Skip to the content.

External STIX 2.0 to MISP Galaxies mapping

When importing STIX 2.0 bundles from third-party tools (not produced by MISP), SDOs such as Attack Pattern, Campaign, Course of Action, Intrusion Set, Malware, Threat Actor, Tool and Vulnerability are imported as MISP Galaxy Clusters with a dynamically generated galaxy type of the form stix-2.0-{object-type}.

Unlike the internal conversion (which maps back to known MISP galaxy types), the external conversion creates new STIX 2.0 * galaxies that preserve the original STIX content. The cluster value is the STIX object’s name, and meta fields are extracted from fields such as aliases, kill_chain_phases, external_references, etc.

The other detailed mappings

For more detailed mappings, click on one of the links below:

(Go back to the main documentation)