Add OpenCTI Analyzer v1#725
Conversation
|
Thank you @dadokkio for the test and the feedback. I admit that I don't use TheHive templates in my main use cases so I tried to provide this one based on existing ones but without proper testing. |
|
@amr-cossi we were thinking about writing a responder in order to push infomation back from thehive to openCTI [maybe related to https://github.com/OpenCTI-Platform/connectors/issues/3 ] |
|
I would think of 2 possible ways to achieve this :
For the other way around, this Analyzer is for IOC searching only. A use case where a TheHive case should be opened from OpenCTI could also exist. In OpenCTI-Platform/connectors#3, @SamuelHassine suggested that the OpenCTI connector could be bi-directionnal. It could be able call the Cortex responder to create a TheHive case based on some filtering. |

#723