Cluster25
Overview
Imports indicators from the Cluster25 (C25) threat intelligence platform into OpenCTI via the C25 API. Requires a valid CLIENT_ID and CLIENT_SECRET. Results are filtered by the user's TLP.
The OpenCTI Cluster25 connector can be used to import indicators from the C25 platform into OpenCTI.It uses che current V1 public APIs to get a valid token and import the supported indicators.In the current implementation, the connector is able to import indicators only.With future releases, it would be possible to import observables, threat actors and various contents as well. Note: in order to use the connector, you need a valid pair of CLIENT_ID and CLIENT_SECRET provided by the C25 team.All the results are implicitly filtered by the user's TLP.