Skip to content

Improve CTIHelper and its methods #2793

@buixor

Description

@buixor

What would you like to be added?

We currently expose a CTIHelper expr method, but it has a few shortcoming:

  1. We might make its usage easier than currently (ie. we need to do CTIHelper(evt.Overflow.GetSources()[0]) or something similar.
  2. We are exposing only a few properties via helpers
  3. The SmokeItem isn't up-to-date (ie. no mitre techniques)
  4. We lack "convenience" helpers

Why is this needed?

make cti helpers great again

Metadata

Metadata

Assignees

Labels

kind/enhancementNew feature or requestneeds/triagequestionFurther information is requestedvalue/lowDoing this kinda improves some areas

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions