Support for Indicators of Behavior (IoBs) and OCA IoB Extensions in OpenCTI #10029
Labels
feature
use for describing a new feature to develop
needs triage
use to identify issue needing triage from Filigran Product team
Support for Indicators of Behavior (IoBs) and OCA IoB Extensions in OpenCTI
Description
OpenCTI currently supports STIX 2.1 Indicators (
indicator
objects), which are primarily used for Indicators of Compromise (IoCs)—atomic artifacts such as IP addresses, domains, hashes, and URLs. However, modern threat detection requires tracking adversary behaviors (IoBs) rather than just static IoCs.This issue proposes adding support for Indicators of Behavior (IoBs) in OpenCTI, following the Open Cybersecurity Alliance (OCA) IoB Sub-Project, which extends STIX 2.1 to model repeatable adversary behaviors, detection correlation, and response playbooks.
Problem Statement
Proposed Solution
Enhance OpenCTI’s STIX 2.1 Indicator capabilities to support IoBs using OCA IoB extensions.
1. Adopt STIX 2.1 Indicators for Behavior-Based Patterns
indicator
objects to store complex behavioral patterns instead of just static artifacts.2. Integrate OCA IoB Extensions for Detection Correlation
3. Add Relationships Between IoBs, MITRE ATT&CK, and Courses of Action
Resources
Conclusion
Supporting Indicators of Behavior (IoBs) in OpenCTI will significantly improve threat intelligence correlation, behavior-based detection, and automated response. This aligns with industry trends towards behavioral analytics over static IoCs and enhances OpenCTI’s capability to provide actionable, real-world intelligence.
The text was updated successfully, but these errors were encountered: