Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stix Difficulties: TTPs are almost mandatory #81

Open
terrymacdonald opened this issue Dec 3, 2015 · 0 comments
Open

Stix Difficulties: TTPs are almost mandatory #81

terrymacdonald opened this issue Dec 3, 2015 · 0 comments

Comments

@terrymacdonald
Copy link

PROBLEM

If you have an Indicator, and you wish to send that out in a manner that matches best practice, you are encouraged to use a TTP, even if that TTP does not add that much value. In addition one requires either a TTP or Incident in most cases to connect an Indicator to other things. As mentioned above in section 21, it may be worth investigating if this does actually need to be the case. It may be worth creating more flexibility in the relationships that are allowed within STIX.

POTENTIAL ANSWER

This may be more of a tooling problem or ‘best practice’ recommendation problem than actually a problem with STIX.

Please see section “21. Relationships are constrained to limited Objects within STIX” above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant