Cyberlium

Threat › Module 7 › Lesson 2

BeginnerModule 7Lesson 2/5

OpenCTI Named

OpenCTI literacy — entities, relationships, knowledge graph, connectors — concept rows on `$TI_LAB` yaml stubs only.

15 min+40 XP3 quiz
Module progress2 of 5

Visual · t33_opencti_named

OpenCTI = named graph platform vocabulary. $TI_LAB stubs. Original Cyberlium.

Opening

OpenCTI connects entities in a graph — name entity and relationship rows on YOUR lab stubs before touching prod OpenCTI without RoE.

OpenCTI literacy names: entity types (threat actor, malware, indicator literacy stubs), relationship edges category, knowledge graph / STIX mapping category, connector/import literacy stub, and workspace/report object category. Analyst drafts OpenCTI concept sketch on `$TI_LAB` — three entities, two relationships in YOUR yaml stub, one connector name literacy (MISP/STIX stub only) — without employer prod OpenCTI admin without ticket, without graphing live victim identities, without OpenCTI as dark-web marketplace front-end. Cyberlium pairs MISP event literacy with graph platform vocabulary — defender reading only on YOUR stubs. Refused: unauthorized prod OpenCTI, victim identity nodes, marketplace connector cookbooks. Lab row: OpenCTI concept sketch (three entities, two relationships, connector stub).

1. Named graph entities

Threat actor, malware, indicator — three entity literacy anchors.

Relationships state directed edge type — document two stubs in yaml.

Command guide

Try these commands — Named graph entities

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

OpenCTI docs — https://docs.opencti.io/latest/ OpenCTI GitHub — https://github.com/OpenCTI-Platform/opencti STIX — https://oasis-open.github.io/cti-documentation/stix/intro.html

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl

macOS: Built-in

Windows: Built-in (PowerShell: Invoke-WebRequest)

═══ LINUX / macOS ═══

Command — copy this

export TI_LAB=${TI_LAB:-$HOME/cyberlium-lab/t33-ti}
curl -sS https://docs.opencti.io/latest/ | head -10
cat > "$TI_LAB/platforms/opencti-named.txt" <<'EOF'
OpenCTI — NAMED LITERACY:
  Knowledge graph: entities (Indicator, Threat-Actor, Campaign, Malware) + relationships
  Import: STIX bundles, MISP events, CSV — maps to graph model
  Workflow: analyst workbench → enrichment → case management → dashboards
  Connectors: sync with MISP, TAXII feeds, MITRE ATT&CK data
Lab: relate YOUR fake STIX stub indicator to a fake campaign note
NEVER: deploy against stranger tenants; no real actor doxxing in graph
EOF

Command — copy this

grep -E 'Knowledge graph|STIX|NEVER|fake' "$TI_LAB/platforms/opencti-named.txt"

Primary tools to practice this lesson: curl, grep. Reference sites: OpenCTI docs (https://docs.opencti.io/latest/); OpenCTI GitHub (https://github.com/OpenCTI-Platform/opencti); STIX (https://oasis-open.github.io/cti-documentation/stix/intro.html). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Connectors literacy

Connector imports from MISP/STIX sources category — lab names only, no live poll.

Knowledge graph links Module 5 ATT&CK mapping rows as coverage overlay literacy.

3. Refused

No unauthorized prod OpenCTI; no victim identity graph nodes.

Platform literacy supports TI program design — not marketplace operationalization.

4. What you ship: OpenCTI concept sketch

Three entities + two relationships + connector stub + NEVER prod OpenCTI line.

5. What you record before the next lesson

OpenCTI concept sketch path.

6. Wrong vs right: criminal markets vs YOUR lab IOCs

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Import marketplace leak bundle into employer prod OpenCTI as 'connector test.'

  • Right

    OpenCTI concept sketch from `$TI_LAB` yaml stub. Next: Platform Ops.

Mission: OpenCTI concept sketch

1) Name three entity types. 2) Two relationship stubs in yaml. 3) One connector name literacy row. 4) Write NEVER unauthorized prod OpenCTI line.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “Entity vs observable — literacy in OpenCTI?”

Knowledge Check

1

APPLY: OpenCTI literacy uses:

Multiple choice

Knowledge Check

2

APPLY: True or False: Victim identity nodes belong in lab graph stubs.

True or False

Knowledge Check

3

APPLY: OpenCTI literacy includes:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)