OpenCTI-Platform / opencti

Open Cyber Threat Intelligence Platform
https://opencti.io
Other
6.38k stars 944 forks source link

Ability to trigger enrichment from Investigation directly #6651

Open nino-filigran opened 7 months ago

nino-filigran commented 7 months ago

Use case

Users without EE cannot use automation to automatically enrich data. As a result, when working on an investigation and needing to pivot on the enrichment, users need to:

This causes a lot of fatigue. Here the discussion on Slack: https://filigran-community.slack.com/archives/CHZC2D38C/p1712732954130589

Current Workaround

Explained above.

Proposed Solution

Add a way to enrich directly from an investigation graph:

Additional Information

If the feature request is approved, would you be willing to submit a PR?

sweet-mentat commented 2 months ago

I think this one is a game changer and would be super helpful to analysts performing analysis