Shadowserver
Verified
Commercial Threat Intel
Overview
The integration uses Shadowserver reports API to query the available Shadowserver reports and transform them into STIX objects making them available within OpenCTI. All available reports are downloaded and an Artifact object is created with the origi
The integration uses Shadowserver reports API to query the available Shadowserver reports and transform them into STIX objects making them available within OpenCTI. All available reports are downloaded and an Artifact object is created with the original file. STIX Note objects are added to both the Report and the CustomObjectCaseIncident with a mark-down rendition of each finding from the report. API and report references from The Shadowserver Foundation The integration creates the following types of Stix objects and relationships between them. On the initial run, the integration defaults to the last 30-days of reports. Every run after that, it provides an update for the last 3-days.