Hybrid Analysis Sandbox
自動配備
Filigranの提供による
Detection & Response Enablement
概要
Submits files, URLs, and domains to Hybrid Analysis for sandbox detonation, enriching OpenCTI observables with MITRE ATT&CK techniques, dropped files, network indicators, and maliciousness scores.
The OpenCTI Hybrid Analysis enrichment connector allows automatic enrichment of StixFile, Artifact, URL, Domain, and Hostname observables by submitting them for sandbox analysis. It enriches observables with associated MITRE ATT&CK techniques, extracts contacted domain names and IP addresses, identifies dropped files during detonation, and assigns maliciousness scores. The connector automatically creates relationships between observables and discovered indicators, enhancing threat intelligence with behavioral analysis results and attack patterns mapped to the MITRE framework.