AssemblyLine
コミュニティの提供による
Detection & Response Enablement
概要
Enriches StixFile and Artifact observables by submitting them to an AssemblyLine 4 instance for automated malware analysis, then imports verdicts, tags, and extracted IOCs back into OpenCTI.
Enrich OpenCTI Artifacts and StixFiles by submitting them to an AssemblyLine 4 deployment for sandbox analysis. AssemblyLine results are pushed back as a Malware-Analysis SDO, malicious indicators (domains, IPs, URLs), Malware SDOs for attributed families, MITRE ATT&CK Attack Patterns observed at runtime, a Note summarising the verdict, and an external reference to the AssemblyLine submission.