rabobank-cdc/DeTTECT

Feature Request - additional Group fields

professorkilo opened this issue · 1 comments

Possible Fields to add upon ingest into YAML or when you are able to import JSON from the Navigator
specific to Groups, but was curious of the LOE to add custom fields, some of these may have overlap already
[sorry for the list, just stood this up locally so I'm diving in right now]

Last Known Active
Services Used
Origins
Services Offered
Community Identifiers [additional Group names]
Customers
Target Nations
Victims
Target Industries / Sectors
Crimes
Reconnaissance
Weaponization
Delivery
Installation
C2
Actions & Objectives
Associated Malware
Monetization
Attack Vectors
Technical Tradecraft
Priority [personal]
Exploitation [CVEs]
Marketing
First Seen
Attribution

The Group file does allow you to add custom fields (also in the Editor). Or, are you referring to having these be part of the output in the metadata in the Navigator?