Skip to content

Releases: OpenCTI-Platform/connectors

Version 6.3.6

14 Oct 23:05
adcdc36
Compare
Choose a tag to compare

Enhancements:

  • #2768 [ransomwarelive] Create predictive ids to prevent stix ids location explosion
  • #2716 [Bit Defender] - New connector request

Bug Fixes:

  • #2780 [ZeroFox] Entity mapping is sometimes inadequately structured
  • #2779 [CrowdStrike] On "uses" relationships, the connector is generating too much STIX IDs and different start time
  • #2753 [ImportExternalReference] BleepingComputer not importable due to Cloudflare protection
  • #2748 [Import Document] Changing type of multiple observables in workbench removes an observable
  • #2713 [Virustotal] Error when enriching certain entities
  • #2671 [VirusTotal] "TypeError: can only concatenate str (not "NoneType") to str" error on certain results

Pull Requests:

  • Update opencti/connector-greynoise-vuln Docker tag to v6.3.5 by @renovate in #2762
  • [ZeroFox] fix ordering in intelligence collector by @DNRRomero in #2751
  • Update dependency boto3 to v1.35.34 - autoclosed by @renovate in #2763
  • Update dependency boto3 to v1.35.35 by @renovate in #2771
  • Update dependency google-api-python-client to v2.148.0 by @renovate in #2770
  • Update dependency boto3 to v1.35.36 by @renovate in #2774
  • [ransomwarelive] Create predictive ids to prevent stix ids location explosion (#2768) by @richard-julien in #2769
  • [importExternalReference] Bypasses certain security measures when generating a PDF or MD by @Megafredo in #2761
  • [VirusTotal] Fix TypeError: can only concatenate str (not NoneType) to str by @Megafredo in #2766
  • Update dependency google-api-core to v2.21.0 by @renovate in #2776
  • [Sentinel] Split former Sentinel connector into two new connectors (external import and stream) by @Powlinett in #2749
  • Update dependency domaintools-api to v2.1.0 by @renovate in #2783
  • Update dependency boto3 to v1.35.39 by @renovate in #2784
  • Update dependency reversinglabs-sdk-py3 to v2.7.1 by @renovate in #2788
  • Update dependency pycti to v6.3.5 by @renovate in #2787
  • [ZeroFox] Format intelligence objects by @DNRRomero in #2789
  • [ Webhook Stream ] - Correct CONNECTOR_SCOPE by @stefanbulof in #2775

New Contributors:

Full Changelog: 6.3.5...6.3.6

Version 6.3.5

04 Oct 12:45
7600ba6
Compare
Choose a tag to compare

Enhancements:

  • #2720 [CISA KEV]: Do not republish all the content at each execution
  • #2708 [GreyNoise Vuln] Add new GreyNoise Vulnerability internal enrichment connector
  • #2623 [Group IB] improvements
  • #2574 [Recorded Future] Integrate the code for Alerts into the connector

Bug Fixes:

  • #2683 [crowdstrike] Push queue message size incorrectly set to 0, disabling buffering/throttling of ingestion

Pull Requests:

Full Changelog: 6.3.4...6.3.5

Version 6.3.4

29 Sep 14:50
c3d8e8e
Compare
Choose a tag to compare

Enhancements:

  • #2725 [Alienvault, CrowdStrike, Phishunt, ThreatFox, URLHaus] added the ability to set x_opencti_score for select connectors

Bug Fixes:

  • #2702 Tanium connector broken
  • #2675 [Intel471] Files attached with no extension

Pull Requests:

  • [Intel 471] Adding attachments extensions by @mmolenda in #2695
  • Update dependency google-api-python-client to v2.147.0 by @renovate in #2705
  • Update dependency stix-shifter to v7.1.1 by @renovate in #2710
  • Update dependency reversinglabs-sdk-py3 to v2.7.0 by @renovate in #2709
  • Update opencti/connector-import-file-misp Docker tag to v6.3.3 by @renovate in #2712
  • Update opencti/connector-first-epss Docker tag to v6.3.3 by @renovate in #2711
  • Update opencti/connector-shadowtrackr Docker tag to v6.3.3 by @renovate in #2714
  • [Tanium] fix : wrong argument name when calling pycti method by @flavienSindou in #2703
  • Update dependency boto3 to v1.35.28 by @renovate in #2715
  • Update dependency elasticsearch to v7.17.12 by @renovate in #2717
  • [Alienvault, CrowdStrike, Phishunt, ThreatFox, URLHaus] added the ability to set x_opencti_score for select connectors by @brett-fitz in #2554
  • Fix configuration issues by @akhanafeer in #2718

New Contributors:

Full Changelog: 6.3.3...6.3.4

Version 6.2.19

29 Sep 14:50
d3657a6
Compare
Choose a tag to compare

No changelog for this release.

Full Changelog: 6.2.18...6.2.19

Version 6.3.3

24 Sep 02:11
0f24f1e
Compare
Choose a tag to compare

Bug Fixes:

  • #2697 [CrowdStrike] Fix KeyError in CrowdStrike processing
  • #2688 Columns in the MITRE ATT&CK kill chain are out of order
  • #2667 [urlscan] Connector issues around getting data since last run and configured interval
  • #2603 [CrowdStrike TIP] "'FetchedReport' object is not subscriptable" error on Indicator
  • #2589 MITRE datasets, filter unsupported types to avoid errors in ingestion works

Pull Requests:

New Contributors:

Full Changelog: 6.3.1...6.3.3

Version 6.3.1

18 Sep 05:31
42f5528
Compare
Choose a tag to compare

No changelog for this release.

Pull Requests:

Full Changelog: 6.3.0...6.3.1

Version 6.3.0

17 Sep 12:14
1a71887
Compare
Choose a tag to compare

Enhancements:

  • #2648 [QRadar Connector : Must create different reference sets for each hash type in case of files]
  • #2638 [isort] isort version needs to be updated in .pre-commit-config.yaml
  • #2351 Improve Ransomware Live connector
  • #2089 [CISA KEV] Be able to run the connector on an interval shorter than 1 day
  • #1866 [import-external-reference] Refactor the connector, enhance PDF / markdown generation
  • #1791 [IPinfo] Create an observable-to-country relationship for country-based victimology

Bug Fixes:

  • #2654 [urlscan] Indicators are missing created_by_ref
  • #2647 [CrowdStrike] CrowdStrike connector internal error: a bytes-like object is required, not 'dict'
  • #2642 [urlscan] Failed: pydantic:parse_raw_as has been removed in V2.
  • #2631 [QRadar Connector : Does not send all hashes in STIX pattern to QRadar]
  • #2618 [Jira] Bug custom_fields is not defined
  • #2595 [Intel471] incorrect indicator names

Pull Requests:

New Contributors:

Full Changelog: 6.2.18...6.3.0

Version 6.2.18

30 Aug 17:08
089d092
Compare
Choose a tag to compare

No changelog for this release.

Pull Requests:

Full Changelog: 6.2.17...6.2.18

Version 6.2.17

30 Aug 15:30
9576357
Compare
Choose a tag to compare

Bug Fixes:

  • #2580 [Mandiant] Fail to parse if end_epoch is None
  • #2577 [Mandiant] In some cases, the connector crashes when handline None reports
  • #2573 [Mandiant] Epoch / state can be set in the future, leading the connector to not work
  • #2564 [GroupIB] Fix groupib docker compose

Pull Requests:

New Contributors:

Full Changelog: 6.2.16...6.2.17

Version 6.2.16

29 Aug 08:34
29f679f
Compare
Choose a tag to compare

Enhancements:

  • #2558 [greynoisefeed] Update indicators to include additional attributes and formatting from enricher
  • #2539 [GroupIB] NEW Create new GroupIB connector
  • #2522 [Cofense] Create Cofense connector
  • #2027 Update templates for Community to have proper guidelines to create/update connectors

Bug Fixes:

  • #2559 [mwdb] Fixed error when tags not present, added except
  • #2544 [RiskIQ] Attack-pattern tag format has changed
  • #2543 [RiskIQ] attack-pattern id generation is incomplete
  • #2535 [jira] Incorrect connector Dockerfile path
  • #2532 [Malpedia] Rate limite Error
  • #2531 [Mandiant] reports not created since August 4
  • #2507 [import-document,import-file-stix] Support running as an arbitrary user (OpenShift Container Platform)

Pull Requests:

New Contributors:

Full Changelog: 6.2.15...6.2.16