Unique identification of threat actors despite referenced in different galaxies #515
Labels
S: stale
Status: stale. This issue has had no activity in a long time, it may not be relevant anymore
T: enhancement
Type: enhancement. This issue is not a bug, it improves an existing feature
Hello,
By today, MISP propose three different galaxies to identify threats actors
Some threat actors are present present in all mentioned galaxies but have a different UUID leading
to dispersion of events and fragmentation.
E.g.
APT28 in "Microsoft Activity Group actor" has UUID 213cdde9-c11a-4ea9-8ce0-c868e9826fec
APT28 in "Threat Actor galaxy" has UUID 5b4ee3ea-eee3-4c8e-8323-85ae32658754
APT28 in "Intrusion Set galaxy" has UUID bef4c620-0787-42a8-a96d-b7eb6e85917c
Historically Galaxy "Threat Actor" is used by majority of the organizations,
leading to non usage of other galaxies like "Intrusion Set galaxy" from ATT&CK.
Threat actors shall be uniquely identified despite potentially referenced in different galaxies.
The text was updated successfully, but these errors were encountered: