Skip to content

Releases: misje/wazuh-opencti

0.3.0

04 Feb 18:07
99bc463
Compare
Choose a tag to compare
  • Look up hostnames similarly to domain names, including relationships
  • Look up fields srcip/dstIp in additional to src_ip/dest_ip etc.
  • Correctly quit if there are no valid public IP addresses in source alert
  • Add source rule.id as rule_id to alert
  • Look up URLs found in audit execve args
  • Use a consistent field name for the stix object type: rename "entity_type" to "type"

0.2.4

02 Feb 17:09
ec94f0b
Compare
Choose a tag to compare

Support graphql API changes introduced in 5.12.24. This version only works on OpenCTI version 5.12.24 or later (until OpenCTI suddenly changes their API again).

0.2.3

22 Jan 10:09
cffa40b
Compare
Choose a tag to compare

This corrects the previous attempt (in 0.2.2) to use the new filter syntax, which resulted in a bad filter that created a flood of alerts due to bad matching.

0.2.1

28 Sep 07:34
362d32a
Compare
Choose a tag to compare
  • Ignore local IP addresses returned by DNS replies
  • Ignore returned indicators whose pattern doesn't fully match the pattern in the search (#7)

0.2.0

02 Sep 17:11
6cf6006
Compare
Choose a tag to compare
Merge pull request #6 from misje/dev

0.2.0