Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
Intezer Sandbox logo

Intezer Sandbox

Supported by community
Detection & Response Enablement

Overview

Submits artifact observables to Intezer Analyze for dynamic malware analysis, enriching OpenCTI with malware family associations, verdicts, and behavioral relationships.

The OpenCTI Intezer Sandbox enrichment connector allows automatic enrichment of Artifact observables by submitting suspicious files for dynamic analysis. It retrieves detailed sandbox detonation results, associates detected malware families, and assigns maliciousness verdicts (Malicious, Suspicious, Trusted, Unknown) to observables. The connector automatically correlates findings within OpenCTI by creating or updating Malware entities and establishing relationships between artifacts and threat families, enhancing the overall threat intelligence context.

Basic information

Intezer Sandbox
Connectors
6.8.13
0

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".