2017-04-25 00:29:56 +02:00
|
|
|
import datetime as dt
|
|
|
|
|
2017-04-19 15:22:08 +02:00
|
|
|
import pytest
|
|
|
|
import pytz
|
2017-05-09 21:10:53 +02:00
|
|
|
|
2017-02-24 18:56:55 +01:00
|
|
|
import stix2
|
|
|
|
|
2017-04-19 15:22:08 +02:00
|
|
|
from .constants import THREAT_ACTOR_ID
|
|
|
|
|
2017-05-09 21:10:53 +02:00
|
|
|
|
2017-02-24 18:56:55 +01:00
|
|
|
EXPECTED = """{
|
2017-08-15 19:41:51 +02:00
|
|
|
"type": "threat-actor",
|
|
|
|
"id": "threat-actor--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f",
|
2017-02-24 18:56:55 +01:00
|
|
|
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff",
|
2017-08-15 19:41:51 +02:00
|
|
|
"created": "2016-04-06T20:03:48.000Z",
|
|
|
|
"modified": "2016-04-06T20:03:48.000Z",
|
|
|
|
"name": "Evil Org",
|
2017-02-24 18:56:55 +01:00
|
|
|
"description": "The Evil Org threat actor group",
|
|
|
|
"labels": [
|
|
|
|
"crime-syndicate"
|
2017-08-15 19:41:51 +02:00
|
|
|
]
|
2017-02-24 18:56:55 +01:00
|
|
|
}"""
|
|
|
|
|
|
|
|
|
|
|
|
def test_threat_actor_example():
|
|
|
|
threat_actor = stix2.ThreatActor(
|
|
|
|
id="threat-actor--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f",
|
|
|
|
created_by_ref="identity--f431f809-377b-45e0-aa1c-6a4751cae5ff",
|
2017-06-23 00:47:35 +02:00
|
|
|
created="2016-04-06T20:03:48.000Z",
|
|
|
|
modified="2016-04-06T20:03:48.000Z",
|
2017-02-24 18:56:55 +01:00
|
|
|
name="Evil Org",
|
|
|
|
description="The Evil Org threat actor group",
|
|
|
|
labels=["crime-syndicate"],
|
|
|
|
)
|
|
|
|
|
|
|
|
assert str(threat_actor) == EXPECTED
|
|
|
|
|
2017-04-19 15:22:08 +02:00
|
|
|
|
|
|
|
@pytest.mark.parametrize("data", [
|
|
|
|
EXPECTED,
|
|
|
|
{
|
2017-06-23 00:47:35 +02:00
|
|
|
"created": "2016-04-06T20:03:48.000Z",
|
2017-04-19 15:22:08 +02:00
|
|
|
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff",
|
|
|
|
"description": "The Evil Org threat actor group",
|
|
|
|
"id": "threat-actor--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f",
|
|
|
|
"labels": [
|
|
|
|
"crime-syndicate"
|
|
|
|
],
|
2017-06-23 00:47:35 +02:00
|
|
|
"modified": "2016-04-06T20:03:48.000Z",
|
2017-04-19 15:22:08 +02:00
|
|
|
"name": "Evil Org",
|
|
|
|
"type": "threat-actor"
|
|
|
|
},
|
|
|
|
])
|
|
|
|
def test_parse_threat_actor(data):
|
|
|
|
actor = stix2.parse(data)
|
|
|
|
|
|
|
|
assert actor.type == 'threat-actor'
|
|
|
|
assert actor.id == THREAT_ACTOR_ID
|
|
|
|
assert actor.created == dt.datetime(2016, 4, 6, 20, 3, 48, tzinfo=pytz.utc)
|
|
|
|
assert actor.modified == dt.datetime(2016, 4, 6, 20, 3, 48, tzinfo=pytz.utc)
|
|
|
|
assert actor.created_by_ref == "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff"
|
|
|
|
assert actor.description == "The Evil Org threat actor group"
|
|
|
|
assert actor.name == "Evil Org"
|
|
|
|
assert actor.labels == ["crime-syndicate"]
|
|
|
|
|
2017-02-24 18:56:55 +01:00
|
|
|
# TODO: Add other examples
|