idps-escape

Integration modules

In this folder, we store all artifacts required for enabling our integration solutions, ranging from integration with well-known TIPs such as MISP and OpenCTI, to custom CTI tools, and fixes to other publicly available solutions incorporated into IDPS-ESCAPE. Below we provide a concise map of the currently available integration possibilities.

We also provide analyses of these integrations in terms of their benefits for automating flows from alerts and events to CTI platform level views.

Automated enrichment workflows for improved CTI

The automated trigger stored at integrations/opencti-wazuh-connector/automated_trigger provides

Resolved timestamp parsing issue in OpenCTI-Wazuh connector

Our modified version of the OpenCTI-Wazuh connector stored at integrations/opencti-wazuh-connector provides