Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
Corelight Investigator logo

Corelight Investigator

Automatic deploy
Supported by community
Detection & Response Enablement

Overview

Import Corelight Investigator alerts and detections into OpenCTI as STIX Incidents.

The OpenCTI Corelight Investigator connector imports alerts and detections from Corelight Investigator (SaaS NDR) into OpenCTI as STIX Incidents. It periodically queries the Investigator Detections and Alerts API (bearer API key), maps the normalized Investigator severity (1-10) to the OpenCTI severity, extracts the source/destination IP observables referenced by an alert, and attributes the imported objects to a Corelight Investigator author identity with a configurable TLP marking. Imports are incremental using the connector state.

Basic information

Corelight Investigator
Connectors
7.260706.0
0

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".