These instructions are for connecting the PrecisionSec Threat Intelligence feed live stream to your existing OpenCTI instance by creating an OpenCTI Stream.

Credentials required. If you have not yet received evaluation credentials, please request access.

This guide follows the OpenCTI automated import documentation.

  1. In the left navigation bar, go to Data → Ingestion.

    OpenCTI left navigation with Data expanded and Ingestion selected

  2. In the Ingestion navigation list, select OpenCTI Streams.

    Ingestion navigation list with OpenCTI Streams selected

  3. Click Create OpenCTI Stream at the top right of the OpenCTI Streams page. A fly-out panel titled Create an OpenCTI Stream appears.

  4. In the Name field, enter PrecisionSec Threat Intelligence or a name of your choice.

  5. In the Remote OpenCTI URL field, enter https://opencti.precisionsec.com/.

  6. In the Remote OpenCTI token field, enter the user token that PrecisionSec provided.

  7. Click Validate. After a moment the button changes to Reset and the Remote OpenCTI stream ID dropdown appears, populated with PrecisionSec OpenCTI Live Stream. Select it.

  8. Automatically create a service account: this controls how the imported data is attributed inside your platform. Pick one:

    • Enable it and OpenCTI provisions a dedicated service account for this stream. The Service account responsible for data creation field below fills in automatically (shown as [S] followed by the stream name) and is read-only.
    • Leave it off and set User responsible for data creation yourself to an existing OpenCTI user. Dedicating one user per source keeps attribution clear.
  9. Confidence level: raise this from its default of 50 (3 - Possibly True) to 80, the value PrecisionSec recommends for this feed.

  10. Set Starting synchronization to the current date and time so the stream ingests data published from that point forward. Leave it empty only if you want OpenCTI to backfill the entire stream history.

  11. Enable Take deletions into account to remove data from your platform when it is deleted on the PrecisionSec stream. Data is not deleted if another source imported it previously.

  12. Enable the Verify SSL certificate toggle.

  13. Leave any remaining options at their defaults.

  14. Click Verify. Verification can take a minute or more. When it succeeds, the Create button is enabled and turns blue. The completed panel looks similar to this:

    Completed Create an OpenCTI Stream panel: the validated remote OpenCTI configuration, Automatically create a service account enabled, and the sync options set

  15. Click Create. Once the stream is verified, you are returned to the Data → Ingestion → OpenCTI Streams page. Click the three dots next to the new stream entry and click Start.

    OpenCTI Streams list with the three-dot menu open on the PrecisionSec Threat Intelligence entry, showing Start, Update, Export, and Delete

  16. When asked Do you want to start this OpenCTI stream?, click Start.

    Confirmation dialog reading “Do you want to start this OpenCTI stream?” with Cancel and Start buttons

  17. Verify the import is running. Go to Data → Ingestion → Monitoring. The dashboard reports connected workers, queued and processed bundles, read and write rates, and the total document count, and the figures climb as data flows in.

    Ingestion Monitoring dashboard: connected workers, queued bundles, bundles processed per second, read and write operations per second, and total documents

The Messages count on the stream entry also begins to climb as your OpenCTI instance ingests data.

Ready to see all of our data?

Request a 15-day free trial and get live, curated threat intelligence feeds.

Request a 15-day trial