Skip to content

Releases: OpenCTI-Platform/connectors

Version 6.4.2

28 Nov 16:33
aefc5a3
Compare
Choose a tag to compare

Bug Fixes:

  • #3042 [Sentinel-Intel] Missing init retries_builder for handle 429
  • #3032 [sentinel-intel] JWT token expire after two hours and is not renewed
  • #3025 [Recorded Future] Issue on getting data from RF Alerts
  • #3001 [Mandiant] Crash if the state is empty
  • #2989 [RecordedFuture] Unexpected error
  • #2980 [Crowdstrike-Security-Endpoint] Error while processing indicator
  • #2868 [MISP] Mapping error on relationships Source = Target = ?

Pull Requests:

New Contributors:

Full Changelog: 6.4.1...6.4.2

Version 6.4.1

21 Nov 15:43
3011eed
Compare
Choose a tag to compare

Enhancements:

  • #2895 OpenCTI internal-enrichment/ipinfo connector, ASN field missing from enrichments
  • #2747 Need filtering capability to limit number of records

Pull Requests:

New Contributors:

Full Changelog: 6.4.0...6.4.1

Version 6.4.0

18 Nov 19:07
c1b173c
Compare
Choose a tag to compare

Bug Fixes:

  • #2983 [Mandiant] Unexpected properties for stix2 Note
  • #2980 [Crowdstrike-Security-Endpoint] Error while processing indicator
  • #2978 [CI] CircleCI failing in tests due to Numpy unsupported version for Python 3.12
  • #2977 [Connectors] When pulling Splunk docker image after release, context build error

Pull Requests:

New Contributors:

Full Changelog: 6.3.13...6.4.0

Version 6.3.13

15 Nov 16:59
834a7ac
Compare
Choose a tag to compare

Enhancements:

  • #2692 [RiskIQ - PassiveTotal]: Create the enrichment connector

Bug Fixes:

  • #2798 [Tanium] Repeating addition of intel

Pull Requests:

Full Changelog: 6.3.12...6.3.13

Version 6.3.12

15 Nov 14:16
d5a531e
Compare
Choose a tag to compare

Enhancements:

  • #2947 [QRadar] Forward offenses from QRadar into OpenCTI as incidents
  • #2923 [Connectors] Add linter check for no generation id stix, no value parameter and unused import in Circle CI
  • #2298 Split logics for Microsoft Sentinel / Tanium Threat Response / HarfangLabs between Stream & Import

Bug Fixes:

  • #2958 [Crowdstrike] Ingestion take too much time: state is not updated properly
  • #2879 [splunk] Entrypoint refers to qradar directory
  • #2867 [Flashpoint] Error occurs after some time running the connector
  • #2816 [Mandiant]: Map Mandiant score to our score attribute on indicator
  • #2803 [Flashpoint] Errors while adding the connector
  • #2765 [Crowdstrike] Observable entities in reports are not imported
  • #2811 Enrichment connectors called too early for artifacts
  • #2700 [YARA] The YARA connector attempts to scan an artifact before the malwarebazaar-recent-additions connector finishes uploading the file
  • #2546 [Yara Scan] Several problem

Pull Requests:

Full Changelog: 6.3.11...6.3.12

Version 6.3.11

07 Nov 16:55
09b4625
Compare
Choose a tag to compare

No changelog for this release.

Pull Requests:

Full Changelog: 6.3.10...6.3.11

Version 6.3.10

05 Nov 17:42
9a5877e
Compare
Choose a tag to compare

Enhancements:

  • #2704 [Sentinel] Store additional information
  • #2590 [Microsoft Sentinel] Enhance the connector i.e. import more data from MS to OCTI
  • #976 [Silobreaker] Overall enhancement + customizable search queries
  • #728 [MISP] hashes are not supported and inserted as Text
  • #477 [TAXII2] Add Client side cert auth support

Bug Fixes:

  • #2918 Relationships not created after workbench validation
  • #2908 [group-ib] collection apt/threat error
  • #2898 [Valhalla]: Many YARA rules are not correctly ingested
  • #2887 [Sentinel Incidents] Error when running Sentinel Incidents image
  • #2884 [Recorded Future] Crash Occurred "Alert" object is not subscriptable
  • #2879 [splunk] Entrypoint refers to qradar directory
  • #2878 [zerofox] cannot import name 'FoxBotnet' from 'zerofox.domain.botnet'
  • #2873 [Valhalla] Object of type 'Indicator' is not JSON serializable

Pull Requests:

Full Changelog: 6.3.9...6.3.10

Version 6.3.9

31 Oct 16:40
2c4406a
Compare
Choose a tag to compare

No changelog for this release.

Pull Requests:

Full Changelog: 6.3.8...6.3.9

Version 6.3.8

30 Oct 10:28
d3a8bb3
Compare
Choose a tag to compare

Bug Fixes:

  • #2865 [connector] Revert flake8 replacement with pylint

Pull Requests:

Full Changelog: 6.3.7...6.3.8

Version 6.3.7

29 Oct 10:38
22283fe
Compare
Choose a tag to compare

Enhancements:

  • #2863 [connectors] Correct stochastic generated stix object id and add linter
  • #2804 [RiskIQ] Set Main observable type
  • #1450 [Tenable Vuln Management] Create the connector

Bug Fixes:

  • #2850 [Tanium] Connector getting terminated without explicit logs
  • #2792 [Mandiant] Importing Campaigns linked to an IOC doesn't import campaign's related entities
  • #2773 [CrowdStrike] API Base URL variable name incorrectly defined

Pull Requests:

Full Changelog: 6.3.6...6.3.7