OpenCTI Feed Deprecated

Deprecated. Use OpenCTI Feed 4.X instead.

Data Enrichment & Threat Intelligence · OpenCTI Feed · Feed

Details

IDOpenCTI Feed
ProviderFiligran
CategoryData Enrichment & Threat Intelligence
From Version5.5.0
Docker Imagedemisto/opencti:1.0.0.41469
Supported ModulesAgentix XSIAM

README

Ingest indicator feeds from OpenCTI.
Compatible with OpenCTI v3 instances. For v4.* and grater OpenCTI versions use the OpenCTI Feed 4.X integration.

Configure OpenCTI Feed in Cortex

Parameter Description Required
apikey API Key True
base_url Base URL True
indicator_types Indicators Type to fetch True
max_indicator_to_fetch Max. indicators per fetch (default is 500) False
feed Fetch indicators False
feedReputation Indicator Reputation False
feedReliability Source Reliability True
feedExpirationPolicy   False
feedExpirationInterval   False
feedFetchInterval Feed Fetch Interval False
feedTags Tags False
feedBypassExclusionList Bypass exclusion list False
insecure Trust any certificate (not secure) False
proxy Use system proxy settings False

Indicator type parameter

Possible values that are supported in XSOAR and will be generated out of the box:

Types  
ALL  
User-Account  
Domain  
Email-Address  
File-md5  
File-sha1  
File-sha256  
HostName  
IPV4-Addr  
IPV6-Addr  
Registry-Key-Value  
URL  

The following types are supported in OpenCTI but are not supported out of the box in XSOAR. To pull these indicator types from OpenCTI you will need to either create dedicated classification and mapping and/or create corresponding indicator types in your XSOAR system.

Types
autonomous-system
cryptographic-key
cryptocurrency-wallet
email-subject
directory
file-name
file-path
mac-addr
mutex
pdb-path
process
registry-key-value
user-agent
windows-service-name
windows-service-display-name
windows-scheduled-task
x509-certificate-issuer
x509-certificate-serial-number

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

opencti-get-indicators


Gets indicators from the feed.

Base Command

opencti-get-indicators

Input

Argument Name Description Required
limit The maximum number of indicators to return per fetch. The default value is “50”. Optional
indicator_types The indicator types to fetch. Out of the box indicator types supported in XSOAR are: “User-Account”, “Domain”, “Email-Address”, “File-md5”, “File-sha1”, “File-sha256”, “HostName”, “IPV4-Addr”, “IPV6-Addr”, “Registry-Key-Value”, and “URL”. The rest will not cause automatic indicator creation in XSOAR. Please refer to the integration documentation for more information. The default is “ALL”. Optional
last_id The last ID from the previous call from which to begin pagination for this call. Optional

Context Output

Path Type Description
OpenCTI.Indicators.type String Indicator type.
OpenCTI.Indicators.value String Indicator value.
OpenCTI.LastRunID String the id of the last fetch to use pagination.

Command Example

!opencti-get-indicators limit=2 indicator_types=domain

Context Example

{
    "OpenCTI": {
        "Indicators": [
            {
                "type": "Domain",
                "value": "test.com"
            },
            {
                "type": "Domain",
                "value": "test1.com"
            }
        ],
        "LastRunID": "YXJyYXljb25uZWN0aW9uOjI="
    }
}

Human Readable Output

Indicators from OpenCTI

type value
Domain test.com
Domain test.com

opencti-reset-fetch-indicators


WARNING: This command will reset your fetch history.

Base Command

opencti-reset-fetch-indicators

Input

There are no input arguments for this command.

Context Output

There is no context output for this command.

Command Example


#### Context Example

{}
```

Human Readable Output

Fetch history deleted successfully

Configuration parameters

  • apikey — API Key (required)
  • base_url — Base URL (required)
  • indicator_types — Indicators Type to fetch (required)
  • max_indicator_to_fetch — Max. indicators per fetch (default is 500)
  • feed — Fetch indicators
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • tlp_color — Traffic Light Protocol Color
  • feedExpirationPolicy
  • feedExpirationInterval
  • feedFetchInterval — Feed Fetch Interval
  • feedTags — Tags
  • feedBypassExclusionList — Bypass exclusion list
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (2)

  • opencti-get-indicators

    Gets indicators from the feed.

  • opencti-reset-fetch-indicators

    WARNING: This command will reset your fetch history.

category: Data Enrichment & Threat Intelligence
provider: Filigran
commonfields:
  id: OpenCTI Feed
  version: -1
configuration:
- display: API Key
  name: apikey
  required: true
  type: 4
- display: Base URL
  name: base_url
  required: true
  type: 0
- additionalinfo: 'The indicator types to fetch. Out of the box indicator types supported in XSOAR are: "User-Account", "Domain", "Email-Address", "File-md5", "File-sha1", "File-sha256", "HostName", "IPV4-Addr", "IPV6-Addr", "Registry-Key-Value", and "URL". The rest will not cause automatic indicator creation in XSOAR. Please refer to the integration documentation for more information. The default is "ALL".'
  defaultvalue: ALL
  display: Indicators Type to fetch
  name: indicator_types
  options:
  - ALL
  - User-Account
  - Domain
  - Email-Address
  - File-MD5
  - File-SHA1
  - File-SHA256
  - HostName
  - IPV4-Addr
  - IPV6-Addr
  - Registry-Key-Value
  - URL
  required: true
  type: 16
- defaultvalue: '500'
  display: Max. indicators per fetch (default is 500)
  name: max_indicator_to_fetch
  type: 0
  required: false
- defaultvalue: 'true'
  display: Fetch indicators
  name: feed
  type: 8
  required: false
- additionalinfo: Indicators from this integration instance will be marked with this reputation
  defaultvalue: feedInstanceReputationNotSet
  display: Indicator Reputation
  name: feedReputation
  options:
  - None
  - Good
  - Suspicious
  - Bad
  type: 18
  required: false
- additionalinfo: Reliability of the source providing the intelligence data
  defaultvalue: F - Reliability cannot be judged
  display: Source Reliability
  name: feedReliability
  options:
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  required: true
  type: 15
- additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed
  display: Traffic Light Protocol Color
  name: tlp_color
  options:
  - RED
  - AMBER
  - GREEN
  - WHITE
  type: 15
  required: false
- display: ''
  name: feedExpirationPolicy
  options:
  - never
  - interval
  - indicatorType
  - suddenDeath
  type: 17
  required: false
- display: ''
  name: feedExpirationInterval
  type: 1
  required: false
- defaultvalue: '240'
  display: Feed Fetch Interval
  name: feedFetchInterval
  type: 19
  required: false
- additionalinfo: Supports CSV values.
  display: Tags
  name: feedTags
  type: 0
  required: false
- additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.
  display: Bypass exclusion list
  name: feedBypassExclusionList
  type: 8
  required: false
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
deprecated: true
description: Deprecated. Use OpenCTI Feed 4.X instead.
display: OpenCTI Feed 3.X (Deprecated)
name: OpenCTI Feed
script:
  commands:
  - arguments:
    - defaultValue: '50'
      description: The maximum number of indicators to return per fetch. The default value is "50".
      name: limit
    - auto: PREDEFINED
      defaultValue: ALL
      description: 'The indicator types to fetch. Out of the box indicator types supported in XSOAR are: "User-Account", "Domain", "Email-Address", "File-md5", "File-sha1", "File-sha256", "HostName", "IPV4-Addr", "IPV6-Addr", "Registry-Key-Value", and "URL". The rest will not cause automatic indicator creation in XSOAR. Please refer to the integration documentation for more information. The default is "ALL".'
      isArray: true
      name: indicator_types
      predefined:
      - ALL
      - User-Account
      - Domain
      - Email-Address
      - File-MD5
      - File-SHA1
      - File-SHA256
      - HostName
      - IPV4-Addr
      - IPV6-Addr
      - Registry-Key-Value
      - URL
    - description: The last ID from the previous call from which to begin pagination for this call.
      name: last_id
    description: Gets indicators from the feed.
    name: opencti-get-indicators
    outputs:
    - contextPath: OpenCTI.Indicators.type
      description: Indicator type.
      type: String
    - contextPath: OpenCTI.Indicators.value
      description: Indicator value.
      type: String
    - contextPath: OpenCTI.LastRunID
      description: the id of the last fetch to use pagination.
      type: String
  - description: 'WARNING: This command will reset your fetch history.'
    name: opencti-reset-fetch-indicators
  dockerimage: demisto/opencti:1.0.0.41469
  feed: true
  runonce: false
  script: '-'
  subtype: python3
  type: python

fromversion: 5.5.0