> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pulsedive.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Integrate with OpenCTI

> Import scored, deduplicated Pulsedive threat intelligence into OpenCTI over TAXII 2.1 for correlation, investigation, and sharing.

OpenCTI is an open-source threat intelligence platform that security teams use to store, correlate, investigate, and share cyber threat intelligence.
With this integration, Pulsedive acts as a TAXII 2.1 server and OpenCTI connects as a TAXII client, polling Pulsedive on a schedule and importing indicators in STIX format into its knowledge base.
Because Pulsedive scores and deduplicates indicators before export, your analysts start from enriched context instead of raw, unsorted data.

OpenCTI offers two ways to import from Pulsedive:

* Native TAXII import, built into recent OpenCTI versions.
  Use this when your version supports it.
* The legacy external-import TAXII2 connector, for older versions that don't yet include native TAXII import.

## Prerequisites

Before you connect OpenCTI to Pulsedive, make sure you have:

* A Pulsedive account and API key.
  Find your API key on your [Pulsedive account page](https://pulsedive.com/account).
* A Pulsedive Pro or Feed plan to access the Indicator and Threat collections.
  The free Test collection works with any account, so you can evaluate the integration first.

In OpenCTI, make sure you have:

* An OpenCTI instance you can administer.
* For the legacy path, the ability to deploy a connector and set its environment variables.

## Connecting OpenCTI to Pulsedive with Native TAXII Import

OpenCTI's built-in TAXII ingester polls Pulsedive and imports each collection you configure.
A TAXII ingester imports one collection, so configure one ingester per Pulsedive collection.

1. In OpenCTI, go to **Data**, then **Ingestion**.
2. Select the **TAXII Feeds** tab.
3. Create a new TAXII feed ingester.
4. Enter details for the ingester:
   | Field Name | Description |
   | - | - |
   | **TAXII server URL** | Use `https://pulsedive.com/taxii2/api/` |
   | **TAXII collection** | ID of the collection you want to import. Available collections include:<br /><ul><li>Indicators: <code>a5cffbfe-c0ff-4842-a235-cb3a7a040a37</code></li><li>Threats: <code>dc9ecfa5-7769-4cf3-b699-38a9776b431d</code></li><li>Test: <code>981c4916-ebb2-4567-aece-54ae970c4230</code><br />(live sample data, free with any API key)</li></ul> |
   | **Username** | Use `taxii2` |
   | **Password** | Your Pulsedive API key |
5. Select the user responsible for the imported data.
   A dedicated import user keeps the source traceable.
6. Optionally, set an **import-from** date to limit how far back OpenCTI retrieves data.
7. Save the ingester, then start it from the burger menu.

To import another collection, repeat these steps with the next Collection ID.

To review the full TAXII reference, visit [STIX/TAXII Reference](/taxii/overview).

## Connecting OpenCTI to Pulsedive with the Legacy Connector

If your OpenCTI version doesn't include native TAXII import, deploy the external-import TAXII2 connector and configure it with these environment variables.

```bash theme={null}
TAXII2_V21=true
TAXII2_DISCOVERY_URL=https://pulsedive.com/taxii2/
TAXII2_USERNAME=taxii2
TAXII2_PASSWORD=<YOUR_PULSEDIVE_API_KEY>
TAXII2_COLLECTIONS=api.Pulsedive indicator data,api.Pulsedive threat data,api.Pulsedive test data
```

<Note>
  Adjust `TAXII2_COLLECTIONS` to the collections you want to ingest.
</Note>

For the connector source and full configuration options, visit the [OpenCTI TAXII2 connector repository](https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/taxii2).

## Verifying the Connection

Confirm that Pulsedive indicators are flowing into OpenCTI before you rely on them in your workflows.
OpenCTI's ingestion manager polls on a schedule and imported data can take a few minutes to appear depending on platform load.

1. Open **Data**, then **Ingestion**, and confirm that your Pulsedive ingester is running.
2. Open the knowledge base and confirm that Pulsedive indicators and observable entities are present.

## Using Pulsedive Data in OpenCTI

Once Pulsedive indicators are in your knowledge base, OpenCTI correlates them with your existing entities so you can investigate, label, and share them.

To shape what you ingest and how you organize it, visit [OpenCTI's automated import documentation](https://docs.opencti.io/latest/usage/import/taxii-feed/).

To review the vendor-agnostic setup, visit [Quick Setup](/taxii/quick-setup).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.