-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Description
In STIX, it leverages observable patterns to do so. Is that something we should replicate in TWIGS, and if so, should it
This has been a point of confusion in STIX, so it's probably worth rethinking it vs. just carrying over the STIX pattern. The confusion mostly stems from the fact that you can have a TTP infrastructure component to describe C2 infrastructure or you can put it in an indicator. So, one possible solution might be to have a relationship to indicator with a type of "Characterized_By" to describe that.
Metadata
Metadata
Assignees
Labels
No labels