Skip to content

feat: document OpenCTI Shodan lab deployment - #17

Closed
egrexsec wants to merge 2 commits into
mainfrom
feat/opencti-shodan-lab
Closed

egrexsec wants to merge 2 commits into
mainfrom
feat/opencti-shodan-lab

Conversation

@egrexsec

@egrexsec egrexsec commented Jul 20, 2026 •

Copy link
Copy Markdown
Owner

1|## Summary
2|- add a pinned, credential-free OpenCTI Community Compose template
3|- add the official Shodan internal-enrichment connector as an opt-in profile
4|- document deployment, hardening, backup, and upgrade gates
5|- record sanitized live enrichment and reboot-persistence validation from the authorized Mayuri lab
6|
7|## Live validation
8|- OpenCTI and dependencies were healthy on the designated CTI host
9|- only the application interface was published to the approved lab segment; backend services remained private to the container network
10|- the Shodan connector registered active for ipv4-addr and indicator
11|- one benign public IPv4 observable completed enrichment with zero connector errors
12|- platform, connector, and observable persisted across guest reboot
13|- a clean post-validation rollback snapshot was created
14|- runtime secrets remained root-only and absent from the repository
15|
16|Exact hostnames, addresses, VM identifiers, snapshot names, credentials, and live environment values are intentionally omitted.
17|
18|## Checks
19|- docker compose --profile shodan config --quiet
20|- python3 automation/validators/check_markdown.py
21|- python3 playbook validate
22|- git diff --check
23|- public-detail scan over PR files: no Mayuri internal address, CTI hostname, VM identifier, or named snapshot remains
24|
25|## Limitations
26|- this proves the historical authorized-lab enrichment path, not production readiness
27|- CTI remains advisory and analyst-triggered
28|- application-consistent backup/restore testing remains open work
29|

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 04f53c3de3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +54 to +55
healthcheck:
test: ["CMD", "mc", "ready", "local"]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use a health check available in the MinIO image

The minio/minio server image does not include the separate mc client binary, so this healthcheck repeatedly exits with mc: not found and MinIO is never marked healthy. Because the opencti service explicitly waits on minio with condition: service_healthy (lines 115–116), a fresh deployment following this template never starts OpenCTI, its worker, or the Shodan profile.

Useful? React with 👍 / 👎.

@egrexsec

Copy link
Copy Markdown
Owner Author

Phase 1 ownership review found this PR is not correctly scoped for cybersecurity-playbook: every changed artifact is OpenCTI/Shodan deployment configuration, operational documentation, or Mayuri lab validation evidence. Per the ecosystem boundary, reusable detection content belongs here, while Mayuri deployment/current-state evidence belongs in mayuri-purple-team-lab. The branch is preserved for re-homing; no fresh live validation is claimed. Closing rather than merging cross-repository operational state.

@egrexsec egrexsec closed this Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant