opencti icon indicating copy to clipboard operation
opencti copied to clipboard

Ability to search OpenCTI for a list of Observables (as opposed to one by one)

Open securitiz opened this issue 3 years ago • 0 comments

Use case

It is useful to see if a list of IOCs have been observed in OpenCTI, and if so, in which Reports

Current Workaround

Search every observable one by one

Proposed Solution

An option by the global search bar (at the top right), to copy/paste a list of observables. A global search would be performed on each one. In order to avoid false positives, each search should be performed in as if there are double quotes around them. Results should only be the direct hits, which should be clickable.

Ideally when hovering over the results, some basic information would pop up about in which situations the observable has been seen. Aka a list of reports, summary of relationships, etc

The results should be clickable (like a singular global search)

Additional Information

If the feature request is approved, would you be willing to submit a PR?

Yes / No (Help can be provided if you need assistance submitting a PR)

securitiz avatar Aug 04 '22 02:08 securitiz