Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Relationship "<Malware> authored by <Threat Actor Individual>" not properly displayed in Knowledge tab #8576

Closed
ups1decyber opened this issue Oct 2, 2024 · 1 comment · Fixed by #8634
Labels
bug use for describing something not working as expected solved use to identify issue that has been solved (must be linked to the solving PR)
Milestone

Comments

@ups1decyber
Copy link

Description

I have created a relationship "authored by" between a malware and a threat actor individual. Now, when I open the knowledge tab of the malware, I can see "Threat actors (1)" in the list on the right. However, when I click on "Threat actors", the displayed list is empty.

Environment

  1. OS (where OpenCTI server runs): -
  2. OpenCTI version: OpenCTI 6.3.1
  3. OpenCTI client: -
  4. Other environment details: -

Reproducible Steps

  1. Create a malware, threat actor individual and report.
  2. In the report, add the malware and threat actor entities
  3. Create a "authored by" relationship for the malware and threat actor entities
  4. Open the knowledge tab of the malware or open the knowledge tab of the threat actor individual
  5. Look at the menu on the right. On the malware page, it should say "Threat Actors (1)", but the corresponding list does not contain any items. On the threat actor individual page, it should say "Malware (1)", but the corresponding list does not contain any items. This is true for both, the "entities view" and the "relationships view".

Expected Output

I would expect the lists to contain items that describe the "authored by" relationship.

Actual Output

No list items

Additional information

Screenshots (optional)

image

@ups1decyber ups1decyber added bug use for describing something not working as expected needs triage use to identify issue needing triage from Filigran Product team labels Oct 2, 2024
@nino-filigran nino-filigran removed the needs triage use to identify issue needing triage from Filigran Product team label Oct 3, 2024
@nino-filigran
Copy link

The problem is generic to Intrusion Sets, Threat Actor individual & Threat Actor group.
The fix is to:

  • for any relation malware -> authored by -> threat actor/intrusion set, display:
    • in the malware knowledge views, in "all threats view" & in the "intrusion set" view, the threat actors and/or the intrusion set. Also, when switching to relation view, the authored by must be displayed.
    • in the threat actors/intrusion knowledges views, in "malware" view, have the malware. And when switching to relation view, be able to display the authored by.

@nino-filigran nino-filigran added this to the Bugs backlog milestone Oct 3, 2024
SamuelHassine pushed a commit that referenced this issue Oct 14, 2024
@SamuelHassine SamuelHassine added the solved use to identify issue that has been solved (must be linked to the solving PR) label Oct 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug use for describing something not working as expected solved use to identify issue that has been solved (must be linked to the solving PR)
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants