Lookup Opencti

Use when you need to query an OpenCTI instance — is this IOC already known, what entities/reports/campaigns exist for an actor — or push new intel into it — creating indicators/observables, labelling, TLP markings, relationships, or importing a STIX 2.1 bundle. Two-way integration. Commonly invoked by /ip-investigation and friends to check whether an indicator is already in your knowledge base, and by analytical skills that want to publish their findings back to OpenCTI. Reads $OPENCTI_URL and $OPENCTI_TOKEN.

Liberty91LTD Updated

File contents

Liberty91LTD/cti-skills/tree/main/skills/lookup-opencti commit f6b9ebef98

Frequently asked questions

npx skillmds@latest add liberty91ltd/lookup-opencti