Skip to content

Normalize dynamic behavior findings into versioned behavior features #38

Description

@haasonsaas

Context

The CAPE adapter maps report fields directly into DYNAMIC_BEHAVIOR findings. That provides useful observations, but equivalent behavior reported with different process IDs, paths, or sandbox-specific wording cannot yet be clustered reliably.

Proposal

Add a normalized behavior schema for process ancestry, API/action categories, network intent, persistence, file/registry changes, and ATT&CK observations. Keep raw provider references and provider/version metadata alongside normalized features.

Acceptance criteria

  • Normalization removes nondeterministic IDs, timestamps, and host-specific paths.
  • Equivalent CAPE reports produce the same behavior feature digest.
  • Provider-specific fields remain visible and are not treated as ground truth.
  • Behavior similarity can be queried without merging static variant groups automatically.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions