What it is
Integrate existing data from Thread into corresponding STIX SDOs within Attack Flows, enriching flow steps with additional context.
Why it matters
- Provides rich, actionable data (indicators, malware, vulnerabilities) alongside actions.
- Improves interoperability with downstream tools.
Requirements
- For each FlowNode:
- Reuse existing IOCs to generate
attack-asset nodes
- Link CVEs to
vulnerability SDOs + related-to relationships
- Map malware/tool mentions to STIX
malware or tool SDOs
- Reference all entities via
asset_refs from parent attack-action.
Acceptance Criteria
What it is
Integrate existing data from Thread into corresponding STIX SDOs within Attack Flows, enriching flow steps with additional context.
Why it matters
Requirements
attack-assetnodesvulnerabilitySDOs +related-torelationshipsmalwareortoolSDOsasset_refsfrom parentattack-action.Acceptance Criteria
attack-action.