Threat › Module 7 › Lesson 2
OpenCTI Named
OpenCTI literacy — entities, relationships, knowledge graph, connectors — concept rows on `$TI_LAB` yaml stubs only.
Visual · t33_opencti_named
OpenCTI = named graph platform vocabulary. $TI_LAB stubs. Original Cyberlium.
Opening
OpenCTI connects entities in a graph — name entity and relationship rows on YOUR lab stubs before touching prod OpenCTI without RoE.
OpenCTI literacy names: entity types (threat actor, malware, indicator literacy stubs), relationship edges category, knowledge graph / STIX mapping category, connector/import literacy stub, and workspace/report object category. Analyst drafts OpenCTI concept sketch on `$TI_LAB` — three entities, two relationships in YOUR yaml stub, one connector name literacy (MISP/STIX stub only) — without employer prod OpenCTI admin without ticket, without graphing live victim identities, without OpenCTI as dark-web marketplace front-end. Cyberlium pairs MISP event literacy with graph platform vocabulary — defender reading only on YOUR stubs. Refused: unauthorized prod OpenCTI, victim identity nodes, marketplace connector cookbooks. Lab row: OpenCTI concept sketch (three entities, two relationships, connector stub).
1. Named graph entities
Threat actor, malware, indicator — three entity literacy anchors.
Relationships state directed edge type — document two stubs in yaml.
Command guide
Try these commands — Named graph entities
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
OpenCTI docs — https://docs.opencti.io/latest/ OpenCTI GitHub — https://github.com/OpenCTI-Platform/opencti STIX — https://oasis-open.github.io/cti-documentation/stix/intro.html
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export TI_LAB=${TI_LAB:-$HOME/cyberlium-lab/t33-ti}
curl -sS https://docs.opencti.io/latest/ | head -10
cat > "$TI_LAB/platforms/opencti-named.txt" <<'EOF'
OpenCTI — NAMED LITERACY:
Knowledge graph: entities (Indicator, Threat-Actor, Campaign, Malware) + relationships
Import: STIX bundles, MISP events, CSV — maps to graph model
Workflow: analyst workbench → enrichment → case management → dashboards
Connectors: sync with MISP, TAXII feeds, MITRE ATT&CK data
Lab: relate YOUR fake STIX stub indicator to a fake campaign note
NEVER: deploy against stranger tenants; no real actor doxxing in graph
EOFCommand — copy this
grep -E 'Knowledge graph|STIX|NEVER|fake' "$TI_LAB/platforms/opencti-named.txt"
Primary tools to practice this lesson: curl, grep. Reference sites: OpenCTI docs (https://docs.opencti.io/latest/); OpenCTI GitHub (https://github.com/OpenCTI-Platform/opencti); STIX (https://oasis-open.github.io/cti-documentation/stix/intro.html). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Connectors literacy
Connector imports from MISP/STIX sources category — lab names only, no live poll.
Knowledge graph links Module 5 ATT&CK mapping rows as coverage overlay literacy.
3. Refused
No unauthorized prod OpenCTI; no victim identity graph nodes.
Platform literacy supports TI program design — not marketplace operationalization.
4. What you ship: OpenCTI concept sketch
Three entities + two relationships + connector stub + NEVER prod OpenCTI line.
5. What you record before the next lesson
OpenCTI concept sketch path.
6. Wrong vs right: criminal markets vs YOUR lab IOCs
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Import marketplace leak bundle into employer prod OpenCTI as 'connector test.'
Right
OpenCTI concept sketch from `$TI_LAB` yaml stub. Next: Platform Ops.
Mission: OpenCTI concept sketch
1) Name three entity types. 2) Two relationship stubs in yaml. 3) One connector name literacy row. 4) Write NEVER unauthorized prod OpenCTI line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Entity vs observable — literacy in OpenCTI?”
Knowledge Check
APPLY: OpenCTI literacy uses:
Multiple choice
Knowledge Check
APPLY: True or False: Victim identity nodes belong in lab graph stubs.
True or False
Knowledge Check
APPLY: OpenCTI literacy includes:
Multiple choice