-
Hello, I am running into a couple of issues, perhaps somebody else has gone through something similar and can share insights?
On a related note, is there an MVT community of interest where users can discuss and help each other out? I didn't see one on Discord, Reddit, or Slack. Thanks! |
Beta Was this translation helpful? Give feedback.
Replies: 5 comments 2 replies
-
Hi,
No, there is no Discord, Reddit or Slack for the MVT commnity |
Beta Was this translation helpful? Give feedback.
-
Hi Te-k, thanks, that makes sense. About the detections, there were no files ending with _detected.json and the other warning was only cosmetic: But you have given me good pointers to work with, I'll tinker some more. Cheers! |
Beta Was this translation helpful? Give feedback.
-
Thanks, I just added iOS 16.1 to the list of versions so this warning shouldn't happen again. |
Beta Was this translation helpful? Give feedback.
-
Thanks, these are some hardware versions I have seen that you might want to add to the versions.py file: iPhone14,8 : iPhone 14 Plus |
Beta Was this translation helpful? Give feedback.
-
Hi @Te-k, Two questions, one related to custom detections:
I used MISP and exported as stix2, but the syntax is different, for example the stix2 file in the MVT repo uses: whereas the stix2 file exported from MISP uses: Something similar for email, the stix2 files that MVT pulls use the syntax: whereas the MISP export uses: Building a stix2 file manually to match the syntax of the stix2 files in the MVT repo works fine, but it is very time consuming and doesn’t scale for more than a handful of indicators.
For example this detection from the webkit_resource_load_statistics_detected.json file: "AppDomain-com.apple.mobilesafari/Library/WebKit/WebsiteData/ResourceLoadStatistics/observations.db": [ Is there additional detail that this detection generates that I can use to find out what called webkit to load the domain? Thanks, |
Beta Was this translation helpful? Give feedback.
Hi,
_detected.json
. Have you seen another warning in the console? Is there any file ending by_detected.json
in the result folder?No, there is no…