You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fukusuket
changed the title
chg: [mitre] add support for analytic references in Detection Strategies
chg: [mitre] add support for Analytic references in Detection StrategiesJan 6, 2026
fukusuket
changed the title
chg: [mitre] add support for Analytic references in Detection Strategies
chg: [mitre] add support for Analytics references in Detection StrategiesJan 6, 2026
Is analyzes appropriate as the verb to use for the relation? I wasn’t sure what the most suitable verb would be here, so I would appreciate your advice.
Thanks, that’s a good question. We might need a new relationship such as composed-of, but I’m not sure what the best option is. It seems that Analytics is more of a composition of elements, while the log source could be linked with detected-by.
We could also introduce new relationships to achieve a better fit.
I like the idea of using the predicate composed-of. I’ve gone ahead and updated analyzes to composed-of.
Adding a relation detected-by for the log source makes a lot of sense, too. I’ll definitely implement that in my next pull request!
Also, I wasn't aware of the MISP Object relationships — thanks for sharing that!
One quick question: how will it look once it's defined in the Object? Will it be automatically reflected in the Galaxy relation graph as well?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thank you for maintaining misp-galaxy :)
I added an
Analyticsreference toDetection StrategyGalaxy. I would appreciate your candid feedback.Thank you for your time.
https://attack.mitre.org/detectionstrategies/DET0210/
