-
Notifications
You must be signed in to change notification settings - Fork 262
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update threat-actor.json #1045
base: main
Are you sure you want to change the base?
Update threat-actor.json #1045
Conversation
Removed link reference to UNC4841 activity from GhostEmperor value. After research and speaking with authors of the report, these two clusters of activity are unrelated.
Ah, that’s on me—thanks for catching it. I initially added that link based on the following observations from Mandiant and to reflect the fact that
However, I overlooked that the blog focuses solely on |
But, I really thik we should capture the reference of linking |
A relationship ( |
I'm okay with this though I wouldn't normally describe use of the same anonymization services or service provider as an overlap. |
@validhorizon, I think you misinterpreted. Mandiant said
@adulau, I added misp-galaxy/clusters/threat-actor.json Lines 15282 to 15296 in ebb6261
|
If it's only similar techniques, then I would go for a new relationship https://misp-project.org/objects.html#_relationships (for your reference existing relationships but we can easily extend it). We could also add relationship |
Yes but as I said, I already added |
Sure. Will you make an updated PR? |
No need to update, we can close this PR once if @validhorizon is ok with this as we discussed. |
Removed link reference to UNC4841 activity from GhostEmperor value. After research and speaking with authors of the report, these two clusters of activity are unrelated.