OpenCTI-Platform / opencti

Open Cyber Threat Intelligence Platform
https://opencti.io
Other
6.25k stars 922 forks source link

OpenCTI and TheHive #4766

Open khoabui333 opened 11 months ago

khoabui333 commented 11 months ago

Hi, I connected OpenCTI with TheHive by TheHive connector. Then, I analyze a case in TheHive by using Cortex and it returned me a report. However, my OpenCTI can only ingest the case from TheHive and the report cannot be ingested with the case.

image

Is there any method that can help me to bring the report from TheHive to OpenCTI. Thanks.

cmandich commented 11 months ago

@khoabui333 , this is an interesting feature request. I believe the current connector only imports alerts and cases.

Just to confirm, is this the connector you are referencing? https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/thehive

khoabui333 commented 11 months ago

yes, I already used it but it didn't allow me to import report to OpenCTI

nino-filigran commented 9 months ago

Thanks for your request. Indeed, the Hive only imports Cases (and not reports) and there's currently no way to import directly from the hive using the connector. Is there q specific reason why you would like to import reports from the Hive?