Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
CAPE Sandbox logo

CAPE Sandbox

Supported by community
Detection & Response Enablement

Overview

The CAPEv2 connector allows submitting File and Artifact observables for dynamic malware analysis, then imports the resulting extracted configurations, network IOCs, MITRE ATT&CK mappings, and payloads back into OpenCTI

CAPEv2 (Config And Payload Extraction) is an open-source malware sandbox derived from Cuckoo Sandbox, specifically designed for extracting malware configurations and payloads. It provides comprehensive behavioral analysis including process monitoring, network traffic capture, API tracing, and automated config extraction.

This connector integrates CAPEv2 with OpenCTI to submit File and Artifact observables for dynamic analysis, import extracted malware configurations, create relationships to MITRE ATT&CK techniques, extract network IOCs (domains, IP addresses), and upload extracted payloads and process dumps as related artifacts.

Basic information

CAPE Sandbox
Connectors
6.8.13
3

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".