TheHive-Project / TheHive-Project/Cortex

Incrementing an analyzer version makes it invalid in Cortex

Open
#280 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Scala
Stars
1.6k
Forks
264
PR merge metrics
No merged PRs in 30d

Description

If you edit the version in the json file for an analyzer or responder, when Cortex picks it up, it sees the previous version of the analyzer as invalid. I presume that this is because the version of the analyzer is part of the name.

Request Type

Bug

Work Environment
Question Answer
OS version (server) Debian
OS version (client) Macos
Cortex version / git hash 3.0.1-1
Package Type Docker
Browser type & version N/A
Problem Description

Changing the version of an analyzer or responder requires additional steps in the UI before the new version is available. It also makes the previous version not work until this step is done.

Steps to Reproduce
  1. Create a custom analyzer with the version in the json file of 0.1.0. In Cortex, the name contains the version, such as My_Analyzer_0_1_0
  2. Create a new version of the analyzer with version 0.1.1, and load it in Cortex. Cortex shows the following on the analyzers page:
You have 1 invalid analyzer

Invalid analyzers have no definition and cannot be run on any observable. You have to remove them.

My_Analyzer_0_1_0

If I search for my analyzer, I see the new version with a completely new title: My_Analyzer_0_1_1
3. You need to disable the invalid analyzer, and then enable the new version before Cortex is able to use it.

Possible Solutions

The name of the analyzer should just be the actual name, as configured in the json file. The version is already a separate piece of metadata, there is no need to have it be part of the module name. If you want to have two versions of the same module, then you can uniquely name them My_Analyzer_1 and My_Analyzer_2, each with their separate actual versions.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing how analyzer and responder names and versions are read from their JSON definitions and represented on the Cortex analyzers page. Verify how loading a changed version creates the invalid previous entry. Done means changing a version does not invalidate the existing definition, while separately named module versions can still coexist.

Written by the indexing model from the issue text.

Assessment

Tech stack
scala
Domain
backend
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.