Enhancements:
- #2704 [Sentinel] Store additional information
- #2590 [Microsoft Sentinel] Enhance the connector i.e. import more data from MS to OCTI
- #976 [Silobreaker] Overall enhancement + customizable search queries
- #728 [MISP] hashes are not supported and inserted as
Text
- #477 [TAXII2] Add Client side cert auth support
Bug Fixes:
- #2918 Relationships not created after workbench validation
- #2908 [group-ib] collection apt/threat error
- #2898 [Valhalla]: Many YARA rules are not correctly ingested
- #2887 [Sentinel Incidents] Error when running Sentinel Incidents image
- #2884 [Recorded Future] Crash Occurred "Alert" object is not subscriptable
- #2879 [splunk] Entrypoint refers to qradar directory
- #2878 [zerofox] cannot import name 'FoxBotnet' from 'zerofox.domain.botnet'
- #2873 [Valhalla] Object of type 'Indicator' is not JSON serializable
Pull Requests:
- Update dependency boto3 to v1.35.54 by @renovate in #2891
- [Recorded-Future] Fix TypeError, AttributeError and refacto by @Megafredo in #2885
- [connectors] update templates to align with best practices by @helene-nguyen in #2872
- Update dependency google-api-python-client to v2.151.0 by @renovate in #2890
- Update dependency crowdstrike-falconpy to v1.4.6 by @renovate in #2897
- [connectors] Distribute build time for CI by @helene-nguyen in #2904
- [connectors] Add docker_layer_caching for image layers in CI by @helene-nguyen in #2905
- Update opencti/connector-tenable-vuln-management Docker tag to v6.3.9 by @renovate in #2903
- Update opencti/connector-tanium-intel Docker tag to v6.3.9 - autoclosed by @renovate in #2902
- [Sentinel-Incidents] Improvment feature by @Megafredo in #2834
- [Sentinel Incidents] Fix dockerfile path by @Megafredo in #2909
- Better update dates of current state by @cert-orangecyberdefense in #2806
- [internal-import] add bundle containers to context entity container (OCTI #8178) by @JeremyCloarec in #2802
- [Connectors] Remove non-existing arguments for generate_id by @helene-nguyen in #2914
- [Zerofox] Rename class for botnet, malware, phishing, ransomware models by @helene-nguyen in #2913
- [Valhalla] Object of type 'Indicator' is not JSON serializable by @romain-filigran in #2896
- Update dependency tldextract to v5.1.3 by @renovate in #2910
- [internal-import] only add object_refs if entity context is a container by @JeremyCloarec in #2915
Full Changelog: 6.3.9...6.3.10