-
Notifications
You must be signed in to change notification settings - Fork 55
Open
Labels
help wantedExtra attention is neededExtra attention is needed
Description
Based on my presentation to the interCERT, some people asked for OpenCTI or MISP import (via enrichment tool or direct import).
Ideas
- Can be useful to create a future connector / ingestor to OpenCTI or MISP
- Create an API endpoint
- Create a button "Export to STIXv2"
- Create a button "Ingest as new MISP Event"
- Create a button "Add IoCs to OpenCTI"
- Make sure to add the ability to select indicators that should be created (via form)
- Make sure all of this is configurable through
secrets.jsonor ENV - Make sure it is well documented
Problems
- How to map correctly to STIX when there is no predictable data? (map every possible field? one by one?)
- How to make sure the observable should be an indicator and that it is not an expired / invalid one?
Resources
https://oasis-open.github.io/cti-documentation/stix/examples
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
help wantedExtra attention is neededExtra attention is needed