Shadowserver
Automatic deploy
Supported by Filigran
Adversary & Campaign Insights
Overview
Imports Shadowserver internet scanning reports into OpenCTI as STIX Artifacts, Reports, and Case Incidents, with findings converted to STIX Notes.
The Shadowserver connector uses the Shadowserver Foundation's reports API to import internet scanning and threat data into OpenCTI. It downloads available reports, creates STIX Artifact objects from the original files, and generates STIX Notes with markdown renditions of each finding linked to Reports and Case Incidents. On the initial run, the connector imports the last 30 days of reports; subsequent runs fetch the last 3 days incrementally.