2018-07-03 13:00:18 +02:00
|
|
|
import datetime as dt
|
|
|
|
|
|
|
|
import pytest
|
|
|
|
import pytz
|
|
|
|
|
|
|
|
import stix2
|
|
|
|
|
2019-01-29 16:52:59 +01:00
|
|
|
from .constants import IDENTITY_ID, INTRUSION_SET_ID
|
2018-07-03 13:00:18 +02:00
|
|
|
|
|
|
|
EXPECTED = """{
|
|
|
|
"type": "intrusion-set",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "intrusion-set--4e78f46f-a023-4e5f-bc24-71b3ca22ec29",
|
2019-01-29 16:52:59 +01:00
|
|
|
"created_by_ref": "identity--311b2d2d-f010-4473-83ec-1edf84858f4c",
|
2018-07-03 13:00:18 +02:00
|
|
|
"created": "2016-04-06T20:03:48.000Z",
|
|
|
|
"modified": "2016-04-06T20:03:48.000Z",
|
|
|
|
"name": "Bobcat Breakin",
|
|
|
|
"description": "Incidents usually feature a shared TTP of a bobcat being released...",
|
|
|
|
"aliases": [
|
|
|
|
"Zookeeper"
|
|
|
|
],
|
|
|
|
"goals": [
|
|
|
|
"acquisition-theft",
|
|
|
|
"harassment",
|
|
|
|
"damage"
|
|
|
|
]
|
|
|
|
}"""
|
|
|
|
|
|
|
|
|
|
|
|
def test_intrusion_set_example():
|
2018-07-03 15:40:51 +02:00
|
|
|
intrusion_set = stix2.v21.IntrusionSet(
|
2019-01-23 16:56:20 +01:00
|
|
|
id=INTRUSION_SET_ID,
|
2019-01-29 16:52:59 +01:00
|
|
|
created_by_ref=IDENTITY_ID,
|
2018-07-03 13:00:18 +02:00
|
|
|
created="2016-04-06T20:03:48.000Z",
|
|
|
|
modified="2016-04-06T20:03:48.000Z",
|
|
|
|
name="Bobcat Breakin",
|
|
|
|
description="Incidents usually feature a shared TTP of a bobcat being released...",
|
|
|
|
aliases=["Zookeeper"],
|
2018-07-13 17:10:05 +02:00
|
|
|
goals=["acquisition-theft", "harassment", "damage"],
|
2018-07-03 13:00:18 +02:00
|
|
|
)
|
|
|
|
|
2021-03-31 18:39:14 +02:00
|
|
|
assert intrusion_set.serialize(pretty=True) == EXPECTED
|
2018-07-03 13:00:18 +02:00
|
|
|
|
|
|
|
|
2018-07-13 17:10:05 +02:00
|
|
|
@pytest.mark.parametrize(
|
|
|
|
"data", [
|
|
|
|
EXPECTED,
|
|
|
|
{
|
|
|
|
"aliases": [
|
|
|
|
"Zookeeper",
|
|
|
|
],
|
|
|
|
"created": "2016-04-06T20:03:48.000Z",
|
2019-01-29 16:52:59 +01:00
|
|
|
"created_by_ref": IDENTITY_ID,
|
2018-07-13 17:10:05 +02:00
|
|
|
"description": "Incidents usually feature a shared TTP of a bobcat being released...",
|
|
|
|
"goals": [
|
|
|
|
"acquisition-theft",
|
|
|
|
"harassment",
|
|
|
|
"damage",
|
|
|
|
],
|
2019-01-23 16:56:20 +01:00
|
|
|
"id": INTRUSION_SET_ID,
|
2018-07-13 17:10:05 +02:00
|
|
|
"modified": "2016-04-06T20:03:48.000Z",
|
|
|
|
"name": "Bobcat Breakin",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"type": "intrusion-set",
|
|
|
|
},
|
|
|
|
],
|
|
|
|
)
|
2018-07-03 13:00:18 +02:00
|
|
|
def test_parse_intrusion_set(data):
|
|
|
|
intset = stix2.parse(data)
|
|
|
|
|
|
|
|
assert intset.type == "intrusion-set"
|
2018-07-03 15:40:51 +02:00
|
|
|
assert intset.spec_version == '2.1'
|
2018-07-03 13:00:18 +02:00
|
|
|
assert intset.id == INTRUSION_SET_ID
|
|
|
|
assert intset.created == dt.datetime(2016, 4, 6, 20, 3, 48, tzinfo=pytz.utc)
|
|
|
|
assert intset.modified == dt.datetime(2016, 4, 6, 20, 3, 48, tzinfo=pytz.utc)
|
|
|
|
assert intset.goals == ["acquisition-theft", "harassment", "damage"]
|
|
|
|
assert intset.aliases == ["Zookeeper"]
|
|
|
|
assert intset.description == "Incidents usually feature a shared TTP of a bobcat being released..."
|
|
|
|
assert intset.name == "Bobcat Breakin"
|
|
|
|
|
|
|
|
# TODO: Add other examples
|