Enhancements:
- #6445 [sdk] Add created in commom properties for base identified entity
- #6437 [Portspoof Pro] New external-import connector for PortSpoofPro session telemetry
- #6435 [virustotal-livehunt-notifications] Propagate malware-config IOCs, per-type indicators, and per-run notifications cap
- #6406 [yara] Propagate 'indicates' Malware relationships and labels from matching YARA Indicator to enriched Artifact
- #5313 [crowdstrike] Link IntrusionSet to Vulnerabilities when processing the 'vulnerability' data collection
- #5178 [Google TI] Connector does not download the actual PDF of the report
- #5165 [Flashpoint] Migrate Flashpoint connector to API v2 for IOC ingestion
Bug Fixes:
- #6438 [crowdstrike] Handle missing indicator scope permission gracefully
- #5428 [SentinelOne-Intel] STIX pattern filter is too restrictive for hashes
- #5161 [Defender Intel Synchronizer] Performance degradation, Hostname not created, various other issues
Pull Requests:
- [sdk] Add created in common properties by @throuxel in #6448
- [crowdstrike] Link IntrusionSet to Vulnerabilities via related_actors field by @Copilot in #6133
- [sentinelone-intel] Fix file-hash regex to accept all OpenCTI shapes by @jacobholtz in #5580
- [yara] Propagate Malware relationships and labels from Indicators to matching Artifacts by @bamed in #5193
- [google-ti-feeds] Download pdf report by @throuxel in #6379
- [connectors-sdk] Rename config to settings for external import connector by @throuxel in #6456
- [crowdstrike] Handle missing indicator scope permission gracefully by @narenvivek in #5577
- [portspoof] Add PortSpoofPro external-import connector by @SamuelHassine in #6430
- [virustotal-livehunt-notifications] Malware-config extraction, indicator switches, per-run limit by @gkallenborn in #5432
- [import-document] Extract Phone-Number, IMEI, ICCID and IMSI observables by @labo-flg in #5685
- [microsoft-defender-intel-synchronizer] Fix performance, correctness, and safety issues (#5161) by @blauwers in #5162
- [flashpoint] update ioc to v2 by @throuxel in #5999
- [sigmahq] New connector to ingest Sigma rules by @romain-filigran in #5525
New Contributors:
- @jacobholtz made their first contribution in #5580
- @bamed made their first contribution in #5193
- @narenvivek made their first contribution in #5577
Full Changelog: 7.260521.0...7.260522.0