-
-
Notifications
You must be signed in to change notification settings - Fork 116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add new response action for trusted communities #285
Conversation
wow, that's was quick! thank you for the first RA contributed (: OK, let me answer this step by step:
Most probably, we will remove the stage definition from the RA yaml file, since it's kinda redundant, but still in use by some scripts. A category is calculated on the fly and automatically added to all exported entities (i.e. markdown/confluence/etc). We will follow the same approach for stages.
This is a legacy from the main ATC project. Actually, RA/RP stuff was developed more than a year ago. The atc-react is just a way to make it more clear for IR people, and provide a better way to visualize/represent the data. So, this is something we will work out on the next development stages. We will have a title fully separated from the filename. (well, make sense to create an issue).
We were thinking about the "filename only an ID"-kind of way, so we will have everything simplified.
Also a legacy. Most probably (I don't see why not) we will switch to Sigma format for the date. But for now, let's keep it consistent, so in the future, we would be able to change it all at once, by one bash oneliner.
Well, we can do the lookup for the next number ourselves (:
Regarding the possible gaps — yes, this is something we need to be careful about, but still, it's wouldn't be a big problem anyway. Yep, I don't think that we will switch to UUID for RA's. Anyway, I will change the date format and you will see your RA published everywhere in a few minutes. Thank you again! |
Done it. Welcome to project contributors! |
Thanks for your explanations above. Looking forward how the project evolves. Thanks for your work! |
created an issue #294 for naming scheme normalisation |
created an issue #296 for date format change |
Add new RA for connecting with trusted communities, like MISP. Hope the format and everything's ok and I included all relevant information for a new RA.
After adding my first RA action to see how that works, the following things came up:
YYYY-MM-DD
, in the template was another format used (minor issue)