{
  "name": "ti_opencti",
  "title": "OpenCTI",
  "version": "2.15.3",
  "release": "ga",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Ingest threat intelligence indicators from OpenCTI with Elastic Agent.",
  "type": "integration",
  "download": "/epr/ti_opencti/ti_opencti-2.15.3.zip",
  "path": "/package/ti_opencti/2.15.3",
  "icons": [
    {
      "src": "/img/opencti-logo.svg",
      "path": "/package/ti_opencti/2.15.3/img/opencti-logo.svg",
      "title": "OpenCTI logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.2 || ^9.0.5"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "threat_intel"
  ],
  "signature_path": "/epr/ti_opencti/ti_opencti-2.15.3.zip.sig",
  "format_version": "3.4.0",
  "readme": "/package/ti_opencti/2.15.3/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/screenshot1.png",
      "path": "/package/ti_opencti/2.15.3/img/screenshot1.png",
      "title": "Dashboard: OpenCTI Overview",
      "size": "1280x1329",
      "type": "image/png"
    },
    {
      "src": "/img/screenshot2.png",
      "path": "/package/ti_opencti/2.15.3/img/screenshot2.png",
      "title": "Dashboard: OpenCTI Tags & Quality",
      "size": "1280x1329",
      "type": "image/png"
    },
    {
      "src": "/img/screenshot3.png",
      "path": "/package/ti_opencti/2.15.3/img/screenshot3.png",
      "title": "Dashboard: OpenCTI Ingestion",
      "size": "1280x1329",
      "type": "image/png"
    },
    {
      "src": "/img/screenshot4.png",
      "path": "/package/ti_opencti/2.15.3/img/screenshot4.png",
      "title": "Add OpenCTI integration",
      "size": "1268x1323",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/ti_opencti/2.15.3/LICENSE.txt",
    "/package/ti_opencti/2.15.3/changelog.yml",
    "/package/ti_opencti/2.15.3/manifest.yml",
    "/package/ti_opencti/2.15.3/validation.yml",
    "/package/ti_opencti/2.15.3/docs/README.md",
    "/package/ti_opencti/2.15.3/img/opencti-logo.svg",
    "/package/ti_opencti/2.15.3/img/screenshot1.png",
    "/package/ti_opencti/2.15.3/img/screenshot2.png",
    "/package/ti_opencti/2.15.3/img/screenshot3.png",
    "/package/ti_opencti/2.15.3/img/screenshot4.png",
    "/package/ti_opencti/2.15.3/data_stream/indicator/lifecycle.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/manifest.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/sample_event.json",
    "/package/ti_opencti/2.15.3/kibana/dashboard/ti_opencti-0628df00-5958-11ee-ba5f-49a63bb985cd.json",
    "/package/ti_opencti/2.15.3/kibana/dashboard/ti_opencti-274cda10-b452-11ee-9ed7-19d912c01624.json",
    "/package/ti_opencti/2.15.3/kibana/dashboard/ti_opencti-83b2bef0-591c-11ee-ba5f-49a63bb985cd.json",
    "/package/ti_opencti/2.15.3/data_stream/indicator/fields/base-fields.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/fields/ecs.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/fields/is-ioc-transform-source-true.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/fields/opencti.yml",
    "/package/ti_opencti/2.15.3/elasticsearch/transform/latest_ioc/manifest.yml",
    "/package/ti_opencti/2.15.3/elasticsearch/transform/latest_ioc/transform.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/agent/stream/cel.yml.hbs",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/default.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_artifact.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_autonomous_system.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_directory.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_domain_name_or_hostname.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_file.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_pattern.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_url_field.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_windows_registry_key.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_windows_registry_value_type.yml",
    "/package/ti_opencti/2.15.3/data_stream/indicator/elasticsearch/ingest_pipeline/ecs_from_x509_certificate.yml",
    "/package/ti_opencti/2.15.3/elasticsearch/transform/latest_ioc/fields/base-fields.yml",
    "/package/ti_opencti/2.15.3/elasticsearch/transform/latest_ioc/fields/ecs.yml",
    "/package/ti_opencti/2.15.3/elasticsearch/transform/latest_ioc/fields/is-ioc-transform-source-false.yml",
    "/package/ti_opencti/2.15.3/elasticsearch/transform/latest_ioc/fields/opencti.yml"
  ],
  "policy_templates": [
    {
      "name": "opencti",
      "title": "OpenCTI",
      "description": "Collect OpenCTI data.",
      "inputs": [
        {
          "type": "cel",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the OpenCTI instance. E.g. https://demo.opencti.io",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "api_key",
              "type": "password",
              "title": "API Key",
              "description": "API key from your profile page in OpenCTI, for bearer authentication.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "oauth2",
              "type": "yaml",
              "title": "OAuth2 Configuration",
              "description": "i.e. client.id, client.secret, token_url and [other OAuth2 options](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#_auth_basic_enabled).",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#client.id: 12345678901234567890abcdef\n#client.secret: abcdef12345678901234567890\n#token_url: http://example.com/oauth2/token\n"
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http[s]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.\n",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "OpenCTI",
          "description": "Collect OpenCTI data."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "ti_opencti.indicator",
      "title": "Indicator",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "cel",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the OpenCTI. NOTE:- Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "page_size",
              "type": "integer",
              "title": "Page Size",
              "description": "Page size for the response from OpenCTI. The maximum supported page size value is 100.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": 50
            },
            {
              "name": "max_executions",
              "type": "integer",
              "title": "Maximum executions",
              "description": "The maximum number of pages to fetch before waiting for an interval to pass.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": 1000
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP Client Timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. NOTE:- Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "opencti-indicator"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original indicator data, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "pattern_types",
              "type": "text",
              "title": "Pattern Types",
              "description": "Filter by pattern type. Most of the time only `stix` is supported.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "indicator_types",
              "type": "text",
              "title": "Indicator Types",
              "description": "Customizable in OpenCTI. Common values: `malicious-activity`, `attribution`, `benign`, `anomalous-activity`, `compromised`, `unknown`.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "revoked",
              "type": "select",
              "title": "Revoked Status",
              "description": "Filter by revoked status.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": ""
            },
            {
              "name": "valid_from_start",
              "type": "text",
              "title": "Valid From (Start Date)",
              "description": "ISO 8601 (2024-01-01T00:00:00Z) or relative (now-30d).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "valid_until_end",
              "type": "text",
              "title": "Valid Until (End Date)",
              "description": "ISO 8601 (2024-12-31T23:59:59Z) or relative (now+30d).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "label_ids",
              "type": "text",
              "title": "Label IDs (UUIDs)",
              "description": "Must be UUIDs. Find in OpenCTI: Settings → Taxonomies → Labels.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "confidence_min",
              "type": "integer",
              "title": "Minimum Confidence Level",
              "description": "Range: 0-100.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "author_ids",
              "type": "text",
              "title": "Author IDs (UUIDs)",
              "description": "Must be UUIDs. Find by clicking on any author entity in OpenCTI.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "creator_ids",
              "type": "text",
              "title": "Creator User IDs (UUIDs)",
              "description": "Must be user UUIDs. Find in Settings → Security → Users.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "created_after",
              "type": "text",
              "title": "Created After",
              "description": "ISO 8601 (2024-01-01T00:00:00Z) or relative (now-7d).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "modified_after",
              "type": "text",
              "title": "Modified After",
              "description": "ISO 8601 (2024-01-01T00:00:00Z) or relative (now-24h).",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "marking_ids",
              "type": "text",
              "title": "Marking Definition IDs (UUIDs)",
              "description": "Filter by marking definitions (e.g., TLP levels). Must be UUIDs. Common markings: TLP:CLEAR, TLP:GREEN, TLP:AMBER, TLP:RED.",
              "multi": true,
              "required": false,
              "show_user": false
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "cel.yml.hbs",
          "title": "Indicator",
          "description": "Collect indicators from OpenCTI.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "ti_opencti",
      "path": "indicator"
    }
  ]
}
