Context
The CAPE adapter maps report fields directly into DYNAMIC_BEHAVIOR findings. That provides useful observations, but equivalent behavior reported with different process IDs, paths, or sandbox-specific wording cannot yet be clustered reliably.
Proposal
Add a normalized behavior schema for process ancestry, API/action categories, network intent, persistence, file/registry changes, and ATT&CK observations. Keep raw provider references and provider/version metadata alongside normalized features.
Acceptance criteria
- Normalization removes nondeterministic IDs, timestamps, and host-specific paths.
- Equivalent CAPE reports produce the same behavior feature digest.
- Provider-specific fields remain visible and are not treated as ground truth.
- Behavior similarity can be queried without merging static variant groups automatically.
References
Context
The CAPE adapter maps report fields directly into
DYNAMIC_BEHAVIORfindings. That provides useful observations, but equivalent behavior reported with different process IDs, paths, or sandbox-specific wording cannot yet be clustered reliably.Proposal
Add a normalized behavior schema for process ancestry, API/action categories, network intent, persistence, file/registry changes, and ATT&CK observations. Keep raw provider references and provider/version metadata alongside normalized features.
Acceptance criteria
References