Cuckoo Feed
Supported by community
Adversary & Campaign Insights
Overview
Polls Cuckoo Sandbox for completed malware analysis tasks and imports behavioral IOCs (file hashes, network activity, dropped files, signatures) into OpenCTI as STIX 2.1 reports and indicators.
Cuckoo Sandbox is an open-source automated malware analysis system that executes suspicious files in an isolated environment and monitors their behavior.
This connector polls the Cuckoo Sandbox API for completed analysis tasks and imports the results into OpenCTI as comprehensive malware analysis reports. For each completed task, it extracts behavioral indicators including network activity, dropped files, processes, and signatures, then converts them into STIX 2.1 objects.
Key features:
- Automatic polling for new completed analysis tasks
- Extraction of behavioral IOCs: file hashes, network connections, dropped files, registry keys
- Optional STIX Indicator creation for observables
- Configurable score threshold to filter low-confidence results
- Supports Network Traffic and Registry Key observables (configurable)
- Incremental sync via configurable start task ID