OpenCTI Graphql
OpenCTI is an open-source platform that facilitates the management and analysis of cyber threat intelligence.
OpenCTI is a comprehensive threat intelligence platform that centralizes and analyzes cyber threat data. The OpenCTI GraphQL connector enables Swimlane Turbine users to execute GraphQL queries and mutations directly against the OpenCTI API, facilitating seamless retrieval and analysis of threat intelligence data. By integrating with OpenCTI GraphQL, users can automate the extraction of valuable threat insights, enhancing their security operations and decision-making processes.
Limitations
None to date.
Supported Versions
This connector targets the OpenCTI GraphQL API as documented at https://docs.opencti.io/latest/reference/api/.
Additional Docs
Configuration
Prerequisites
Before you can use the OpenCTI GraphQL connector for Turbine, you'll need access to the OpenCTI API. This requires the following:
- HTTP Bearer authentication using the following parameters:
- URL: The endpoint URL for accessing the OpenCTI API.
- API Key: A valid API key to authenticate requests to the OpenCTI API.
Authentication Methods
To use the OpenCTI GraphQL connector within the Swimlane Turbine platform, ensure you have:
- Bearer token (API key) authentication:
- URL: The base URL of your OpenCTI instance.
- API Key: Your OpenCTI API key, used as a Bearer token.
Capabilities
This OpenCTI GraphQL Connector provides the following capabilities:
- Execute GraphQL Query
Execute GraphQL Query
- Execute an arbitrary GraphQL query or mutation against the OpenCTI /graphql endpoint and return the JSON response. Click Here.
Notes
- More information on OpenCTI can be found here.
Configurations
OpenCTI GraphQL Bearer Authentication
Authenticates to the OpenCTI API using a Bearer token (API key).
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | Base URL of the OpenCTI instance (for example, https://opencti.example.com). | string | Required |
token | OpenCTI API key used as a Bearer token in the Authorization header. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Execute GraphQL Query
Execute a GraphQL query or mutation against the OpenCTI /graphql endpoint and return the JSON response. Requires a JSON body with a query.
Endpoint
- URL: graphql
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
query | string | Optional | GraphQL query or mutation string to execute against the OpenCTI API. |
variables | object | Optional | Optional variables object to pass to the GraphQL query. |
operationName | string | Optional | Optional operation name. Required when the query string contains multiple operations. |
Input Example
{"json_body":{"query":"query StixCyberObservables($search: String) {\n stixCyberObservables(search: $search) {\n edges {\n node {\n id\n entity_type\n observable_value\n }\n }\n }\n}","variables":{"search":"8.8.8.8"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP response status code returned by the OpenCTI API. |
reason | string | HTTP reason phrase. OK indicates success. |
data | object | GraphQL response data. Shape depends on the executed query. |
errors | array | List of GraphQL errors returned for the request, when present. |
errors.message | string | Response message |
errors.path | array | Error message if any |
errors.extensions | object | Error message if any |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"data":{"stixCyberObservables":{}}}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |