Threat › Module 7 › Lesson 2
OpenCTI Named
OpenCTI literacy — entities, relationships, knowledge graph, connectors — concept rows on `$TI_LAB` yaml stubs only.
Visual · t33_opencti_named
OpenCTI = named graph platform vocabulary. $TI_LAB stubs. Original Cyberlium.
Opening
OpenCTI connects entities in a graph — name entity and relationship rows on YOUR lab stubs before touching prod OpenCTI without RoE.
OpenCTI literacy names: entity types (threat actor, malware, indicator literacy stubs), relationship edges category, knowledge graph / STIX mapping category, connector/import literacy stub, and workspace/report object category. Analyst drafts OpenCTI concept sketch on `$TI_LAB` — three entities, two relationships in YOUR yaml stub, one connector name literacy (MISP/STIX stub only) — without employer prod OpenCTI admin without ticket, without graphing live victim identities, without OpenCTI as dark-web marketplace front-end. Cyberlium pairs MISP event literacy with graph platform vocabulary — defender reading only on YOUR stubs. Refused: unauthorized prod OpenCTI, victim identity nodes, marketplace connector cookbooks. Lab row: OpenCTI concept sketch (three entities, two relationships, connector stub).
1. Named graph entities
Threat actor, malware, indicator — three entity literacy anchors.
Relationships state directed edge type — document two stubs in yaml.
Command guide
Try these commands — Named graph entities
═══ LINUX / macOS (Terminal Practice) ═══
Check system state and user context
Command — copy this
id whoami uname -a
Inspect network sockets listening for connections
Command — copy this
ss -tuln 2>/dev/null || netstat -tuln
Audit active processes
Command — copy this
ps aux | grep -v "\[" | head -15
═══ WINDOWS (POWERSHELL) ═══ Query user identity and system information
Command — copy this
whoami /all Get-ComputerInfo | Select-Object CsName, OsName, OsVersion
Primary tools to practice this lesson: curl, grep. Reference sites: OpenCTI docs (https://docs.opencti.io/latest/); OpenCTI GitHub (https://github.com/OpenCTI-Platform/opencti); STIX (https://oasis-open.github.io/cti-documentation/stix/intro.html). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Connectors literacy
Connector imports from MISP/STIX sources category — lab names only, no live poll.
Knowledge graph links Module 5 ATT&CK mapping rows as coverage overlay literacy.
3. Refused
No unauthorized prod OpenCTI; no victim identity graph nodes.
Platform literacy supports TI program design — not marketplace operationalization.
4. What you ship: OpenCTI concept sketch
Three entities + two relationships + connector stub + NEVER prod OpenCTI line.
5. What you record before the next lesson
OpenCTI concept sketch path.
6. Wrong vs right: criminal markets vs YOUR lab IOCs
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Import marketplace leak bundle into employer prod OpenCTI as 'connector test.'
Right
OpenCTI concept sketch from `$TI_LAB` yaml stub. Next: Platform Ops.
Mission: OpenCTI concept sketch
1) Name three entity types. 2) Two relationship stubs in yaml. 3) One connector name literacy row. 4) Write NEVER unauthorized prod OpenCTI line.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Entity vs observable — literacy in OpenCTI?”
Knowledge Check
APPLY: OpenCTI literacy uses:
Multiple choice
Knowledge Check
APPLY: True or False: Victim identity nodes belong in lab graph stubs.
True or False
Knowledge Check
APPLY: OpenCTI literacy includes:
Multiple choice