Skip to content

[TruKno] Add external import connector #6286

@hieuttmmo

Description

@hieuttmmo

Summary

Add a new external-import connector for TruKno breach intelligence.

Problem

OpenCTI currently does not provide an official connector for importing TruKno breach reports and their linked malware / ATT&CK techniques.

Proposed solution

Introduce a TruKno external-import connector that polls the TruKno API incrementally, converts updated breach reports into STIX 2.1 bundles, and sends them into OpenCTI.

Initial scope

  • report
  • attack-pattern
  • malware

Notes

This issue is opened to track the upstream contribution associated with PR #6285.

Metadata

Metadata

Assignees

No one assigned

    Labels

    communityuse to identify PR from communityfeatureuse for describing a new feature to developnewuse to identify new integration

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions