OpenCTI Feed 4.X
Ingest indicators from the OpenCTI feed. Compatible with OpenCTI 5.12.17 and above.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedOpenCTI
Configuration parameters
- base_url — Base URL (required)
- credentials — API Key (leave empty. Fill in the API key in the password field.)
- indicator_types — Indicator types to fetch (required)
- max_indicator_to_fetch — Max indicators per fetch
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedTags — Tags
- feedBypassExclusionList — Bypass exclusion list
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- score_start — Score minimum value
- score_end — Score maximum value
Commands (2)
- opencti-get-indicators — Gets indicators from the feed.
- opencti-reset-fetch-indicators — WARNING: This command will reset your fetch history.