OpenCTI-Platform/opencti — reverse-engineered prompt
Reverse engineered prompt
Build me an open source cyber threat intelligence platform like OpenCTI. I want security analysts to be able to collect and organize information about threats, malware, attack techniques, incidents, reports, indicators, victims, and sources in one place.
The app should let users link related pieces of intelligence together, track confidence levels, first seen and last seen dates, and always show where the information came from. It should make the data easy to explore visually, not just as tables, so analysts can understand relationships and discover useful patterns.
Please include a clean web interface, user friendly search and filtering, import and export options such as CSV and STIX2 bundles, and a way to connect with common tools or datasets like MISP, TheHive, and MITRE ATTACK. Keep it practical for a small security team to run, preferably with Docker setup instructions.
Look up the current OpenCTI docs online if you need to understand the expected behavior.
Want more depth? Deep Reverse