Skip to main content
OpenCTI is an open-source threat intelligence platform that security teams use to store, correlate, investigate, and share cyber threat intelligence. With this integration, Pulsedive acts as a TAXII 2.1 server and OpenCTI connects as a TAXII client, polling Pulsedive on a schedule and importing indicators in STIX format into its knowledge base. Because Pulsedive scores and deduplicates indicators before export, your analysts start from enriched context instead of raw, unsorted data. OpenCTI offers two ways to import from Pulsedive:
  • Native TAXII import, built into recent OpenCTI versions. Use this when your version supports it.
  • The legacy external-import TAXII2 connector, for older versions that don’t yet include native TAXII import.

Prerequisites

Before you connect OpenCTI to Pulsedive, make sure you have:
  • A Pulsedive account and API key. Find your API key on your Pulsedive account page.
  • A Pulsedive Pro or Feed plan to access the Indicator and Threat collections. The free Test collection works with any account, so you can evaluate the integration first.
In OpenCTI, make sure you have:
  • An OpenCTI instance you can administer.
  • For the legacy path, the ability to deploy a connector and set its environment variables.

Connecting OpenCTI to Pulsedive with Native TAXII Import

OpenCTI’s built-in TAXII ingester polls Pulsedive and imports each collection you configure. A TAXII ingester imports one collection, so configure one ingester per Pulsedive collection.
  1. In OpenCTI, go to Data, then Ingestion.
  2. Select the TAXII Feeds tab.
  3. Create a new TAXII feed ingester.
  4. Enter details for the ingester:
  5. Select the user responsible for the imported data. A dedicated import user keeps the source traceable.
  6. Optionally, set an import-from date to limit how far back OpenCTI retrieves data.
  7. Save the ingester, then start it from the burger menu.
To import another collection, repeat these steps with the next Collection ID. To review the full TAXII reference, visit STIX/TAXII Reference.

Connecting OpenCTI to Pulsedive with the Legacy Connector

If your OpenCTI version doesn’t include native TAXII import, deploy the external-import TAXII2 connector and configure it with these environment variables.
Adjust TAXII2_COLLECTIONS to the collections you want to ingest.
For the connector source and full configuration options, visit the OpenCTI TAXII2 connector repository.

Verifying the Connection

Confirm that Pulsedive indicators are flowing into OpenCTI before you rely on them in your workflows. OpenCTI’s ingestion manager polls on a schedule and imported data can take a few minutes to appear depending on platform load.
  1. Open Data, then Ingestion, and confirm that your Pulsedive ingester is running.
  2. Open the knowledge base and confirm that Pulsedive indicators and observable entities are present.

Using Pulsedive Data in OpenCTI

Once Pulsedive indicators are in your knowledge base, OpenCTI correlates them with your existing entities so you can investigate, label, and share them. To shape what you ingest and how you organize it, visit OpenCTI’s automated import documentation. To review the vendor-agnostic setup, visit Quick Setup.