Skip to content

Conversation

@fukusuket
Copy link
Contributor

@fukusuket fukusuket commented Jan 6, 2026

Thank you for maintaining misp-galaxy :)

I added an Analytics reference to Detection Strategy Galaxy. I would appreciate your candid feedback.
Thank you for your time.

https://attack.mitre.org/detectionstrategies/DET0210/
スクリーンショット 2026-01-07 0 44 44

@fukusuket
Copy link
Contributor Author

fukusuket commented Jan 6, 2026

スクリーンショット 2026-01-07 0 48 17 スクリーンショット 2026-01-07 0 46 17 スクリーンショット 2026-01-07 0 46 28 スクリーンショット 2026-01-07 0 47 16

@fukusuket fukusuket changed the title chg: [mitre] add support for analytic references in Detection Strategies chg: [mitre] add support for Analytic references in Detection Strategies Jan 6, 2026
@fukusuket fukusuket changed the title chg: [mitre] add support for Analytic references in Detection Strategies chg: [mitre] add support for Analytics references in Detection Strategies Jan 6, 2026
@fukusuket fukusuket marked this pull request as ready for review January 6, 2026 15:53
@fukusuket
Copy link
Contributor Author

Is analyzes appropriate as the verb to use for the relation? I wasn’t sure what the most suitable verb would be here, so I would appreciate your advice.

@adulau
Copy link
Member

adulau commented Jan 6, 2026

Thanks, that’s a good question. We might need a new relationship such as composed-of, but I’m not sure what the best option is. It seems that Analytics is more of a composition of elements, while the log source could be linked with detected-by.

We could also introduce new relationships to achieve a better fit.

https://www.misp-project.org/objects.html#_relationships

@fukusuket
Copy link
Contributor Author

fukusuket commented Jan 7, 2026

@adulau
Thank you for the quick feedback!

I like the idea of using the predicate composed-of. I’ve gone ahead and updated analyzes to composed-of.
Adding a relation detected-by for the log source makes a lot of sense, too. I’ll definitely implement that in my next pull request!

Also, I wasn't aware of the MISP Object relationships — thanks for sharing that!
One quick question: how will it look once it's defined in the Object? Will it be automatically reflected in the Galaxy relation graph as well?

@fukusuket
Copy link
Contributor Author

スクリーンショット 2026-01-07 9 11 13 スクリーンショット 2026-01-07 9 11 21

@adulau adulau merged commit 1349a46 into MISP:main Jan 7, 2026
3 checks passed
@fukusuket fukusuket deleted the add-relations-to-detection-strategy branch January 7, 2026 08:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants