The TAXII server currently sources STIX objects from the Workbench 'Get Collection Bundles' endpoint. These objects should match those published to mitre-attack/attack-stix-data, but there are inconsistencies due to post-processing.
Example inconsistency:
- Objects from 'Get Collection Bundles' may contain empty arrays like:
"x_mitre_data_sources": []
- These empty arrays are stripped during processing before publishing to mitre-attack/attack-stix-data
This issue tracks aligning the Workbench REST API 'Get Collection Bundles' endpoint output with the published STIX data structure.
The TAXII server currently sources STIX objects from the Workbench 'Get Collection Bundles' endpoint. These objects should match those published to mitre-attack/attack-stix-data, but there are inconsistencies due to post-processing.
Example inconsistency:
"x_mitre_data_sources": []This issue tracks aligning the Workbench REST API 'Get Collection Bundles' endpoint output with the published STIX data structure.