Skip to content

How should TWIGS represent infrastructure? #38

@johnwunder

Description

@johnwunder

In STIX, it leverages observable patterns to do so. Is that something we should replicate in TWIGS, and if so, should it

This has been a point of confusion in STIX, so it's probably worth rethinking it vs. just carrying over the STIX pattern. The confusion mostly stems from the fact that you can have a TTP infrastructure component to describe C2 infrastructure or you can put it in an indicator. So, one possible solution might be to have a relationship to indicator with a type of "Characterized_By" to describe that.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions