Malanta Attribution
概要
Derives Intrusion Sets and `indicates` relationships from Malanta's `apt:` attribution labels on indicators.
Malanta's TAXII feed delivers threat-actor attribution as flat, namespaced labels on indicators (for example apt:APT44) rather than as entities, because OpenCTI's built-in TAXII ingester applies no transformation. This stream connector listens to the OpenCTI event stream and, for every Malanta indicator carrying such a label, creates the corresponding Intrusion Set and an indicates relationship from the indicator to it. The result is a pivotable attribution graph instead of a set of opaque label strings. It is designed to run alongside OpenCTI's native TAXII ingestion, which handles the bulk import; the connector only reacts to the small share of indicators that carry attribution. Malanta's own infrastructure clusters are left untouched: a cluster may aggregate infrastructure from several actors, so attribution is applied to indicators only.