Intel 471 Hunter
Overview
Enrich OpenCTI entities with Intel 471 Hunter hunt packages: sigma detections, analyst runbooks and the threat context around them.
On-demand enrichment of OpenCTI entities with detection coverage from the Intel 471 Hunter hunt package corpus (formerly Cyborg Security Hunter). When an analyst triggers enrichment on a Threat-Actor, Intrusion-Set, Campaign, Attack-Pattern, Vulnerability, Malware, Tool, Sector or Location entity, the connector queries the Hunter /es/query endpoint with the matching filter (actors, campaigns, mitre_technique_ids, exploit_or_vulns, threat_names, tools, target_industries, target/source countries and regions) and materialises every returned hunt package as a STIX 2.1 Report. Each Report carries the hunt title, description, severity-derived score, labels and external references back to the Hunter UI. Its object_refs hold the sigma detection as an Indicator plus the auto-created context - Threat-Actor, Campaign, Malware, Vulnerability, Attack-Pattern, Tool, Sector and Location entities - and the relationships between them. Analyst runbook, mitigation, validation and running-update Notes attach to the Report. A UUID and last_updated cache skips unchanged hunts on repeat enrichments. Intel 471 Website: https://www.intel471.com