/ui/alerts 3 files changed +3
-3
lines changed Original file line number Diff line number Diff line change @@ -150,7 +150,7 @@ To extract and model alert fields as OpenCTI observables attached to the inciden
150
150
151
151
#### CIM model
152
152
153
- The “CIM Model ” method is based on the definition of CIM model fields. With this method, the Add-on will extract all the following fields and model them as follows:
153
+ The “CIM model ” method is based on the definition of CIM model fields. With this method, the Add-on will extract all the following fields and model them as follows:
154
154
155
155
| CIM Field | Observable type |
156
156
| -------------------| -------------------------------------|
Original file line number Diff line number Diff line change 1
- < form class ="form-horizontal form-complex "> < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_name "> Name < span class ="required "> *</ span > </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.name " id ="opencti_create_incident_name "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_description "> Description </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.description " id ="opencti_create_incident_description "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_type "> Type </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.type " id ="opencti_create_incident_type "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_severity "> Severity </ label > < div class ="controls "> < select name ="action.opencti_create_incident.param.severity " id ="opencti_create_incident_severity "> < option value ="low "> Low</ option > < option value ="medium "> Medium</ option > < option value ="high "> High</ option > < option value ="critical "> Critical</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_labels "> Labels </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.labels " id ="opencti_create_incident_labels "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_tlp "> TLP </ label > < div class ="controls "> < select name ="action.opencti_create_incident.param.tlp " id ="opencti_create_incident_tlp "> < option value ="tlp_clear "> TLP:CLEAR</ option > < option value ="tlp_green "> TLP:GREEN</ option > < option value ="tlp_amber "> TLP:AMBER</ option > < option value ="tlp_red "> TLP_RED</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_observables_extraction "> Observables extraction < span class ="required "> *</ span > </ label > < div class ="controls "> < select name ="action.opencti_create_incident.param.observables_extraction " id ="opencti_create_incident_observables_extraction "> < option value ="disable "> Disable</ option > < option value ="cim_model "> CIM Model</ option > < option value ="field_mapping "> OpenCTI Fields mapping</ option > </ select > < span class ="help-block "> Enable extraction of observables </ span > </ div > </ div > </ form >
1
+ < form class ="form-horizontal form-complex "> < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_name "> Name < span class ="required "> *</ span > </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.name " id ="opencti_create_incident_name "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_description "> Description </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.description " id ="opencti_create_incident_description "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_type "> Type </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.type " id ="opencti_create_incident_type "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_severity "> Severity </ label > < div class ="controls "> < select name ="action.opencti_create_incident.param.severity " id ="opencti_create_incident_severity "> < option value ="low "> Low</ option > < option value ="medium "> Medium</ option > < option value ="high "> High</ option > < option value ="critical "> Critical</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_labels "> Labels </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident.param.labels " id ="opencti_create_incident_labels "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_tlp "> TLP </ label > < div class ="controls "> < select name ="action.opencti_create_incident.param.tlp " id ="opencti_create_incident_tlp "> < option value ="tlp_clear "> TLP:CLEAR</ option > < option value ="tlp_green "> TLP:GREEN</ option > < option value ="tlp_amber "> TLP:AMBER</ option > < option value ="tlp_red "> TLP_RED</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_observables_extraction "> Observables extraction < span class ="required "> *</ span > </ label > < div class ="controls "> < select name ="action.opencti_create_incident.param.observables_extraction " id ="opencti_create_incident_observables_extraction "> < option value ="disable "> Disable</ option > < option value ="cim_model "> CIM model</ option > < option value ="field_mapping "> Field mapping</ option > </ select > < span class ="help-block "> Enable extraction of observables </ span > </ div > </ div > </ form >
Original file line number Diff line number Diff line change 1
- < form class ="form-horizontal form-complex "> < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_name "> Name < span class ="required "> *</ span > </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.name " id ="opencti_create_incident_response_name "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_description "> Description </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.description " id ="opencti_create_incident_response_description "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_severity "> Severity </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.severity " id ="opencti_create_incident_response_severity "> < option value ="low "> Low</ option > < option value ="medium "> Medium</ option > < option value ="high "> High</ option > < option value ="critical "> Critical</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_priority "> Priority </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.priority " id ="opencti_create_incident_response_priority "> < option value ="p1 "> P1</ option > < option value ="p2 "> P2</ option > < option value ="p3 "> P3</ option > < option value ="p4 "> P4</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_type "> Type </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.type " id ="opencti_create_incident_response_type "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_labels "> Labels </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.labels " id ="opencti_create_incident_response_labels "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_tlp "> TLP </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.tlp " id ="opencti_create_incident_response_tlp "> < option value ="tlp_clear "> TLP:CLEAR</ option > < option value ="tlp_green "> TLP:GREEN</ option > < option value ="tlp_amber "> TLP:AMBER</ option > < option value ="tlp_red "> TLP:RED</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_extraction "> Observables extraction < span class ="required "> *</ span > </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.observables_extraction " id ="opencti_create_incident_response_extraction "> < option value ="disable "> Disable</ option > < option value ="cim_model "> CIM Model</ option > < option value ="field_mapping "> OpenCTI Fields mapping</ option > </ select > < span class ="help-block "> Enable extraction of observables </ span > </ div > </ div > </ form >
1
+ < form class ="form-horizontal form-complex "> < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_name "> Name < span class ="required "> *</ span > </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.name " id ="opencti_create_incident_response_name "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_description "> Description </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.description " id ="opencti_create_incident_response_description "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_severity "> Severity </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.severity " id ="opencti_create_incident_response_severity "> < option value ="low "> Low</ option > < option value ="medium "> Medium</ option > < option value ="high "> High</ option > < option value ="critical "> Critical</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_priority "> Priority </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.priority " id ="opencti_create_incident_response_priority "> < option value ="p1 "> P1</ option > < option value ="p2 "> P2</ option > < option value ="p3 "> P3</ option > < option value ="p4 "> P4</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_type "> Type </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.type " id ="opencti_create_incident_response_type "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_labels "> Labels </ label > < div class ="controls "> < input type ="text " name ="action.opencti_create_incident_response.param.labels " id ="opencti_create_incident_response_labels "/> </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_tlp "> TLP </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.tlp " id ="opencti_create_incident_response_tlp "> < option value ="tlp_clear "> TLP:CLEAR</ option > < option value ="tlp_green "> TLP:GREEN</ option > < option value ="tlp_amber "> TLP:AMBER</ option > < option value ="tlp_red "> TLP:RED</ option > </ select > </ div > </ div > < div class ="control-group "> < label class ="control-label " for ="opencti_create_incident_response_extraction "> Observables extraction < span class ="required "> *</ span > </ label > < div class ="controls "> < select name ="action.opencti_create_incident_response.param.observables_extraction " id ="opencti_create_incident_response_extraction "> < option value ="disable "> Disable</ option > < option value ="cim_model "> CIM model</ option > < option value ="field_mapping "> Field mapping</ option > </ select > < span class ="help-block "> Enable extraction of observables </ span > </ div > </ div > </ form >
You can’t perform that action at this time.
0 commit comments