-
-
Notifications
You must be signed in to change notification settings - Fork 110
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create Threat Intelligence apps #24
Comments
More sources (OpenCTI): https://luatix.notion.site/OpenCTI-Ecosystem-868329e9fb734fca89692b2ed6087e76 Extra: Create a simple workflow that merges threat lists daily into the shuffle K:V store. |
It would be pretty useful to see an app for OpenCTI in Shuffle that can be used for enrichment of data within Shuffle as well using shuffle to push data into OpenCTI. Similar to Shuffle this platform has been fast maturing and is a very easily adoptable opensource threat intelligence platform. |
@cvdsouza agreed! If you or someone else that uses OpenCTI would be willing to work with us to build it out, we can set it up and prepare everything for OpenCTI very easily I haven't used OpenCTI in years myself, and setting up every instance of every system is just not feasible at our current scale, so we need some community & customer help :) |
I might be able to help with putting something to together. Let me know! |
Yes please Wes! We still got some work to do with Velociraptor, and doing some at the intersection of the two would be even better |
awesome. thank you both , really appreciate it. There is a Demo instance of OpenCTI that is always open to the public to test against : https://demo.opencti.io/dashboard As for use-cases, the ones that I've used with XSOAR that I think would be beneficial for Shuffle would be :
|
My OpenCTI Stack using docker swarm will be available soon also. |
I think the single reason it's harder to build out than expected is because it's GraphQL without good docs on how to use the API directly (-python). The first time we tried (2.5 years ago), Shuffle didn't support GraphQL, but we do now. Since we don't really want to make it a custom Python app, we'll have to do some reverse engineering of the PyCTI library and frontend it seems.. Shouldn't be too hard :) |
Aaand edit 2: We pushed the platform fixes, and it's been deployed with a base set of actions. Have a look here: It's all from reversing the UI's interactions and can probably be optimized quite a bit. @weslambert - I'd love if you could take over some of this work :) |
Threat Intel gives us an important insight into how the world outside our organization works - what incidents occurred etc.
Basic use-cases:
TI systems:
The text was updated successfully, but these errors were encountered: