Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add threat.indicator.tags field #2263

Open
mbudge opened this issue Aug 31, 2023 · 0 comments
Open

Add threat.indicator.tags field #2263

mbudge opened this issue Aug 31, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@mbudge
Copy link
Contributor

mbudge commented Aug 31, 2023

Many threat intelligence platforms use a tagging system to group indicators.

https://knowledge.threatconnect.com/docs/applying-tags

An example would be indexing indicators from a Phishing URL feed. If the indicator from the threat intelligence feed has the brand name set as a tag, we would set that tag to the elastic document.

Tags tend to be very generic so they can contain any keyword value, making it difficult to parse tags to a specific ECS field.

We noticed there's no ECS field for tags in the threat object.

I'd recommend threat.indicator.tags or threat.indicator.tag

@mbudge mbudge added the enhancement New feature or request label Aug 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant