connectors icon indicating copy to clipboard operation
connectors copied to clipboard

[Crowdstrike] Create an internal enrichment connector for Crowdstrike

Open TechBurn0ut opened this issue 2 years ago • 0 comments

Use case

Current, the OpenCTI platform only supports feeds from Crowdstrike and not enrichment. As a cyber threat analyst, I require an automation that can enrich a given indicator from the Crowdstrike API.

Current Workaround

This feature does not exist in the platform. We currently utilize xSOAR to handle the connections to the CS API.

Proposed Solution

Create a new internal-enrichment connector that can enrich an observable\indicator from the Crowdstrike API.

TechBurn0ut avatar Apr 07 '22 16:04 TechBurn0ut