MISP has a threat actor dataset (intrusion set in STIX senses) that would be interesting to add to OpenCTI and could be integrated into our dataset.
Resources:
Note:
- "cfr-suspected-state-sponsor" -> Seems to be the "Originates from" field for intrusions set
- "cfr-suspected-victims" -> Should be a country and a relationship "targets" with the intrusion set
- "cfr-target-category -> Should be a sector and a relationship "targets" with the intrusion set
- "cfr-type-of-incident" -> Seems to be the "Primary motivation" field for intrusions set
MISP has a threat actor dataset (intrusion set in STIX senses) that would be interesting to add to OpenCTI and could be integrated into our dataset.
Resources:
Note: