Group-IB Threat Intelligence & Attribution

Pack helps to integrate Group-IB Threat Intelligence and get incidents directly into Cortex XSOAR. The list of included collections: Compromised Accounts, Compromised Cards, Compromised Masked Cards, Brand Protection Phishing, Brand Protection Phishing Kit, OSI Git Leak, OSI Public Leak, Targeted Malware.

Data Enrichment & Threat Intelligence · Group-IB Threat Intelligence

Details

IDGroup-IB Threat Intelligence & Attribution
ProviderGroup IB
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/vendors-sdk:1.0.0.10120494
Supported ModulesAgentix XSIAM

README

Group-IB Threat Intelligence

Pack helps to integrate Group-IB Threat Intelligence and get incidents directly into Cortex XSOAR.
The integration supports multiple collections including compromised accounts, bank cards, breaches, malware, attacks, OSI leaks, vulnerabilities, and threat intelligence. See the Data Collections Overview section below for the complete list with descriptions and recommended date ranges.

Prerequisites

  1. Access Group-IB Threat Intelligence (TI) Web Interface
  2. Generate API Credentials
    • In the web interface, click your name in the upper right corner
    • Select ProfileSecurity and Access tab
    • Click Personal token and follow the instructions to generate your API token
    • Note: The API token serves as your password for authentication
  3. Network Configuration
    • Important: Contact Group-IB support to add your Cortex XSOAR server’s IP address to the allow list
    • If you are using a proxy, provide the public IP address of the proxy server instead
    • Make sure you have added Group-IB API IPs/URLs to you FW/Proxy rules.

Important Notes

Recommended Instance Layout

Run separate integration instances for the following groups:

  • Accounts unique
  • Accounts combolist
  • Cards (masked/unmasked)
  • Public leaks/Git Leaks
  • Breached
  • Vulnerabilities
  • Malware reports and threats including profiles
  • SPD
  • Suspicious IP
  • Malware CNC
  • DDoS/Deface/phishing/phishing_kit

Limit Parameter

The Limit (items per request) parameter specifies the number of records requested per API page. This limit applies to all collections configured in the integration instance.

Important considerations:

  • The limit determines how many records are fetched in a single API request. For example, if “Number of requests per collection” is set to 2 and the limit is 500, the integration will make 2 requests per collection, each requesting up to 500 records, resulting in up to 1000 records per collection per fetch cycle.
  • Different collections may have different optimal limit values based on their data structure and API recommendations. We strongly recommend consulting the official API Limitations documentation for specific limit recommendations for each collection.
  • Best practice: Create separate integration instances for different collections or groups of collections that share similar optimal limit values. This allows you to optimize performance for each collection type.

Collection-Specific Filters

The following three filters control data collection behavior for the compromised/account_group collection:

  • Include unique type in data: Filter to include unique data from the compromised/account_group collection
  • Include combolist type in data: Filter to include combolist data from the compromised/account_group collection
  • Enable filter “Probable Corporate Access”: Filter to limit data collection to only corporate accounts

Filter Logic (applies to unique and combolist filters):

  • If both Include unique type in data and Include combolist type in data are disabled: No filtering is applied, and both types of data are collected
  • If only Include unique type in data is enabled: Only unique records are collected
  • If only Include combolist type in data is enabled: Only combolist records are collected
  • If both Include unique type in data and Include combolist type in data are enabled: Both types of data are collected
  • When both unique and combolist filters are not enabled (no checkboxes selected): Both unique and combolist data types are collected by default (as stated above). In this state, you can enable Enable filter "Probable Corporate Access" to limit the entire feed (both unique and combolist data) to only corporate accounts. You can also combine the corporate access filter with unique or combolist filters, if needed. For example, if you are collecting only combolist data (without unique), you can enable Enable filter "Probable Corporate Access" to limit the combolist collection to only corporate accounts

Best Practice: For optimal organization and performance, consider running two separate integration instances:

  • Instance 1: Enable Include unique type in data only
  • Instance 2: Enable Include combolist type in data only
  • Instance 3 (optional): Enable ‘Probable Corporate Access’ - if you need to focus on your company employees compromises only

These filters have no effect on other collections.

Data Collections Overview

Once the configuration is complete, the following collections become available in Cortex XSOAR. For detailed information about each collection, its structure, and available fields, please refer to the official Collections Details documentation.

Note: If you’re using a POC or partner license, access to data is limited to 30 days. The recommended date ranges below are guidelines and can be adjusted according to your needs.

Collection Description Recommended Date Range
compromised/account_group The collection contains credentials collected from various phishing resources, botnets, C&C servers, Darkweb, etc., used by hackers. All indicated sources are unique and private. It also includes combolist and corporate accounts. For Public Breaches - please refer to compromised/breached. 2-4 years
compromised/bank_card_group Information about compromised bank cards, sourced from card shops, forums, and public leaks. 2 years
compromised/masked_card Information about compromised masked bank card records returned as individual card entries, including card, owner, malware, source, and CNC context. 2 years
compromised/mule Information on compromised accounts used by threat actors for money laundering and fund transfers. 90 days
compromised/spd Suspicious payment details collected from underground markets, forums, and messaging platforms. 90 days
compromised/breached Information about publicly leaked databases containing credentials and personal data. Note: Hunting rules are on by default here. 90 days
attacks/ddos Data on Distributed Denial of Service (DDoS) attacks, including targeted resources and attack durations. 5-10 days
attacks/deface Records of defacement attacks, highlighting compromised websites and related actors. 5-10 days
attacks/phishing_group Information on phishing attacks, including URLs of phishing websites. Note: Do not use IPs for detection - it may cause many false positives. Focus only on URLs. 3-5 days
attacks/phishing_kit Collections of phishing website templates, scripts, and configurations used by attackers. 30 days
apt/threat Reports on nation-state APTs activities, including associated indicators (IOCs), attack techniques, and MITRE ATT&CK mappings. 2-4 years
apt/threat_actor Profiles of nation-state groups detailing their characteristics, targets, motivations, and techniques. 2-4 years
hi/threat Finance motivated cybercriminals reports, including associated indicators (IOCs), attack techniques, and MITRE ATT&CK mappings. 2-4 years
hi/threat_actor Profiles of financially motivated cybercriminals detailing their characteristics, targets, motivations, and techniques. 2-4 years
malware/cnc Information on malware Command-and-Control (C&C) servers used for data exfiltration and command distribution. 90 days
malware/malware Detailed malware descriptions. 2-4 years
osi/git_repository Publicly available code from repositories like GitHub, filtered by your hunting rules. Note: Hunting rules are on by default here. 30 days
osi/public_leak Public data leaks from sources like Pastebin, ghostbin, and others, including credentials, database dumps, configuration files, and logs. Note: Hunting rules are on by default here. 15 days
osi/vulnerability Information on software vulnerabilities, associated exploits, and available proof-of-concept details. 90 days
suspicious_ip/tor_node Data about known Tor exit nodes used as anonymity relays. 5 days
suspicious_ip/open_proxy Information on publicly available proxy servers, including potentially misconfigured proxies. 5 days
suspicious_ip/scanner IP addresses identified as scanning or probing corporate networks. 5 days
suspicious_ip/socks_proxy IP addresses of infected hosts configured as SOCKS proxies used for anonymized attacks. 5 days
suspicious_ip/vpn Information about public and private VPN servers identified as potentially malicious or suspicious. 5 days

Configure Group-IB Threat Intelligence in Cortex

Parameter Description Required
GIB TI URL The FQDN/IP the integration should connect to (default: https://tap.group-ib.com/api/v2/). True
Username Enter the email address you use to log into the web interface. The API token serves as your password for authentication. True
Trust any certificate (not secure) Whether to allow connections without verifying SSL certificates validity. False
Use system proxy settings Whether to use XSOAR system proxy settings to connect to the API. False
Source Reliability Reliability of the source providing the intelligence data. Used as a fixed reliability for reputation commands unless overridden by Ignore Source Reliability override. True
Ignore Source Reliability override If enabled, ignore the instance Source Reliability setting and use the integration’s computed reliability per indicator for reputation commands. False
Colletions to fetch Select the collections you want to fetch incidents from. Read more about collections here. False
Incidents first fetch Specify the date range for initial data fetch (default: “3 days”). False
Number of requests per collection Number of API requests per collection in each fetch iteration (default: 3). If you face some runtime errors, lower the value. False
Skip updated incidents (prevent duplicates) Disabled by default. Enable this only when you want the integration itself to suppress duplicate incidents because Pre-Processing Rules are not working reliably in your environment. When enabled, the integration skips Group-IB records that were already fetched and later re-sent after updates. False
Deduplication lookback (days) Used only when Skip updated incidents (prevent duplicates) is enabled. Defines how long fetched Group-IB incident IDs are remembered in the built-in deduplication cache. Recommended value is 365 days. False
Limit (items per request) Number of items requested per API page. This limit applies to all collections in the instance. The limit determines how many records are fetched in a single API request. For example, if “Number of requests per collection” is 2 and limit is 500, the integration will make 2 requests per collection, each requesting up to 500 records, resulting in up to 1000 records per collection per fetch cycle. We recommend following the official API Limitations documentation for collection-specific limit recommendations. Best practice: create separate integration instances for different collections or groups of collections with similar optimal limit values. False
Enable reputation commands Multi-select list of reputation commands to enable for this integration instance (supported: ip, domain, file). Default: none enabled (fail-safe). Only selected commands perform enrichment and return DBotScore. False
Include combolist type in data Filter to include combolist data from the compromised/account_group collection. Works only for compromised/account_group collection. Filter logic: If only this filter is enabled, only combolist records are collected. If both combolist and unique filters are enabled, both types are collected. If both are disabled, both types are collected by default. False
Include unique type in data Filter to include unique data from the compromised/account_group collection. Works only for compromised/account_group collection. Filter logic: If only this filter is enabled, only unique records are collected. If both combolist and unique filters are enabled, both types are collected. If both are disabled, both types are collected by default. False
Enable filter “Probable Corporate Access” Filter to limit data collection to only corporate accounts. Works only for compromised/account_group collection. When both unique and combolist filters are not enabled, you can enable this to limit the whole feed to corporate accounts only. Can also be combined with unique or combolist filters if needed. False
Hunting Rules To enable the collection of data using hunting rules, please select this parameter. False

Note

Requests to the following collections come with the Hunting Rules parameter by default - and turing it off or on won’t make any changes: osi/git_repository, osi/public_leak, compromised/breached, compromised/messenger, compromised/discord

Built-in deduplication should be enabled only when Pre-Processing Rules are not working reliably in your environment. If you rely on Pre-Processing Rules to update existing incidents, keep Skip updated incidents (prevent duplicates) disabled.

Additional Resources

For detailed information about collections, their structure, available fields, and recommended date ranges, refer to the official Collections Details documentation.

Reputation Commands (ip / domain / file)

This integration implements the standard Cortex XSOAR reputation commands:

  • ip
  • domain
  • file

Best practice: use a dedicated instance for reputation

We recommend using a dedicated integration instance for reputation commands, such as Group-IB Threat Intelligence (Partner Contribution).

Enabling reputation commands

Reputation commands are disabled by default to avoid unexpected auto-enrichment side effects.
To enable them, configure the integration instance parameter Enable reputation commands and select the command types you want to allow (ip, domain, file).

Source Reliability and override behavior

The integration supports two reliability modes for reputation commands:

  • Instance override mode (fixed reliability):
    • Controlled by the instance parameter Source Reliability.
    • When Ignore Source Reliability override is disabled (unchecked), the integration attaches the configured Source Reliability value to every reputation response, regardless of indicator-specific findings.
  • Integration-calculated reliability mode (dynamic reliability):
    • Enabled by the instance parameter Ignore Source Reliability override.
    • When Ignore Source Reliability override is enabled (checked), the integration ignores the instance Source Reliability value and calculates reliability per indicator based on the collections that returned matches (see rules below).

Score (DBotScore) calculation rules

Score and reliability are calculated independently. A finding may affect reliability without affecting score.

file score rules

  • BAD: at least one match in ioc/common
  • UNKNOWN (NONE): no matches

Note: For file reputation, the integration evaluates only the ioc/common collection for score.

domain score rules

The integration uses a 3-year recency window and the following date fields:

  • ioc/common.dateLastSeen
  • hi/open_threats.detected
  • attacks/deface.date

Rules (evaluated top-to-bottom):

  • BAD: ioc/common match with dateLastSeen within the last 3 years
  • SUSPICIOUS: hi/open_threats or attacks/deface match with a date within the last 3 years
  • SUSPICIOUS: ioc/common has records but dateLastSeen is missing or older than 3 years
  • UNKNOWN (NONE): no findings (no matches in ioc/common, hi/open_threats, attacks/deface)

ip score rules

The integration maps the numeric Group-IB riskScore (0..100) to DBotScore:

  • GOOD: 0..49
  • SUSPICIOUS: 50..84
  • BAD: 85..100
  • UNKNOWN (NONE): score is missing or out of range

Reliability calculation rules (only when Ignore Source Reliability override is enabled)

When the integration-calculated reliability mode is enabled, reliability is computed as follows:

file reliability rules

  • A - Completely reliable: at least one match in ioc/common
  • None: no matches

domain and ip reliability rules

Reliability is derived from which collections returned matches:

  • A - Completely reliable:
    • any match in apt/threat or apt/threat_actor (nation-state intelligence), or
    • any match in ioc/common
  • B - Usually reliable:
    • any match in attacks/deface, or
    • any match in hi/open_threats

Final selection logic (deterministic):

  • If there is at least one A - Completely reliable source → reliability is A - Completely reliable
  • Else if there is at least one B - Usually reliable source → reliability is B - Usually reliable
  • Else → reliability is None

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

Available Commands

The following commands are available in this integration:

Note: Commands now use the gibti- prefix. Legacy gibtia- commands remain available for backward compatibility and are marked as deprecated in the integration settings.

  • gibti-get-available-collections - Returns list of available collections
  • gibti-get-compromised-account-info - Performs Group-IB event lookup in compromised/account collection
  • gibti-get-compromised-card-group-info - Performs Group-IB event lookup in compromised/card collection
  • gibti-get-compromised-masked-card-info - Performs Group-IB event lookup in compromised/masked_card collection
  • gibti-get-compromised-breached-info - Performs Group-IB event lookup in compromised/breached collection
  • gibti-get-phishing-group-info - Performs Group-IB event lookup in attacks/phishing_group collection
  • gibti-get-phishing-kit-info - Performs Group-IB event lookup in attacks/phishing_kit collection
  • gibti-get-osi-git-leak-info - Performs Group-IB event lookup in osi/git_repository collection
  • gibti-get-osi-public-leak-info - Performs Group-IB event lookup in osi/public_leak collection
  • gibti-get-osi-vulnerability-info - Performs Group-IB event lookup in osi/vulnerability collection
  • gibti-get-malware-malware-info - Performs Group-IB event lookup in malware/malware collection
  • gibti-get-compromised-mule-info - Performs Group-IB event lookup in compromised/mule collection
  • gibti-get-compromised-spd-info - Performs Group-IB event lookup in compromised/spd (suspicious payment details) collection
  • gibti-get-attacks-ddos-info - Performs Group-IB event lookup in attacks/ddos collection
  • gibti-get-attacks-deface-info - Performs Group-IB event lookup in attacks/deface collection
  • gibti-get-threat-info - Performs Group-IB event lookup in hi/threat or apt/threat collection
  • gibti-get-threat-actor-info - Performs Group-IB event lookup in hi/threat_actor or apt/threat_actor collection
  • gibti-get-suspicious-ip-tor-node-info - Performs Group-IB event lookup in suspicious_ip/tor_node collection
  • gibti-get-suspicious-ip-open-proxy-info - Performs Group-IB event lookup in suspicious_ip/open_proxy collection
  • gibti-get-suspicious-ip-socks-proxy-info - Performs Group-IB event lookup in suspicious_ip/socks_proxy collection
  • gibti-get-suspicious-ip-vpn-info - Performs Group-IB event lookup in suspicious_ip/vpn collection
  • gibti-get-suspicious-ip-scanner-info - Performs Group-IB event lookup in suspicious_ip/scanner collection
  • gibti-get-malware-cnc-info - Performs Group-IB event lookup in malware/cnc collection
  • gibti-global-search - Performs global Group-IB search across all collections
  • gibtia-local-search - Performs Group-IB search in selected collection

gibti-get-compromised-account-info


Command performs Group-IB event lookup in compromised/account collection with provided ID.

Base Command

gibti-get-compromised-account-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 253b9a136f0d574149fc43691eaf7ae27aff141a.
Required

Context Output

Path Type Description
GIBTIA.CompromisedAccount.client.ipv4.asn String Victim IP address
GIBTIA.CompromisedAccount.client.ipv4.countryName String Country name
GIBTIA.CompromisedAccount.client.ipv4.ip String Victim IP address
GIBTIA.CompromisedAccount.client.ipv4.region String Region name
GIBTIA.CompromisedAccount.cnc.domain String Event CNC domain
GIBTIA.CompromisedAccount.cnc.url String CNC URL
GIBTIA.CompromisedAccount.cnc.ipv4.ip String CNC IP address
GIBTIA.CompromisedAccount.dateCompromised Date Date of compromise
GIBTIA.CompromisedAccount.dateDetected Date Date of detection
GIBTIA.CompromisedAccount.dropEmail.email String Email where compromised data were sent to
GIBTIA.CompromisedAccount.dropEmail.domain String Email domain
GIBTIA.CompromisedAccount.login String Compromised login
GIBTIA.CompromisedAccount.password String Compromised password
GIBTIA.CompromisedAccount.malware.name String Malware name
GIBTIA.CompromisedAccount.malware.id String Group-IB malware ID
GIBTIA.CompromisedAccount.person.name String Card owner name
GIBTIA.CompromisedAccount.person.email String Card owner e-mail
GIBTIA.CompromisedAccount.portalLink String Link to GIB incident
GIBTIA.CompromisedAccount.threatActor.name String Associated threat actor
GIBTIA.CompromisedAccount.threatActor.isAPT Boolean Is threat actor APT group
GIBTIA.CompromisedAccount.threatActor.id String Threat actor GIB ID
GIBTIA.CompromisedAccount.id String Group-IB incident ID
GIBTIA.CompromisedAccount.evaluation.severity String Event severity

Command Example

!gibti-get-compromised-account-info id=253b9a136f0d574149fc43691eaf7ae27aff141a

Human Readable Output

Feed from compromised/account with ID 253b9a136f0d574149fc43691eaf7ae27aff141a

client ipv4 ip cnc cnc cnc domain cnc ipv4 asn cnc ipv4 city cnc ipv4 countryCode cnc ipv4 countryName cnc ipv4 ip cnc ipv4 provider cnc ipv4 region cnc url companyId dateDetected domain evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl id login malware id malware name malware stixGuid oldId password portalLink silentInsert sourceType stixGuid
0.0.0.0 ««««http://some.com»»»» some.com AS1111 City RU Country 11.11.11.11 some.com City http://some.com -1 2020-02-22T01:21:03+00:00 some.com A2 80 100 red red 90 253b9a136f0d574149fc43691eaf7ae27aff141a some.com 411ac9df6c5515922a56e30013e8b8b366eeec80 PredatorStealer 2f7650f4-bc72-2068-d1a5-467b688975d8 396792583 @some@ https://group-ib.com/cd/accounts?searchValue=id:253b9a136f0d574149fc43691eaf7ae27aff141a 0 Botnet 8abb3aa9-e351-f837-d61a-856901c3dc9d

URL indicator

gibid severity value
253b9a136f0d574149fc43691eaf7ae27aff141a red http://some.com

Domain indicator

gibid severity value
253b9a136f0d574149fc43691eaf7ae27aff141a red some.com

IP indicator

asn geocountry geolocation gibid severity value
AS1111 Country City 253b9a136f0d574149fc43691eaf7ae27aff141a red 11.11.11.11

gibti-get-compromised-breached-info


Command performs Group-IB event lookup in compromised/breached collection with provided ID.

Base Command

gibti-get-compromised-breached-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 6fd344f340f4bdc08548cb36ded62bdf.
Required

Context Output

Path Type Description
GIBTIA.DataBreach.email String List of breached emails
GIBTIA.DataBreach.leakName String Name of the leak
GIBTIA.DataBreach.password String List of breached passwords
GIBTIA.DataBreach.uploadTime Date Date of breached data upload
GIBTIA.DataBreach.id String Group-IB incident ID
GIBTIA.DataBreach.evaluation.severity String Event severity

Command Example

!gibti-get-compromised-breached-info id=277c4112d348c91f6dabe9467f0d18ba

Human Readable Output

Feed from compromised/breached with ID 277c4112d348c91f6dabe9467f0d18ba

addInfo email evaluation id leakName password uploadTime
address:
some@gmail.com admiraltyCode: C3
credibility: 50
reliability: 50
severity: green
tlp: amber
ttl: null
277c4112d348c91f6dabe9467f0d18ba some.com AC91C480FDE9D7ACB8AC4B78310EB2TD,
1390DDDFA28AE085D23518A035703112
2021-06-12T03:02:00

gibti-get-compromised-mule-info


Command performs Group-IB event lookup in compromised/mule collection with provided ID.

Base Command

gibti-get-compromised-mule-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 50a3b4abbfca5dcbec9c8b3a110598f61ba93r33.
Required

Context Output

Path Type Description
GIBTIA.CompromisedMule.account String Account number (card/phone), which was used by threat actor to cash out
GIBTIA.CompromisedMule.cnc.ipv4.asn String CNC ASN
GIBTIA.CompromisedMule.cnc.ipv4.countryName String Country name
GIBTIA.CompromisedMule.cnc.ipv4.ip String Victim IP address
GIBTIA.CompromisedMule.cnc.ipv4.region String Region name
GIBTIA.CompromisedMule.cnc.url String CNC URL
GIBTIA.CompromisedMule.cnc.domain String CNC domain
GIBTIA.CompromisedMule.dateAdd Date Date of detection
GIBTIA.CompromisedMule.malware.name String Malware name
GIBTIA.CompromisedMule.portalLink String Link to GIB incident
GIBTIA.CompromisedMule.threatActor.name String Associated threat actor
GIBTIA.CompromisedMule.threatActor.id String Threat actor GIB ID
GIBTIA.CompromisedMule.threatActor.isAPT Boolean Is threat actor APT group
GIBTIA.CompromisedMule.id String Group-IB incident ID
GIBTIA.CompromisedMule.sourceType String Information source
GIBTIA.CompromisedMule.evaluation.severity String Event severity

Command Example

!gibti-get-compromised-mule-info id=50a3b4abbfca5dcbec9c8b3a110598f61ba90a99

Human Readable Output

Feed from compromised/mule with ID 50a3b4abbfca5dcbec9c8b3a110598f61ba90a99

account cnc cnc cnc domain cnc ipv4 ip cnc url dateAdd evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl hash id malware id malware name malware stixGuid oldId organization name portalLink sourceType stixGuid type
1111111111111111 ««««««««««««««««http://some.com»»»»»»»»»»»»»»»» some 11.11.11.11 http://some.com 2020-02-21T13:02:00+00:00 A2 80 100 red amber 30 some 50a3b4abbfca5dcbec9c8b3a110598f61ba90a99 5a2b741f8593f88178623848573abc899f9157d4 Anubis 7d837524-7b01-ddc9-a357-46e7136a9852 392993084 Some https://group-ib.com/cd/mules?searchValue=id:50a3b4abbfca5dcbec9c8b3a110598f61ba90a99 Botnet 2da6b164-9a12-6db5-4346-2a80a4e03255 Person

URL indicator

gibid severity value
50a3b4abbfca5dcbec9c8b3a110598f61ba90a99 red http://some.com

Domain indicator

gibid severity value
50a3b4abbfca5dcbec9c8b3a110598f61ba90a99 red some

IP indicator

gibid severity value
50a3b4abbfca5dcbec9c8b3a110598f61ba90a99 red 11.11.11.11

gibti-get-compromised-spd-info


Command performs Group-IB event lookup in compromised/spd (suspicious payment details) collection with provided ID. Returns payment-related observables (e.g. cryptocurrency wallets) linked to threat actors and leaks, including type, value, events, sources, malware, and evaluation (severity, TLP, TTL).

Base Command

gibti-get-compromised-spd-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 5120a3b4abbfca5dcbed3ac9c8b3a110598f61.
Required

Context Output

Path Type Description
GIBTIA.CompromisedSPD.id String Group-IB SPD incident ID.
GIBTIA.CompromisedSPD.type String Observable type (e.g. Cryptocurrency Wallet).
GIBTIA.CompromisedSPD.value.value String Main observable value (wallet address, etc.).
GIBTIA.CompromisedSPD.serviceType String Service type (e.g. BTCLike, XMRLike).
GIBTIA.CompromisedSPD.ownerName String Owner name if available.
GIBTIA.CompromisedSPD.illegalScore Number Illegal score.
GIBTIA.CompromisedSPD.portalLink String Link to GIB incident.
GIBTIA.CompromisedSPD.events Unknown Events table (compromisedAt, detectedAt, source, malware, threatActor).
GIBTIA.CompromisedSPD.sources Unknown Sources table (name, type).
GIBTIA.CompromisedSPD.malware Unknown Malware table (id, name, stixGuid).
GIBTIA.CompromisedSPD.threatActor Unknown Threat actor table (id, name, stixGuid).
GIBTIA.CompromisedSPD.evaluation.severity String Event severity.
GIBTIA.CompromisedSPD.evaluation.tlp String TLP.
GIBTIA.CompromisedSPD.evaluation.ttl Number TTL (days).

Command Example

!gibti-get-compromised-spd-info id=5120a3b4abbfca5dcbed3ac9c8b3a110598f61

Human Readable Output

Feed from compromised/spd with ID 5120a3b4abbfca5dcbed3ac9c8b3a110598f61

id type value serviceType illegalScore portalLink evaluation severity evaluation tlp evaluation ttl
5120a3b4abbfca5dcbed3ac9c8b3a110598f61 Cryptocurrency Wallet bc1qrc4zze8zr96pwt49fn6nq53rks625guzn7navy BTCLike 100 https://tap.group-ib.com/cd/suspicious-payment-details?id=5120a3b4abbfca5dcbed3ac9c8b3a110598f61 red amber 30

Events, sources, malware, and threat actor tables are included in the full feed object.

gibti-get-osi-git-leak-info


Command performs Group-IB event lookup in osi/git_leak collection with provided ID.

Base Command

gibti-get-osi-git-leak-info

Input

Argument Name Description Required
id GIB event id.
e.g.: f201c253ac71f7d78db39fa111a2af9d7ee7a3f7.
Required

Context Output

Path Type Description
GIBTIA.GitLeak.dateDetected Date Leak detection date
GIBTIA.GitLeak.matchesType String List of matches type
GIBTIA.GitLeak.name String GIT filename
GIBTIA.GitLeak.repository String GIT repository
GIBTIA.GitLeak.revisions.file String Leaked file link
GIBTIA.GitLeak.revisions.fileDiff String Leaked file diff
GIBTIA.GitLeak.revisions.info.authorName String Revision author
GIBTIA.GitLeak.revisions.info.authorEmail String Author name
GIBTIA.GitLeak.revisions.info.dateCreated Date Revision creation date
GIBTIA.GitLeak.source String Source(github/gitlab/etc.)
GIBTIA.GitLeak.evaluation.severity String Event severity

Command Example

!gibti-get-osi-git-leak-info id=ead0d8ae9f2347789941ebacde88ad2e3b1ef691

Human Readable Output

Feed from osi/git_leak with ID ead0d8ae9f2347789941ebacde88ad2e3b1ef691

companyId dateDetected dateUpdated evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl file fileId id matchesType matchesTypeCount card matchesTypeCount cisco matchesTypeCount commonKeywords matchesTypeCount domain matchesTypeCount dsn matchesTypeCount email matchesTypeCount google matchesTypeCount ip matchesTypeCount keyword matchesTypeCount login matchesTypeCount metasploit matchesTypeCount nmap matchesTypeCount pgp matchesTypeCount sha matchesTypeCount slackAPI matchesTypeCount ssh name repository source
40,
1872,
2060,
2248,
2522,
2692
2020-03-12T01:12:00+00:00 2020-02-11T01:12:00+00:00 A6 100 100 green amber 30 https://group-ib.com/api/v2/osi/git_leak/ead0d8ae9f2347789941ebacde88ad2e3b1ef691/file/bWFpbi0zOTFkYjVkNWYxN2FiNmNiYmJmN2MzNWQxZjRkMDc2Y2I0YzgzMGYwOTdiMmE5ZWRkZDJkZjdiMDY1MDcwOWE3 391db5d5f17ab6cbbbf7c35d1f4d076cb4c830f097b2a9eddd2df7b0650709a7 ead0d8ae9f2347789941ebacde88ad2e3b1ef691 commonKeywords,
keyword
0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 some some.com github

revisions table

bind companyId data file fileDiff fileDiffId fileId hash info parentFileId
{‘bindBy’: ‘cert’, ‘companyId’: [2692], ‘data’: ‘cert’, ‘type’: ‘keyword’} 2692 commonKeywords: {“password”: [“password”]} https://group-ib.com/api/v2/osi/git_leak/ead0d8ae9f2347789941ebacde88ad2e3b1ef691/file/cmV2aXNpb24tZmlsZS0zOTFkYjVkNWYxN2FiNmNiYmJmN2MzNWQxZjRkMDc2Y2I0YzgzMGYwOTdiMmE5ZWRkZDJkZjdiMDY1MDcwOWE3 https://group-ib.com/api/v2/osi/git_leak/ead0d8ae9f2347789941ebacde88ad2e3b1ef691/file/cmV2aXNpb24tZmlsZURpZmYtMzkxZGI1ZDVmMTdhYjZjYmJiZjdjMzVkMWY0ZDA3NmNiNGM4MzBmMDk3YjJhOWVkZGQyZGY3YjA2NTA3MDlhNw== a2187ee179076a22e550e8f7fbc51840e87aba260431ab9cb2d4e0192ad4134c 391db5d5f17ab6cbbbf7c35d1f4d076cb4c830f097b2a9eddd2df7b0650709a7 Some authorEmail: some@gmail.com
authorName: some
dateCreated: 2020-01-03T11:17:52+00:00
timestamp: 1617794272
ead0d8ae9f2347789941ebacde88ad2e3b1ef691

gibti-get-osi-public-leak-info


Command performs Group-IB event lookup in osi/public_leak collection with provided ID.

Base Command

gibti-get-osi-public-leak-info

Input

Argument Name Description Required
id GIB event id.
e.g.: a9a5b5cb9b971a2a037e3a0a30654185ea148095.
Required

Context Output

Path Type Description
GIBTIA.PublicLeak.created Date Leak event detection date
GIBTIA.PublicLeak.data String Leaked data
GIBTIA.PublicLeak.hash String Leak data hash
GIBTIA.PublicLeak.linkList.author String Leak entry author
GIBTIA.PublicLeak.linkList.dateDetected Date Leak detection date
GIBTIA.PublicLeak.linkList.datePublished Date Leak publish date
GIBTIA.PublicLeak.linkList.hash String Leak hash
GIBTIA.PublicLeak.linkList.link String Leak link
GIBTIA.PublicLeak.linkList.source String Leak source
GIBTIA.PublicLeak.matches String Matches
GIBTIA.PublicLeak.portalLink String Group-IB portal link
GIBTIA.PublicLeak.evaluation.severity String Event severity

Command Example

!gibti-get-osi-public-leak-info id=a09f2354e52d5fa0a8697c8df0b4ed99cc956273

Human Readable Output

Feed from osi/public_leak with ID a11f2354e52d5fa0a8697c8df0b4ed99cc956211

created data evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl hash id language portalLink size updated useful
2020-02-02T13:52:01+03:00 Big chunk of data C3 50 50 green amber 30 a11f2354e52d5fa0a8697c8df0b4ed99cc956211 a11f2354e52d5fa0a8697c8df0b4ed99cc956211 java https://group-ib.com/osi/public_leak?searchValue=id:a09f2354e52d5fa0a8697c8df0b4ed99cc956273 709 B 2021-04-01T14:57:01+03:00 1

linkList table

dateDetected datePublished hash itemSource link size source status
2021-04-01T14:57:01+03:00 2021-04-01T14:50:45+03:00 5d9657dbdf59487a6031820add2cacbe54e86814 api https://some.com 709 some.com 1

gibti-get-osi-vulnerability-info


Command performs Group-IB event lookup in osi/vulnerability collection with provided ID.

Base Command

gibti-get-osi-vulnerability-info

Input

Argument Name Description Required
id GIB event id.

e.g.: CVE-2021-27152.
Required

Context Output

Path Type Description
GIBTIA.OSIVulnerability.affectedSoftware.name String Affected software name
GIBTIA.OSIVulnerability.affectedSoftware.operator String Affected software version operator( ex. le=less or equal)
GIBTIA.OSIVulnerability.affectedSoftware.version String Affected software version
GIBTIA.OSIVulnerability.bulletinFamily String Bulletin family
GIBTIA.OSIVulnerability.cvss.score String CVSS score
GIBTIA.OSIVulnerability.cvss.vector String CVSS vector
GIBTIA.OSIVulnerability.dateLastSeen Date Date last seen
GIBTIA.OSIVulnerability.datePublished Date Date published
GIBTIA.OSIVulnerability.description String Vulnerability description
GIBTIA.OSIVulnerability.id String Vulnerability ID
GIBTIA.OSIVulnerability.reporter String Vulnerability reporter
GIBTIA.OSIVulnerability.title String Vulnerability title
GIBTIA.OSIVulnerability.evaluation.severity String Event severity

Command Example

!gibti-get-osi-vulnerability-info id=CVE-2021-27152

Human Readable Output

Feed from osi/vulnerability with ID CVE-2021-27152

bulletinFamily cvss score cvss vector dateLastSeen dateModified datePublished description displayOptions isFavourite displayOptions isHidden evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl exploitCount extCvss base extCvss environmental extCvss exploitability extCvss impact extCvss mImpact extCvss overall extCvss temporal extCvss vector extDescription href id lastseen modified portalLink provider published references reporter title type
NVD 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P 2021-02-11T14:35:24+03:00 2021-02-11T00:45:00+03:00 2021-02-10T19:15:00+03:00 Description false false A1 100 100 red green 30 0 9.8 0.0 3.9 5.9 0.0 9.8 0.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Big description ««««https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-27152»»»» CVE-2021-27152 2021-02-11T14:35:24+03:00 2021-02-11T00:45:00+03:00 https://group-ib.com/osi/vulnerabilities?searchValue=id:CVE-2021-27152 some.com 2021-02-10T19:15:00+03:00 https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html#httpd-hardcoded-credentials,
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-27152
some.com CVE-2021-27152 cve

softwareMixed table

os osVendor osVersion vendor
some_firmware some some some

gibti-get-attacks-ddos-info


Command performs Group-IB event lookup in attacks/ddos collection with provided ID.

Base Command

gibti-get-attacks-ddos-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 26a05baa4025edff367b058b13c6b43e820538a5.
Required

Context Output

Path Type Description
GIBTIA.AttacksDDoS.cnc.url String CNC URL
GIBTIA.AttacksDDoS.cnc.domain String CNC domain
GIBTIA.AttacksDDoS.cnc.ipv4.asn String CNC ASN
GIBTIA.AttacksDDoS.cnc.ipv4.countryName String CNC IP country name
GIBTIA.AttacksDDoS.cnc.ipv4.ip String CNC IP address
GIBTIA.AttacksDDoS.cnc.ipv4.region String CNC region name
GIBTIA.AttacksDDoS.target.ipv4.asn String DDoS target ASN
GIBTIA.AttacksDDoS.target.ipv4.countryName String DDoS target country name
GIBTIA.AttacksDDoS.target.ipv4.ip String DDoS target IP address
GIBTIA.AttacksDDoS.target.ipv4.region String DDoS target region name
GIBTIA.AttacksDDoS.target.category String DDoS target category
GIBTIA.AttacksDDoS.target.domain String DDoS target domain
GIBTIA.AttacksDDoS.threatActor.id String Associated threat actor ID
GIBTIA.AttacksDDoS.threatActor.name String Associated threat actor
GIBTIA.AttacksDdos.threatActor.isAPT Boolean Is threat actor APT
GIBTIA.AttacksDDoS.id String GIB incident ID
GIBTIA.AttacksDDoS.evaluation.severity String Event severity

Command Example

!gibti-get-attacks-ddos-info id=26a05baa4025edff367b058b13c6b43e820538a5

Human Readable Output

Feed from attacks/ddos with ID 26a05baa4025edff367b058b13c6b43e820538a5

cnc cnc cnc domain cnc ipv4 asn cnc ipv4 city cnc ipv4 countryCode cnc ipv4 countryName cnc ipv4 ip cnc ipv4 provider cnc ipv4 region companyId dateBegin dateEnd dateReg evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl id oldId portalLink protocol source stixGuid target domainsCount target ipv4 asn target ipv4 city target ipv4 countryCode target ipv4 countryName target ipv4 ip target ipv4 provider target ipv4 region target port type
some.com some.com AS11111 Some US United States 11.11.11.11 Some Some -1 2021-01-16T02:58:53+00:00 2021-01-16T02:58:55+00:00 2021-01-16 A2 90 90 red green 30 26a05baa4025edff367b058b13c6b43e820538a5 394657345 https://group-ib.com/attacks/ddos?searchValue=id:26a05baa4025edff367b058b13c6b43e820538a5 udp honeypot_logs:1 ea05c117-2cca-b3cd-f033-a8e16e5db3c2 0 AS11111 Some US United States 11.11.11.11 Some Some 55843 DNS Reflection

Domain indicator

gibid severity value
26a05baa4025edff367b058b13c6b43e820538a5 red some.com

IP indicator

asn geocountry geolocation gibid severity value
AS11111 United States Some 26a05baa4025edff367b058b13c6b43e820538a5 red 11.11.11.11

gibti-get-attacks-deface-info


Command performs Group-IB event lookup in attacks/deface collection with provided ID.

Base Command

gibti-get-attacks-deface-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 6009637a1135cd001ef46e21.
Required

Context Output

Path Type Description
GIBTIA.AttacksDeface.date Date Date of deface
GIBTIA.AttacksDeface.id String GIB incident ID
GIBTIA.AttacksDeface.targetIp.asn String Victim ASN
GIBTIA.AttacksDeface.targetIp.countryName String Victim country name
GIBTIA.AttacksDeface.targetIp.region String Victim IP region name
GIBTIA.AttacksDeface.threatActor.id String Associated threat actor ID
GIBTIA.AttacksDeface.threatActor.name String Associated threat actor
GIBTIA.AttacksDeface.threatActor.isAPT Boolean Is threat actor APT
GIBTIA.AttacksDeface.url String URL of compromised resource
GIBTIA.AttacksDeface.evaluation.severity String Event severity

Command Example

!gibti-get-attacks-deface-info id=6009637a1135cd001ef46e21

Human Readable Output

Feed from attacks/deface with ID 6009637a1135cd001ef46e21

date evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl id mirrorLink portalLink providerDomain siteUrl source targetDomain targetIp countryName targetIp ip threatActor id threatActor isAPT threatActor name tsCreate url
2021-01-21T02:22:18+00:00 B2 80 80 orange amber 30 6009637a1135cd001ef46e21 https://some.com/id:-6009637a1135cd001ef46e21: https://group-ib.com/attacks/deface?searchValue=id:6009637a1135cd001ef46e21 some.com ««««««««««««««««http://some.com»»»»»»»»»»»»»»»» some.com some.com Indonesia 11.11.11.11 d7ff75c35f93dce6f5410bba9a6c206bdff66555 false FRK48 2021-01-21T11:19:52+00:00 http://some.com

URL indicator

gibid severity value
6009637a1135cd001ef46e21 orange http://some.com

Domain indicator

gibid severity value
6009637a1135cd001ef46e21 orange some.com

IP indicator

geocountry gibid severity value
Indonesia 6009637a1135cd001ef46e21 orange 11.11.11.11

gibti-get-phishing-kit-info


Command performs Group-IB event lookup in attacks/phishing_kit collection with provided ID.

Base Command

gibti-get-phishing-kit-info

Legacy alias gibtia-get-phishing-kit-info remains available for backward compatibility.

Input

Argument Name Description Required
id GIB event id. Required

Command Example

!gibti-get-phishing-kit-info id=<phishing-kit-id>

gibti-get-threat-info


Command performs Group-IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.

Base Command

gibti-get-threat-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 1b09d389d016121afbffe481a14b30ea995876e4.
Required
isAPT Is threat APT. Possible values are: true, false. Default is false. Optional

Context Output

Path Type Description
GIBTIA.Threat.contacts.account String Threat accounts found in this threat action.
GIBTIA.Threat.contacts.flag String Is account fake or not
GIBTIA.Threat.contacts.service String Account service
GIBTIA.Threat.contacts.type String Type of account(social_network/email/wallet etc.)
GIBTIA.Threat.countries String Affected countries
GIBTIA.Threat.createdAt Date Threat report creation date
GIBTIA.Threat.cveList.name String List of abused CVE
GIBTIA.Threat.dateFirstSeen Date Attack first seen date
GIBTIA.Threat.dateLastSeen Date Attack last seen date
GIBTIA.Threat.datePublished Date Date published
GIBTIA.Threat.description String Threat description
GIBTIA.Threat.forumsAccounts.url String Related forum URL
GIBTIA.Threat.forumsAccounts.nickname String Related forums account
GIBTIA.Threat.forumsAccounts.registeredAt Date Related forums account registration date
GIBTIA.Threat.forumsAccounts.messageCount Number Related forums messages count
GIBTIA.Threat.id String GIB internal threat ID
GIBTIA.Threat.indicators String Can be either network or file indicators
GIBTIA.Threat.langs String Languages actors related
GIBTIA.Threat.malwareList.name String Related Malware Name
GIBTIA.Threat.malwareList.id String Related malware GIB internal ID
GIBTIA.Threat.mitreMatrix.attackPatternId String MITRE attack pattern ID
GIBTIA.Threat.mitreMatrix.attackTactic String MITRE attack tactic name
GIBTIA.Threat.mitreMatrix.attackType String MITRE attack type
GIBTIA.Threat.mitreMatrix.id String MITRE attack id
GIBTIA.Threat.regions String Regions affected by attack
GIBTIA.Threat.reportNumber String GIB report number
GIBTIA.Threat.sectors String Affected sectors
GIBTIA.Threat.shortDescription String Short description
GIBTIA.Threat.title String Threat title
GIBTIA.Threat.targetedCompany String Targeted company name
GIBTIA.Threat.ThreatActor.name String Threat actor name
GIBTIA.Threat.ThreatActor.id String Threat actor ID
GIBTIA.Threat.ThreatActor.isAPT Boolean Is threat actor APT group
GIBTIA.Threat.sources String Sources links
GIBTIA.Threat.evaluation.severity String Event severity

Command Example

!gibti-get-threat-info id=1b09d389d016121afbffe481a14b30ea995876e4 isAPT=true

Human Readable Output

Feed from threat with ID 1b09d389d016121afbffe481a14b30ea995876e4

createdAt dateFirstSeen dateLastSeen datePublished deleted description evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp id isPublished isTailored langs oldId reportNumber sectors threatActor country threatActor id threatActor isAPT threatActor name title type updatedAt
2021-01-15T16:53:20+03:00 2021-01-15 2021-01-15 2021-01-15 false Big description B1 100 80 orange amber 1b09d389d016121afbffe481a14b30ea995876e4 true false en,
com
4c01c2d4-5ebb-44d8-9e91-be89231b0eb3 CP-2501-1653 financial-services,
finance
KP 5e9f20fdcf5876b5772b3d09b432f4080711ac5f true Lazarus Lazarus launches new attack with cryptocurrency trading platforms threat 2021-04-02T14:08:03+03:00

files table

hash mime name size
fa5b6b2f074ba6eb58f8b093f0e92cb8ff44b655dc8e9ce93f850e71474e4e11 image/png fa5b6b2f074ba6eb58f8b093f0e92cb8ff44b655dc8e9ce93f850e71474e4e11 284731
a6851a6b91759d00afce8e65c0e5087429812b8c49d39631793d8b6bdeb08711 image/png a6851a6b91759d00afce8e65c0e5087429812b8c49d39631793d8b6bdeb08711 129240
644f5b8e38f55b82f811240af7c4abdaf8c8bc18b359f8f169074ba881d93b1d image/png 644f5b8e38f55b82f811240af7c4abdaf8c8bc18b359f8f169074ba881d93b1d 556552
623102f6cf9d2e6c978898117b7b5b85035b3d5e67c4ee266879868c9eb24dd2 image/png 623102f6cf9d2e6c978898117b7b5b85035b3d5e67c4ee266879868c9eb24dd2 209254

mitreMatrix table

attackPatternId attackTactic attackType id params
attack-pattern–45242287-2964-4a3e-9373-159fad4d8195 establish-&-maintain-infrastructure pre_attack_tactics PRE-T1105 data:

indicatorRelationships table

sourceId targetId
9f3a2a244570a38e772a35d7c9171eed92bec6f7 12cad1ca535a92a2ed306c0edf3025e7d9776693

indicators table

deleted id langs params seqUpdate type
false 9f3a2a244570a38e772a35d7c9171eed12bec6f7 en hashes: {“md4”: “”, “md5”: “8397ea747d2ab50da4f876a36d631272”, “md6”: “”, “ripemd160”: “”, “sha1”: “48a6d5141e25b6c63ad8da20b954b56afe512031”, “sha224”: “”, “sha256”: “89b5e248c222ebf2cb3b525d3650259e01cf7d8fff5e1aa15ccd7512b1e63957”, “sha384”: “”, “sha512”: “”, “whirlpool”: “”}
name: some.com
size: null
16107188499162 file
false 8b96c56cbc980c1e3362060ffa953e65281fb1df en domain: some.com
ipv4:
ipv6:
ssl:
url: https://some.com
16107188498393 network
false 42a9929807fd954918f9bb603135754be7a6e11c en hashes: {“md4”: “”, “md5”: “5d43baf1c9e9e3a939e5defd8f3fbd1d”, “md6”: “”, “ripemd120”: “”, “sha1”: “d5ff73c043f3bb75dd749636307500b60a336150”, “sha224”: “”, “sha256”: “867c8b49d29ae1f6e4a7cd31b6fe7e278753a1ba03d4be338ed11fd1efc3dd12”, “sha384”: “”, “sha512”: “”, “whirlpool”: “”}
name: 5d43baf1c9e9e3a939e5defd8f8fbd1d
size: null
16107188498634 file
false 12cad1ca535a92a2ed306c0edf3025e7d9776612 en domain: some.com
ipv4:
ipv6:
ssl:
url: https://some.com
16107188498908 network

gibti-get-threat-actor-info


Command performs Group-IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.

Base Command

gibti-get-threat-actor-info

Input

Argument Name Description Required
id GIB internal threatActor ID.
e.g.: 0d4496592ac3a0f5511cd62ef29887f48d9cb545.
Required
isAPT Is threat actor APT group. Possible values are: true, false. Default is false. Optional

Context Output

Path Type Description
GIBTIA.ThreatActor.aliases String Threat actor aliases
GIBTIA.ThreatActor.country String Threat actor country
GIBTIA.ThreatActor.createdAt Date Threat actor record creation time
GIBTIA.ThreatActor.description String Threat actor description
GIBTIA.ThreatActor.goals String Threat actor goals sectors(financial, diplomatic, etc.)
GIBTIA.ThreatActor.id String Threat actor id
GIBTIA.ThreatActor.isAPT Boolean Threat actor is APT
GIBTIA.ThreatActor.labels String GIB internal threat actor labels(hacker, nation-state, etc.)
GIBTIA.ThreatActor.langs String Threat actor communication language
GIBTIA.ThreatActor.name String Threat actor name
GIBTIA.ThreatActor.roles String Threat actor roles
GIBTIA.ThreatActor.stat.countries String Threat actor countries activity found in
GIBTIA.ThreatActor.stat.dateFirstSeen Date Date first seen
GIBTIA.ThreatActor.stat.dateLastSeen Date Date last seen
GIBTIA.ThreatActor.stat.regions String Threat actor activity regions
GIBTIA.ThreatActor.stat.reports.datePublished Date Related threat report publishing date
GIBTIA.ThreatActor.stat.reports.id String Related threat report id
GIBTIA.ThreatActor.stat.reports.name.en String Related threat report language
GIBTIA.ThreatActor.stat.sectors String Sectors attacked by threat actor

Command Example

!gibti-get-threat-actor-info id=0d4496592ac3a0f5511cd62ef29887f48d9cb545 isAPT=true

Human Readable Output

Feed from threat_actor with ID 0d4496592ac3a0f5511cd62ef29887f48d9cb545

aliases country createdAt deleted description goals id isAPT isPublished labels langs name roles spokenOnLangs stat countries stat dateFirstSeen stat dateLastSeen stat regions stat sectors stixGuid updatedAt
SectorC08 RU 2018-09-26T16:59:50+03:00 false Big description Information 0d4496592ac3a0f5511cd62ef29887f48d9cb545 true true spy en Gamaredon agent com US 2013-06-01 2021-03-19 asia non-profit 63d0e4d4-9f55-4fa2-87af-b6c91ded80e0 2021-04-08T22:09:07+03:00

stat reports table

datePublished id name
2021-02-04 59dec5947c5adac898445e3958b1d05e1c260459 en: Template injection attacks from the Gamaredon group continued: protocol topics

gibti-get-suspicious-ip-tor-node-info


Command performs Group-IB event lookup in suspicious_ip/tor_node collection with provided ID.

Base Command

gibti-get-suspicious-ip-tor-node-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 109.70.100.46.
Required

Context Output

Path Type Description
GIBTIA.SuspiciousIPTorNode.ipv4.asn String Tor node ASN
GIBTIA.SuspiciousIPTorNode.ipv4.countryName String Tor node IP country name
GIBTIA.SuspiciousIPTorNode.ipv4.ip String Tor node IP address
GIBTIA.SuspiciousIPTorNode.ipv4.region String Tor node IP region name
GIBTIA.SuspiciousIPTorNode.id String GIB id
GIBTIA.SuspiciousIPTorNode.evaluation.severity String Event severity

Command Example

!gibti-get-suspicious-ip-tor-node-info id=109.70.100.46

Human Readable Output

Feed from suspicious_ip/tor_node with ID 11.11.11.11

dateFirstSeen dateLastSeen evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl id ipv4 ip portalLink source
2020-09-03T14:15:25+00:00 2021-04-25T03:15:29+00:00 A1 90 90 green green 30 11.11.11.11 11.11.11.11 https://group-ib.com/suspicious/tor?searchValue=id:11.11.11.11 some.com

IP indicator

gibid severity value
11.11.11.11 green 11.11.11.11

gibti-get-suspicious-ip-open-proxy-info


Command performs Group-IB event lookup in suspicious_ip/open_proxy collection with provided ID.

Base Command

gibti-get-suspicious-ip-open-proxy-info

Input

Argument Name Description Required
id GIB event id.
e.g.: cc6a2856da2806b03839f81aa214f22dbcfd7369.
Required

Context Output

Path Type Description
GIBTIA.SuspiciousIPOpenProxy.ipv4.asn String Proxy ASN
GIBTIA.SuspiciousIPOpenProxy.ipv4.countryName String Proxy IP country name
GIBTIA.SuspiciousIPOpenProxy.ipv4.ip String Proxy IP address
GIBTIA.SuspiciousIPOpenProxy.ipv4.region String Proxy IP region name
GIBTIA.SuspiciousIPOpenProxy.ipv4.port Number Proxy port
GIBTIA.SuspiciousIPOpenProxy.ipv4.source String Information source
GIBTIA.SuspiciousIPOpenProxy.ipv4.anonymous String Proxy anonymous level
GIBTIA.SuspiciousIPOpenProxy.id String GIB event ID
GIBTIA.SuspiciousIPOpenProxy.evaluation.severity String Event severity

Command Example

!gibti-get-suspicious-ip-open-proxy-info id=cc6a2856da2806b03839f81aa214f22dbcfd7369

Human Readable Output

Feed from suspicious_ip/open_proxy with ID cc6a2856da2806b03839f81aa214f22dbcfd7369

anonymous dateDetected dateFirstSeen evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl id ipv4 countryCode ipv4 countryName ipv4 ip ipv4 provider oldId port portalLink source stixGuid type
11.11.11.11 2021-01-21T11:01:02+00:00 2020-03-19T23:01:01+00:00 C3 50 50 green white 15 cc6a2856da2806b03839f81aa214f22dbcfd7369 Country Code Country 11.11.11.11 Some 241549215 80 https://group-ib.com/suspicious/proxies?searchValue=id:cc6a2856da2806b03839f81aa214f22dbcfd7369 some.com c30604ac-94d5-b514-f1d1-7230ec13c739 http

IP indicator

geocountry gibid gibproxyanonymous gibproxyport severity source value
Country cc6a2856da2806b03839f81aa214f22dbcfd7369 11.11.11.11 80 green some.com 11.11.11.11

gibti-get-suspicious-ip-socks-proxy-info


Command performs Group-IB event lookup in suspicious_ip/socks_proxy collection with provided ID.

Base Command

gibti-get-suspicious-ip-socks-proxy-info

Input

Argument Name Description Required
id GIB event id.
e.g.: 02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e.
Required

Context Output

Path Type Description
GIBTIA.SuspiciousIPSocksProxy.ipv4.asn String Proxy IP ASN
GIBTIA.SuspiciousIPSocksProxy.ipv4.countryName String Proxy IP country name
GIBTIA.SuspiciousIPSocksProxy.ipv4.ip String Proxy IP address
GIBTIA.SuspiciousIPSocksProxy.ipv4.region String Proxy IP region name
GIBTIA.SuspiciousIPSocksProxy.id String GIB ID
GIBTIA.SuspiciousIPSocksProxy.evaluation.severity String Event severity

Command Example

!gibti-get-suspicious-ip-socks-proxy-info id=02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e

Human Readable Output

Feed from suspicious_ip/socks_proxy with ID 02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e

dateDetected dateFirstSeen dateLastSeen evaluation admiraltyCode evaluation credibility evaluation reliability evaluation severity evaluation tlp evaluation ttl id ipv4 asn ipv4 countryCode ipv4 countryName ipv4 ip ipv4 provider oldId portalLink source stixGuid
2021-01-19T07:41:11+00:00 2021-01-19T07:41:11+00:00 2021-02-23T20:58:51+00:00 A1 100 90 green amber 2 02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e AS11111 Country Code Country 11.11.11.11 Some 395880626 https://group-ib.com/suspicious/socks?searchValue=id:02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e awmproxy.com 78cd5f78-e542-bf2c-fc40-e2a41b36dd97

IP indicator

asn geocountry gibid severity value
AS11111 Country 02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e green 11.11.11.11

gibti-get-malware-cnc-info


Command performs Group-IB event lookup in malware/cnc collection by provided ID.

Base Command

gibti-get-malware-cnc-info

Input

Argument Name Description Required
id GIB event id.
e.g.: aeed277396e27e375d030a91533aa232444d0089.
Required

Context Output

Path Type Description
GIBTIA.MalwareCNC.dateDetected Date Date CNC detected
GIBTIA.MalwareCNC.dateLastSeen Date Date CNC last seen
GIBTIA.MalwareCNC.url String CNC URL
GIBTIA.MalwareCNC.domain String CNC domain
GIBTIA.MalwareCNC.ipv4.asn String CNC ASN
GIBTIA.MalwareCNC.ipv4.countryName String CNC IP country name
GIBTIA.MalwareCNC.ipv4.ip String CNC IP address
GIBTIA.MalwareCNC.ipv4.region String CNC region name
GIBTIA.MalwareCNC.malwareList.name String Associated malware
GIBTIA.MalwareCNC.threatActor.id String Associated threat actor ID
GIBTIA.MalwareCNC.threatActor.name String Associated threat actor
GIBTIA.MalwareCNC.threatActor.isAPT Boolean Is APT or not
GIBTIA.MalwareCNC.id String GIB event ID

Command Example

!gibti-get-malware-cnc-info id=aeed277396e27e375d030a91533aa232444d0089

Human Readable Output

Feed from malware/cnc with ID aeed277396e27e375d030a91533aa232444d0089

cnc dateDetected dateLastSeen domain id oldId stixGuid url
««««««««««««««««https://some.com»»»»»»»»»»»»»»»» 2021-04-25T13:37:23+00:00 2021-04-25T13:37:23+00:00 some.com aeed277396e27e375d030a91533aa232444d0089 211146923 417b2644-1105-d65b-4b67-a78e82f59b65 https://some.com

ipv4 table

asn countryCode countryName ip provider
AS1111 US United States 11.11.11.11 Some

malwareList table

id name stixGuid
e99c294ffe7b79655d6ef1f32add638d8a2d4b24 JS Sniffer - Poter 1ac5a303-ef6f-2d6a-ad20-a39196815a1a

URL indicator

gibid value
aeed277396e27e375d030a91533aa232444d0089 https://some.com

Domain indicator

gibid value
aeed277396e27e375d030a91533aa232444d0089 some.com

IP indicator

asn geocountry gibid value
AS1111 United States aeed277396e27e375d030a91533aa232444d0089 11.11.11.11

gibti-get-available-collections


Returns list of available collections.

Base Command

gibti-get-available-collections

Input

There are no input arguments for this command.

Context Output

Path Type Description
GIBTIA.OtherInfo.collections String List of availiable collections

Command Example

!gibti-get-available-collections

Human Readable Output

Available collections

collections
compromised/account,
compromised/card,
bp/phishing,
bp/phishing_kit,
osi/git_leak,
osi/public_leak,
malware/targeted_malware,
compromised/mule,
compromised/imei,
attacks/ddos,
attacks/deface,
attacks/phishing,
attacks/phishing_kit,
apt/threat,
hi/threat,
suspicious_ip/tor_node,
suspicious_ip/open_proxy,
suspicious_ip/socks_proxy,
malware/cnc,
osi/vulnerability,
hi/threat_actor,
apt/threat_actor

gibti-global-search


Command performs global Group-IB search

Base Command

gibti-global-search

Input

Argument Name Description Required
query Query you want to search.
e.g.: 8.8.8.8.
Required

Context Output

Path Type Description
apiPath String Name of collection in which found matches
count Number Count of feeds matching this query
GIBLink String Link to GIB TI&A interface

Command Example

!gibti-global-search query=100.100.100.100

Human Readable Output

Search results

apiPath count GIBLink
compromised/account 14  
attacks/phishing 1 https://group-ib.com/attacks/phishing?searchValue=100.100.100.100&q=100.100.100.100
bp/phishing 1  
osi/git_leak 5 https://group-ib.com/osi/git_leaks?searchValue=100.100.100.100&q=100.100.100.100
osi/public_leak 23 https://group-ib.com/osi/public_leak?searchValue=100.100.100.100&q=100.100.100.100

gibtia-local-search


Command performs Group-IB search in selected collection.

Base Command

gibtia-local-search

Input

Argument Name Description Required
collection_name Collection you want to search. Possible values are same as collection names in Data Collections Overview . Required
query Query you want to search.
e.g.: 8.8.8.8.
Required

Context Output

Path Type Description
GIBTI.search.local.id String Id of a feed that matches a query
GIBTI.search.local.additional_info String Additional info about feed
GIBTI.search.local.seqUpdate Number seqUpdate value of the page/portion that returned the feed
GIBTI.search.local.raw_feed String One-line JSON string of the full feed for War Room rendering (only when include_raw_feed=true)

Command Example

!gibtia-local-search collection_name=attacks/phishing query=100.100.100.100

Human Readable Output

Search results

id additional_info
8bd7e5cef2290b0c3f04bf283586406dceffe25d phishingDomain_domain: some.com

Configuration parameters

  • url — GIB TI URL (required)
  • credentials — Username (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • integration_reliability — Source Reliability (required)
  • disable_integration_reliability_override — Ignore Source Reliability override
  • enabled_reputation_commands — Enable reputation commands
  • isFetch — Fetch incidents
  • incident_collections — Collections to fetch
  • first_fetch — Incidents first fetch
  • exclude_combolist — Exclude All with Combolist type
  • combolist — Include combolist type in data
  • unique — Include unique type in data
  • enable_probable_corporate_access — Enable filter "Probable Corporate Access"
  • max_fetch — Number of requests per collection
  • skip_updated_incidents — Skip updated incidents (prevent duplicates)
  • dedup_lookback_days — Deduplication lookback (days)
  • limit — Limit (items per request)
  • incidentType — Incident type
  • incidentFetchInterval — Incidents Fetch Interval
  • hunting_rules — Hunting Rules

Commands (51)

  • domain

    Runs reputation on domains.

  • file

    Runs reputation on files.

  • gibti-get-attacks-ddos-info

    Command performs Group IB event lookup in attacks/ddos collection with provided ID.

  • gibti-get-attacks-deface-info

    Command performs Group IB event lookup in attacks/deface collection with provided ID.

  • gibti-get-available-collections

    Returns list of available collections.

  • gibti-get-compromised-account-info

    Command performs Group IB event lookup in compromised/account collection with provided ID.

  • gibti-get-compromised-breached-info

    Command performs Group IB event lookup in compromised/breached collection with provided ID.

  • gibti-get-compromised-card-group-info

    Command performs Group IB event lookup in compromised/bank_card_group collection by provided ID.

  • gibti-get-compromised-masked-card-info

    Command performs Group IB event lookup in compromised/masked_card collection by provided ID.

  • gibti-get-compromised-mule-info

    Command performs Group IB event lookup in compromised/mule collection with provided ID.

  • gibti-get-compromised-spd-info

    Command performs Group IB event lookup in compromised/spd (suspicious payment details) collection with provided ID.

  • gibti-get-malware-cnc-info

    Command performs Group IB event lookup in malware/cnc collection by provided ID.

  • gibti-get-malware-malware-info

    Command performs Group IB event lookup in malware/malware collection by provided ID.

  • gibti-get-osi-git-leak-info

    Command performs Group IB event lookup in osi/git_leak collection with provided ID.

  • gibti-get-osi-public-leak-info

    Command performs Group IB event lookup in osi/public_leak collection with provided ID.

  • gibti-get-osi-vulnerability-info

    Command performs Group IB event lookup in osi/vulnerability collection with provided ID.

  • gibti-get-phishing-group-info

    Command performs Group IB event lookup in attacks/phishing_group collection by provided ID.

  • gibti-get-suspicious-ip-open-proxy-info

    Command performs Group IB event lookup in suspicious_ip/open_proxy collection with provided ID.

  • gibti-get-suspicious-ip-scanner-info

    Command performs Group IB event lookup in suspicious_ip/scanner collection by provided ID.

  • gibti-get-suspicious-ip-socks-proxy-info

    Command performs Group IB event lookup in suspicious_ip/socks_proxy collection with provided ID.

  • gibti-get-suspicious-ip-tor-node-info

    Command performs Group IB event lookup in suspicious_ip/tor_node collection with provided ID.

  • gibti-get-suspicious-ip-vpn-info

    Command performs Group IB event lookup in suspicious_ip/vpn collection by provided ID.

  • gibti-get-threat-actor-info

    Command performs Group IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.

  • gibti-get-threat-info

    Command performs Group IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.

  • gibti-global-search

    Command performs global Group IB search.

  • gibti-ip-scoring

    Returns Group-IB scoring for IPs (numeric and DBotScore).

  • gibti-local-search

    Command performs Group IB search in selected collection.

  • gibtia-get-attacks-ddos-info

    Command performs Group IB event lookup in attacks/ddos collection with provided ID.

  • gibtia-get-attacks-deface-info

    Command performs Group IB event lookup in attacks/deface collection with provided ID.

  • gibtia-get-available-collections

    Returns list of available collections.

  • gibtia-get-compromised-account-info

    Command performs Group IB event lookup in compromised/account collection with provided ID.

  • gibtia-get-compromised-breached-info

    Command performs Group IB event lookup in compromised/breached collection with provided ID.

  • gibtia-get-compromised-card-group-info

    Command performs Group IB event lookup in compromised/bank_card_group collection by provided ID.

  • gibtia-get-compromised-mule-info

    Command performs Group IB event lookup in compromised/mule collection with provided ID.

  • gibtia-get-compromised-spd-info

    Command performs Group IB event lookup in compromised/spd (suspicious payment details) collection with provided ID.

  • gibtia-get-malware-cnc-info

    Command performs Group IB event lookup in malware/cnc collection by provided ID.

  • gibtia-get-malware-malware-info

    Command performs Group IB event lookup in malware/malware collection by provided ID.

  • gibtia-get-osi-git-leak-info

    Command performs Group IB event lookup in osi/git_leak collection with provided ID.

  • gibtia-get-osi-public-leak-info

    Command performs Group IB event lookup in osi/public_leak collection with provided ID.

  • gibtia-get-osi-vulnerability-info

    Command performs Group IB event lookup in osi/vulnerability collection with provided ID.

  • gibtia-get-phishing-group-info

    Command performs Group IB event lookup in attacks/phishing_group collection by provided ID.

  • gibtia-get-suspicious-ip-open-proxy-info

    Command performs Group IB event lookup in suspicious_ip/open_proxy collection with provided ID.

  • gibtia-get-suspicious-ip-scanner-info

    Command performs Group IB event lookup in suspicious_ip/scanner collection by provided ID.

  • gibtia-get-suspicious-ip-socks-proxy-info

    Command performs Group IB event lookup in suspicious_ip/socks_proxy collection with provided ID.

  • gibtia-get-suspicious-ip-tor-node-info

    Command performs Group IB event lookup in suspicious_ip/tor_node collection with provided ID.

  • gibtia-get-suspicious-ip-vpn-info

    Command performs Group IB event lookup in suspicious_ip/vpn collection by provided ID.

  • gibtia-get-threat-actor-info

    Command performs Group IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.

  • gibtia-get-threat-info

    Command performs Group IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.

  • gibtia-global-search

    Command performs global Group IB search.

  • gibtia-local-search

    Command performs Group IB search in selected collection.

  • ip

    Runs reputation on IPs.

category: Data Enrichment & Threat Intelligence
provider: Group IB
commonfields:
  id: Group-IB Threat Intelligence & Attribution
  version: -1
configuration:
- additionalinfo: The FQDN/IP the integration should connect to.
  defaultvalue: https://tap.group-ib.com/api/v2/
  display: GIB TI URL
  name: url
  required: true
  type: 0
  section: Connect
- additionalinfo: The API Key and Username required to authenticate to the service.
  display: Username
  name: credentials
  required: true
  type: 9
  section: Connect
- additionalinfo: Whether to allow connections without verifying SSL certificates validity.
  display: Trust any certificate (not secure)
  name: insecure
  required: false
  type: 8
  section: Connect
- additionalinfo: Whether to use XSOAR system proxy settings to connect to the API.
  display: Use system proxy settings
  name: proxy
  required: false
  type: 8
  section: Connect
- display: Source Reliability
  name: integration_reliability
  required: true
  type: 15
  section: Connect
  additionalinfo: Reliability of the source providing the intelligence data.
  defaultvalue: C - Fairly reliable
  options:
  - A+ - 3rd party enrichment
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
- additionalinfo: If true, ignore the instance Source Reliability setting and use the integration’s computed reliability per indicator.
  display: Ignore Source Reliability override
  section: Connect
  name: disable_integration_reliability_override
  required: false
  type: 8
  defaultvalue: "false"
- additionalinfo: |-
    Select which reputation commands should be enabled for this integration instance.
    Default is none enabled. Only the selected commands will perform enrichment and return DBotScore.
  section: Connect
  display: Enable reputation commands
  name: enabled_reputation_commands
  required: false
  type: 16
  options:
  - ip
  - domain
  - file
- section: Collect
  display: Fetch incidents
  name: isFetch
  required: false
  type: 8
- display: Collections to fetch
  name: incident_collections
  section: Collect
  required: false
  type: 16
  additionalinfo: Type(s) of incidents to fetch from the third party API.
  hidden: false
  options:
  - compromised/account_group
  - compromised/bank_card_group
  - compromised/masked_card
  - compromised/breached
  - compromised/spd
  - osi/git_repository
  - osi/public_leak
  - osi/vulnerability
  - attacks/ddos
  - attacks/deface
  - attacks/phishing_group
  - attacks/phishing_kit
  - suspicious_ip/tor_node
  - suspicious_ip/open_proxy
  - suspicious_ip/socks_proxy
  - suspicious_ip/vpn
  - suspicious_ip/scanner
  - malware/cnc
  - malware/malware
  - hi/threat
  - hi/threat_actor
  - apt/threat_actor
  - apt/threat
- display: Incidents first fetch
  name: first_fetch
  section: Collect
  defaultvalue: "3 days"
  type: 0
  required: false
  additionalinfo: Date to start fetching incidents from.
  hidden: false
- display: Exclude All with Combolist type
  name: exclude_combolist
  section: Collect
  required: false
  type: 8
  defaultvalue: "false"
  additionalinfo: This parameter has been deprecated.
- display: Include combolist type in data
  name: combolist
  section: Collect
  defaultvalue: "false"
  type: 8
  required: false
  additionalinfo: Works only for compromised/account_group. If the parameter is enabled, the response contains combolist data. If you enable “Include unique type in data” with this filter, the response will contain data of both types. If “Include combolist type in data” and “Include unique type in data” are disabled, the response will contain data of both types.
- display: Include unique type in data
  name: unique
  section: Collect
  defaultvalue: "false"
  type: 8
  required: false
  additionalinfo: Works only for compromised/account_group. If the parameter is enabled, the response contains unique data. If you enable “Include combolist type in data” with this filter, the response will contain data of both types. If “Include combolist type in data” and “Include unique type in data” are disabled, the response will contain data of both types.
- display: Enable filter "Probable Corporate Access"
  name: enable_probable_corporate_access
  section: Collect
  required: false
  type: 8
  defaultvalue: "false"
  additionalinfo: Works only for compromised/account_group
- display: Number of requests per collection
  name: max_fetch
  section: Collect
  defaultvalue: '3'
  type: 15
  required: false
  additionalinfo: A number of requests per collection that integration sends in one fetch iteration (each request picks up to 200 incidents). If you face some runtime errors, lower the value.
  hidden: false
  options:
  - '1'
  - '2'
  - '3'
  - '4'
  - '5'
- display: Skip updated incidents (prevent duplicates)
  name: skip_updated_incidents
  section: Collect
  defaultvalue: "false"
  type: 8
  required: false
  additionalinfo: Disabled by default. Enable this only when you want the integration itself to prevent duplicate incidents by skipping Group-IB records that were already fetched and later re-returned after updates because Pre-Processing Rules cannot be used reliably. Leave this disabled if you intentionally want updated incidents to be re-ingested so a Pre-Processing Rule can update existing incidents instead.
- display: Deduplication lookback (days)
  name: dedup_lookback_days
  section: Collect
  defaultvalue: "365"
  type: 0
  required: false
  additionalinfo: Number of days to remember fetched Group-IB incident IDs in the built-in deduplication cache. This setting is used only when Skip updated incidents is enabled. Recommended value is 365 days so older updated records are still skipped if the API re-sends them much later. Set this to 0 only if you intentionally want to disable built-in deduplication.
- display: Limit (items per request)
  name: limit
  section: Collect
  defaultvalue: '100'
  type: 0
  required: false
  additionalinfo: Number of items requested per API page. Larger values reduce API round-trips but may increase response size. Server-side caps may apply.
- display: Incident type
  name: incidentType
  section: Collect
  required: false
  type: 13
- display: Incidents Fetch Interval
  name: incidentFetchInterval
  defaultvalue: '1'
  required: false
  type: 19
  section: Collect
  advanced: true
- display: Hunting Rules
  name: hunting_rules
  section: Collect
  defaultvalue: "false"
  type: 8
  required: false
  additionalinfo: To enable the collection of data using hunting rules, please select this parameter.
description: "Pack helps to integrate Group-IB Threat Intelligence and get incidents directly into Cortex XSOAR. \nThe list of included collections: \nCompromised Accounts, Compromised Cards, Compromised Masked Cards, Brand Protection Phishing, Brand Protection Phishing Kit, OSI Git Leak, OSI Public Leak, Targeted Malware."
detaileddescription: "### Group-IB Threat Intelligence\n  \n  \n- This section explains how to configure the instance of Threat Intelligence in Cortex XSOAR.  \n  \n1. Open Group-IB TI web interface. (It may be either new interface: [https://tap.group-ib.com](https://tap.group-ib.com))  \n2. To generate API key(password):  \n2.1. In the new interface: click on your name in the right upper corner -> choose **Profile** option -> switch to **Security and Access** tab -> click **Personal token** -> follow instructions to generate API token.  \n3. Your server URL is the same as your TI web interface URL.  \n4. Your username is the email that you use to enter in the web interface.\n5. Set classifier and mapper with Group-IB Threat Intelligence classifier and mapper or with your own if needed.\n6. Built-in fetch deduplication is intended for environments where Pre-Processing Rules do not work reliably or cannot be used operationally. **Skip updated incidents** is disabled by default and should be enabled only if you want the integration itself to suppress duplicates when the Group-IB API re-sends the same incident after an update.\n7. **Deduplication lookback (days)** controls how long the integration remembers fetched Group-IB incident IDs while built-in deduplication is enabled. Recommended value is **365 days**.\n8. If you intentionally rely on Pre-Processing Rules to update existing incidents, keep **Skip updated incidents** disabled and configure the `GIBIncidentUpdate`, `GIBIncidentUpdateAllTypes`, or `GIBIncidentUpdateIncludingClosed` script manually. Use `GIBIncidentUpdateAllTypes` when you want the fallback rule to apply without excluding the `GIB Data Breach` incident type.\n9. Don't forget to contact Group-IB to add to allow list your Cortex IP or public IP of a proxy that you are using with Cortex."
display: Group-IB Threat Intelligence
name: Group-IB Threat Intelligence & Attribution
script:
  commands:
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 253b9a136f0d574149fc43691eaf7ae27aff141a.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/account collection with provided ID.
    name: gibtia-get-compromised-account-info
    outputs:
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.asn
      description: Victim IP address.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.countryName
      description: Country name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.ip
      description: Victim IP address.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.region
      description: Region name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.cnc.domain
      description: Event CNC domain.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.cnc.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.cnc.ipv4.ip
      description: CNC IP address.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.dateCompromised
      description: Date of compromise.
      type: Date
    - contextPath: GIBTIA.CompromisedAccount.dateDetected
      description: Date of detection.
      type: Date
    - contextPath: GIBTIA.CompromisedAccount.dropEmail.email
      description: Email where compromised data were sent to.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.dropEmail.domain
      description: Email domain.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.login
      description: Compromised login.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.password
      description: Compromised password.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.malware.name
      description: Malware name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.malware.id
      description: Group IB malware ID.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.person.name
      description: Card owner name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.person.email
      description: Card owner e-mail.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.portalLink
      description: Link to GIB incident.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.threatActor.isAPT
      description: Is threat actor APT group.
      type: Boolean
    - contextPath: GIBTIA.CompromisedAccount.threatActor.id
      description: Threat actor GIB ID.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.id
      description: Group IB incident ID.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 50a3b4abbfca5dcbec9c8b3a110598f61ba93r33.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/spd (suspicious payment details) collection with provided ID.
    name: gibtia-get-compromised-spd-info
    outputs:
    - contextPath: GIBTIA.CompromisedSPD.id
      description: Group IB SPD incident ID.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.type
      description: Observable type (e.g. Cryptocurrency Wallet).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.value.value
      description: Main observable value (wallet address, etc.).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.serviceType
      description: Service type (e.g. BTCLike, XMRLike).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.portalLink
      description: Link to GIB incident.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 50a3b4abbfca5dcbec9c8b3a110598f61ba93r33.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/mule collection with provided ID.
    name: gibtia-get-compromised-mule-info
    outputs:
    - contextPath: GIBTIA.CompromisedMule.account
      description: Account number (card/phone), which was used by threat actor to cash out.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.asn
      description: CNC ASN.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.countryName
      description: Country name.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.ip
      description: Victim IP address.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.region
      description: Region name.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.domain
      description: CNC domain.
      type: String
    - contextPath: GIBTIA.CompromisedMule.dateAdd
      description: Date of detection.
      type: Date
    - contextPath: GIBTIA.CompromisedMule.malware.name
      description: Malware name.
      type: String
    - contextPath: GIBTIA.CompromisedMule.portalLink
      description: Link to GIB incident.
      type: String
    - contextPath: GIBTIA.CompromisedMule.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.CompromisedMule.threatActor.id
      description: Threat actor GIB ID.
      type: String
    - contextPath: GIBTIA.CompromisedMule.threatActor.isAPT
      description: Is threat actor APT group.
      type: Boolean
    - contextPath: GIBTIA.CompromisedMule.id
      description: Group IB incident ID.
      type: String
    - contextPath: GIBTIA.CompromisedMule.sourceType
      description: Information source.
      type: String
    - contextPath: GIBTIA.CompromisedMule.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 6fd344f340f4bdc08548cb36ded62bdf.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/breached collection with provided ID.
    name: gibtia-get-compromised-breached-info
    outputs:
    - contextPath: GIBTIA.DataBreach.email
      description: List of breached emails.
      type: String
    - contextPath: GIBTIA.DataBreach.leakName
      description: Name of the leak.
      type: String
    - contextPath: GIBTIA.DataBreach.password
      description: List of breached passwords.
      type: String
    - contextPath: GIBTIA.DataBreach.uploadTime
      description: Date of breached data upload.
      type: Date
    - contextPath: GIBTIA.DataBreach.id
      description: Group IB incident ID.
      type: String
    - contextPath: GIBTIA.DataBreach.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: f201c253ac71f7d78db39fa111a2af9d7ee7a3f7.
      name: id
      required: true
    description: Command performs Group IB event lookup in osi/git_leak collection with provided ID.
    name: gibtia-get-osi-git-leak-info
    outputs:
    - contextPath: GIBTIA.GitLeak.dateDetected
      description: Leak detection date.
      type: Date
    - contextPath: GIBTIA.GitLeak.matchesType
      description: List of matches type.
      type: String
    - contextPath: GIBTIA.GitLeak.name
      description: GIT filename.
      type: String
    - contextPath: GIBTIA.GitLeak.repository
      description: GIT repository.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.file
      description: Leaked file link.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.fileDiff
      description: Leaked file diff.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.info.authorName
      description: Revision author.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.info.authorEmail
      description: Author name.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.info.dateCreated
      description: Revision creation date.
      type: Date
    - contextPath: GIBTIA.GitLeak.source
      description: Source(github/gitlab/etc.)
      type: String
    - contextPath: GIBTIA.GitLeak.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: a9a5b5cb9b971a2a037e3a0a30654185ea148095.
      name: id
      required: true
    description: Command performs Group IB event lookup in osi/public_leak collection with provided ID.
    name: gibtia-get-osi-public-leak-info
    outputs:
    - contextPath: GIBTIA.PublicLeak.created
      description: Leak event detection date.
      type: Date
    - contextPath: GIBTIA.PublicLeak.data
      description: Leaked data.
      type: String
    - contextPath: GIBTIA.PublicLeak.hash
      description: Leak data hash.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.author
      description: Leak entry author.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.dateDetected
      description: Leak detection date.
      type: Date
    - contextPath: GIBTIA.PublicLeak.linkList.datePublished
      description: Leak publish date.
      type: Date
    - contextPath: GIBTIA.PublicLeak.linkList.hash
      description: Leak hash.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.link
      description: Leak link.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.source
      description: Leak source.
      type: String
    - contextPath: GIBTIA.PublicLeak.matches
      description: Matches.
      type: String
    - contextPath: GIBTIA.PublicLeak.portalLink
      description: Group IB portal link.
      type: String
    - contextPath: GIBTIA.PublicLeak.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.

        e.g.: CVE-2021-27152.
      name: id
      required: true
    description: Command performs Group IB event lookup in osi/vulnerability collection with provided ID.
    name: gibtia-get-osi-vulnerability-info
    outputs:
    - contextPath: GIBTIA.OSIVulnerability.affectedSoftware.name
      description: Affected software name.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.affectedSoftware.operator
      description: Affected software version operator( ex. le=less or equal).
      type: String
    - contextPath: GIBTIA.OSIVulnerability.affectedSoftware.version
      description: Affected software version.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.bulletinFamily
      description: Bulletin family.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.cvss.score
      description: CVSS score.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.cvss.vector
      description: CVSS vector.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.dateLastSeen
      description: Date last seen.
      type: Date
    - contextPath: GIBTIA.OSIVulnerability.datePublished
      description: Date published.
      type: Date
    - contextPath: GIBTIA.OSIVulnerability.description
      description: Vulnerability description.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.id
      description: Vulnerability ID.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.reporter
      description: Vulnerability reporter.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.title
      description: Vulnerability title.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 26a05baa4025edff367b058b13c6b43e820538a5.
      name: id
      required: true
    description: Command performs Group IB event lookup in attacks/ddos collection with provided ID.
    name: gibtia-get-attacks-ddos-info
    outputs:
    - contextPath: GIBTIA.AttacksDDoS.cnc.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.domain
      description: CNC domain.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.asn
      description: CNC ASN.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.countryName
      description: CNC IP country name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.ip
      description: CNC IP address.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.region
      description: CNC region name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.asn
      description: DDoS target ASN.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.countryName
      description: DDoS target country name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.ip
      description: DDoS target IP address.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.region
      description: DDoS target region name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.category
      description: DDoS target category.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.domain
      description: DDoS target domain.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.threatActor.id
      description: Associated threat actor ID.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.AttacksDdos.threatActor.isAPT
      description: Is threat actor APT.
      type: Boolean
    - contextPath: GIBTIA.AttacksDDoS.id
      description: GIB incident ID.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 6009637a1135cd001ef46e21.
      name: id
      required: true
    description: Command performs Group IB event lookup in attacks/deface collection with provided ID.
    name: gibtia-get-attacks-deface-info
    outputs:
    - contextPath: GIBTIA.AttacksDeface.date
      description: Date of deface.
      type: Date
    - contextPath: GIBTIA.AttacksDeface.id
      description: GIB incident ID.
      type: String
    - contextPath: GIBTIA.AttacksDeface.targetIp.asn
      description: Victim ASN.
      type: String
    - contextPath: GIBTIA.AttacksDeface.targetIp.countryName
      description: Victim country name.
      type: String
    - contextPath: GIBTIA.AttacksDeface.targetIp.region
      description: Victim IP region name.
      type: String
    - contextPath: GIBTIA.AttacksDeface.threatActor.id
      description: Associated threat actor ID.
      type: String
    - contextPath: GIBTIA.AttacksDeface.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.AttacksDeface.threatActor.isAPT
      description: Is threat actor APT.
      type: Boolean
    - contextPath: GIBTIA.AttacksDeface.url
      description: URL of compromised resource.
      type: String
    - contextPath: GIBTIA.AttacksDeface.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 1b09d389d016121afbffe481a14b30ea995876e4.
      name: id
      required: true
    - name: isAPT
      auto: PREDEFINED
      predefined:
      - "true"
      - "false"
      description: Is threat APT.
      defaultValue: "false"
    description: Command performs Group IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.
    name: gibtia-get-threat-info
    outputs:
    - contextPath: GIBTIA.Threat.contacts.account
      description: Threat accounts found in this threat action.
      type: String
    - contextPath: GIBTIA.Threat.contacts.flag
      description: Is account fake or not.
      type: String
    - contextPath: GIBTIA.Threat.contacts.service
      description: Account service.
      type: String
    - contextPath: GIBTIA.Threat.contacts.type
      description: Type of account(social_network/email/wallet etc.)
      type: String
    - contextPath: GIBTIA.Threat.countries
      description: Affected countries.
      type: String
    - contextPath: GIBTIA.Threat.createdAt
      description: Threat report creation date.
      type: Date
    - contextPath: GIBTIA.Threat.cveList.name
      description: List of abused CVE.
      type: String
    - contextPath: GIBTIA.Threat.dateFirstSeen
      description: Attack first seen date.
      type: Date
    - contextPath: GIBTIA.Threat.dateLastSeen
      description: Attack last seen date.
      type: Date
    - contextPath: GIBTIA.Threat.datePublished
      description: Date published.
      type: Date
    - contextPath: GIBTIA.Threat.description
      description: Threat description.
      type: String
    - contextPath: GIBTIA.Threat.forumsAccounts.url
      description: Related forum URL.
      type: String
    - contextPath: GIBTIA.Threat.forumsAccounts.nickname
      description: Related forums account.
      type: String
    - contextPath: GIBTIA.Threat.forumsAccounts.registeredAt
      description: Related forums account registration date.
      type: Date
    - contextPath: GIBTIA.Threat.forumsAccounts.messageCount
      description: Related forums messages count.
      type: Number
    - contextPath: GIBTIA.Threat.id
      description: GIB internal threat ID.
      type: String
    - contextPath: GIBTIA.Threat.indicators
      description: Can be either network or file indicators.
      type: String
    - contextPath: GIBTIA.Threat.langs
      description: Languages actors related.
      type: String
    - contextPath: GIBTIA.Threat.malwareList.name
      description: Related Malware Name.
      type: String
    - contextPath: GIBTIA.Threat.malwareList.id
      description: Related malware GIB internal ID.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.attackPatternId
      description: MITRE attack pattern ID.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.attackTactic
      description: MITRE attack tactic name.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.attackType
      description: MITRE attack type.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.id
      description: MITRE attack id.
      type: String
    - contextPath: GIBTIA.Threat.regions
      description: Regions affected by attack.
      type: String
    - contextPath: GIBTIA.Threat.reportNumber
      description: GIB report number.
      type: String
    - contextPath: GIBTIA.Threat.sectors
      description: Affected sectors.
      type: String
    - contextPath: GIBTIA.Threat.shortDescription
      description: Short description.
      type: String
    - contextPath: GIBTIA.Threat.title
      description: Threat title.
      type: String
    - contextPath: GIBTIA.Threat.targetedCompany
      description: Targeted company name.
      type: String
    - contextPath: GIBTIA.Threat.ThreatActor.name
      description: Threat actor name.
      type: String
    - contextPath: GIBTIA.Threat.ThreatActor.id
      description: Threat actor ID.
      type: String
    - contextPath: GIBTIA.Threat.ThreatActor.isAPT
      description: Is threat actor APT group.
      type: Boolean
    - contextPath: GIBTIA.Threat.sources
      description: Sources links.
      type: String
    - contextPath: GIBTIA.Threat.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB internal threatActor ID.
        e.g.: 0d4496592ac3a0f5511cd62ef29887f48d9cb545.
      name: id
      required: true
    - name: isAPT
      auto: PREDEFINED
      predefined:
      - "true"
      - "false"
      description: Is threat actor APT group.
      defaultValue: "false"
    description: Command performs Group IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.
    name: gibtia-get-threat-actor-info
    outputs:
    - contextPath: GIBTIA.ThreatActor.aliases
      description: Threat actor aliases.
      type: String
    - contextPath: GIBTIA.ThreatActor.country
      description: Threat actor country.
      type: String
    - contextPath: GIBTIA.ThreatActor.createdAt
      description: Threat actor record creation time.
      type: Date
    - contextPath: GIBTIA.ThreatActor.description
      description: Threat actor description.
      type: String
    - contextPath: GIBTIA.ThreatActor.goals
      description: Threat actor goals sectors(financial, diplomatic, etc.)
      type: String
    - contextPath: GIBTIA.ThreatActor.id
      description: Threat actor id.
      type: String
    - contextPath: GIBTIA.ThreatActor.isAPT
      description: Threat actor is APT.
      type: Boolean
    - contextPath: GIBTIA.ThreatActor.labels
      description: GIB internal threat actor labels(hacker, nation-state, etc.)
      type: String
    - contextPath: GIBTIA.ThreatActor.langs
      description: Threat actor communication language.
      type: String
    - contextPath: GIBTIA.ThreatActor.name
      description: Threat actor name.
      type: String
    - contextPath: GIBTIA.ThreatActor.roles
      description: Threat actor roles.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.countries
      description: Threat actor countries activity found in.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.dateFirstSeen
      description: Date first seen.
      type: Date
    - contextPath: GIBTIA.ThreatActor.stat.dateLastSeen
      description: Date last seen.
      type: Date
    - contextPath: GIBTIA.ThreatActor.stat.regions
      description: Threat actor activity regions.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.reports.datePublished
      description: Related threat report publishing date.
      type: Date
    - contextPath: GIBTIA.ThreatActor.stat.reports.id
      description: Related threat report id.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.reports.name.en
      description: Related threat report language.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.sectors
      description: Sectors attacked by threat actor.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 109.70.100.46.
      name: id
      required: true
    description: Command performs Group IB event lookup in suspicious_ip/tor_node collection with provided ID.
    name: gibtia-get-suspicious-ip-tor-node-info
    outputs:
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.asn
      description: Tor node ASN.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.countryName
      description: Tor node IP country name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.ip
      description: Tor node IP address.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.region
      description: Tor node IP region name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.id
      description: GIB id.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: cc6a2856da2806b03839f81aa214f22dbcfd7369.
      name: id
      required: true
    description: Command performs Group IB event lookup in suspicious_ip/open_proxy collection with provided ID.
    name: gibtia-get-suspicious-ip-open-proxy-info
    outputs:
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.asn
      description: Proxy ASN.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.countryName
      description: Proxy IP country name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.ip
      description: Proxy IP address.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.region
      description: Proxy IP region name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.port
      description: Proxy port.
      type: Number
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.source
      description: Information source.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.anonymous
      description: Proxy anonymous level.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.id
      description: GIB event ID.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.evaluation.severity
      description: Event severity.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e.
      name: id
      required: true
    description: Command performs Group IB event lookup in suspicious_ip/socks_proxy collection with provided ID.
    name: gibtia-get-suspicious-ip-socks-proxy-info
    outputs:
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.asn
      description: Proxy IP ASN.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.countryName
      description: Proxy IP country name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.ip
      description: Proxy IP address.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.region
      description: Proxy IP region name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.id
      description: GIB ID.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.evaluation.severity
      description: Event severity.
      type: String
  - arguments: []
    description: Returns list of available collections.
    name: gibtia-get-available-collections
    outputs:
    - contextPath: GIBTIA.OtherInfo.collections
      description: List of availiable collections.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: aeed277396e27e375d030a91533aa232444d0089.
      name: id
      required: true
    description: Command performs Group IB event lookup in malware/cnc collection by provided ID.
    name: gibtia-get-malware-cnc-info
    outputs:
    - contextPath: GIBTIA.MalwareCNC.dateDetected
      description: Date CNC detected.
      type: Date
    - contextPath: GIBTIA.MalwareCNC.dateLastSeen
      description: Date CNC last seen.
      type: Date
    - contextPath: GIBTIA.MalwareCNC.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.MalwareCNC.domain
      description: CNC domain.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.asn
      description: CNC ASN.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.countryName
      description: CNC IP country name.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.ip
      description: CNC IP address.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.region
      description: CNC region name.
      type: String
    - contextPath: GIBTIA.MalwareCNC.malwareList.name
      description: Associated malware.
      type: String
    - contextPath: GIBTIA.MalwareCNC.threatActor.id
      description: Associated threat actor ID.
      type: String
    - contextPath: GIBTIA.MalwareCNC.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.MalwareCNC.threatActor.isAPT
      description: Is APT or not.
      type: Boolean
    - contextPath: GIBTIA.MalwareCNC.id
      description: GIB event ID.
      type: String
  - arguments:
    - description: |-
        Query you want to search.
        e.g.: 8.8.8.8.
      name: query
      required: true
    description: Command performs global Group IB search.
    name: gibtia-global-search
    outputs:
    - contextPath: apiPath
      description: Name of collection in which found matches.
      type: String
    - contextPath: count
      description: Count of feeds matching this query.
      type: Number
    - contextPath: GIBLink
      description: Link to GIB TI&A interface.
      type: String
  - arguments:
    - description: |-
        Collection you want to search.
      name: collection_name
      required: true
      auto: PREDEFINED
      predefined:
      - compromised/account_group
      - compromised/bank_card_group
      - compromised/masked_card
      - compromised/breached
      - compromised/mule
      - compromised/spd
      - osi/git_repository
      - osi/public_leak
      - osi/vulnerability
      - attacks/ddos
      - attacks/deface
      - attacks/phishing_group
      - attacks/phishing_kit
      - suspicious_ip/tor_node
      - suspicious_ip/open_proxy
      - suspicious_ip/socks_proxy
      - suspicious_ip/vpn
      - suspicious_ip/scanner
      - malware/cnc
      - malware/malware
      - hi/threat
      - hi/threat_actor
      - apt/threat_actor
      - apt/threat
    - name: query
      required: true
      description: |-
        Query you want to search.
        e.g.: 8.8.8.8.
    - name: date_from
      description: Start date of search session.
    - name: date_to
      description: End date of search session.
    - name: requests_limit
      description: |-
        Maximum number of API requests (pages) sent to the collection.
        Default is 1 to keep the command deterministic and avoid long-running executions.
      defaultValue: "1"
    - name: page_size_limit
      description: |-
        Maximum number of entries per API response (page size).
        If not set, the service default will be used.
      defaultValue: "100"
    - name: seq_update
      description: |-
        Optional starting seqUpdate for update-based iteration.
        Warning: providing an old seqUpdate (or using 0) can cause very long executions.
    - name: include_raw_feed
      description: |-
        If set to true, include the full parsed feed object in outputs as 'raw_feed'.
        Use with caution: can increase context size.
      defaultValue: "false"
    description: Command performs Group IB search in selected collection.
    name: gibtia-local-search
    outputs:
    - contextPath: id
      description: Id of a feed that matches a query.
      type: String
    - contextPath: additional_info
      description: Additional info about feed.
      type: String
    - contextPath: GIBTIA.search.local.id
      description: Id of a feed that matches a query.
      type: String
    - contextPath: GIBTIA.search.local.additional_info
      description: Additional info about feed.
      type: String
    - contextPath: GIBTIA.search.local.seqUpdate
      description: seqUpdate value of the page/portion that returned the feed.
      type: Number
    - contextPath: GIBTIA.search.local.raw_feed
      description: One-line JSON string of the full feed for War Room rendering (only when include_raw_feed=true).
      type: String
  - description: Command performs Group IB event lookup in suspicious_ip/vpn collection by provided ID.
    name: gibtia-get-suspicious-ip-vpn-info
    arguments:
    - name: id
      description: 'GIB event id.e.g.: 192.168.0.1.'
  - arguments:
    - description: 'List of IPs to score.'
      name: ip
      required: true
      default: true
      isArray: true
    description: Returns Group-IB scoring for IPs (numeric and DBotScore).
    name: gibti-ip-scoring
    outputs:
    - contextPath: DBotScore.Indicator
      description: The indicator value.
      type: String
    - contextPath: DBotScore.Type
      description: Indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: Vendor reporting the score.
      type: String
    - contextPath: DBotScore.Score
      description: DBot score (0 unknown, 1 good, 2 suspicious, 3 bad).
      type: Number
    - contextPath: DBotScore.Reliability
      description: Source reliability.
      type: String
    - contextPath: IP.Address
      description: IP address.
      type: String
    compliantpolicies:
    - IP Blockage
  - arguments:
    - description: 'GIB event id.e.g.: 192.168.0.1.'
      name: id
    description: Command performs Group IB event lookup in suspicious_ip/scanner collection by provided ID.
    name: gibtia-get-suspicious-ip-scanner-info
  - arguments:
    - description: 'GIB event id.e.g.: 653654fb986b47a31c73d92f4a20a273acd2f779.'
      name: id
    description: Command performs Group IB event lookup in malware/malware collection by provided ID.
    name: gibtia-get-malware-malware-info
  - arguments:
    - description: GIB event id.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/bank_card_group collection by provided ID.
    name: gibtia-get-compromised-card-group-info
  - arguments:
    - description: GIB event id.
      name: id
      required: true
    description: Command performs Group IB event lookup in attacks/phishing_group collection by provided ID.
    name: gibtia-get-phishing-group-info
  - name: ip
    description: Runs reputation on IPs.
    arguments:
    - name: ip
      default: true
      isArray: true
      description: List of IPs.
    outputs:
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Source reliability.
      type: String
    - contextPath: IP.Address
      description: IP address.
      type: String
    compliantpolicies:
    - IP Blockage
  - name: domain
    description: Runs reputation on domains.
    arguments:
    - name: domain
      default: true
      isArray: true
      description: List of domains.
    outputs:
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Source reliability.
      type: String
    - contextPath: Domain.Name
      description: Domain name.
      type: String
    compliantpolicies:
    - User Soft Remediation
  - name: file
    description: Runs reputation on files.
    arguments:
    - name: file
      default: true
      isArray: true
      description: List of files (hashes).
    outputs:
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Source reliability.
      type: String
    - contextPath: File.MD5
      description: File MD5 hash.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 253b9a136f0d574149fc43691eaf7ae27aff141a.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/account collection with provided ID.
    name: gibti-get-compromised-account-info
    outputs:
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.asn
      description: Victim IP address.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.countryName
      description: Country name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.ip
      description: Victim IP address.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.client.ipv4.region
      description: Region name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.cnc.domain
      description: Event CNC domain.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.cnc.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.cnc.ipv4.ip
      description: CNC IP address.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.dateCompromised
      description: Date of compromise.
      type: Date
    - contextPath: GIBTIA.CompromisedAccount.dateDetected
      description: Date of detection.
      type: Date
    - contextPath: GIBTIA.CompromisedAccount.dropEmail.email
      description: Email where compromised data were sent to.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.dropEmail.domain
      description: Email domain.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.login
      description: Compromised login.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.password
      description: Compromised password.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.malware.name
      description: Malware name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.malware.id
      description: Group IB malware ID.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.person.name
      description: Card owner name.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.person.email
      description: Card owner e-mail.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.portalLink
      description: Link to GIB incident.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.threatActor.isAPT
      description: Is threat actor APT group.
      type: Boolean
    - contextPath: GIBTIA.CompromisedAccount.threatActor.id
      description: Threat actor GIB ID.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.id
      description: Group IB incident ID.
      type: String
    - contextPath: GIBTIA.CompromisedAccount.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 50a3b4abbfca5dcbec9c8b3a110598f61ba93r33.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/spd (suspicious payment details) collection with provided ID.
    name: gibti-get-compromised-spd-info
    outputs:
    - contextPath: GIBTIA.CompromisedSPD.id
      description: Group IB SPD incident ID.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.type
      description: Observable type (e.g. Cryptocurrency Wallet).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.value.value
      description: Main observable value (wallet address, etc.).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.serviceType
      description: Service type (e.g. BTCLike, XMRLike).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.portalLink
      description: Link to GIB incident.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.evaluation.severity
      description: Event severity.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.evaluation.tlp
      description: Traffic Light Protocol (TLP).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.evaluation.ttl
      description: Time-to-live (days) from evaluation.
      type: Number
    - contextPath: GIBTIA.CompromisedSPD.ownerName
      description: Owner name.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.illegalScore
      description: Illegal score.
      type: Number
    - contextPath: GIBTIA.CompromisedSPD.events
      description: SPD events (compromised at, source, malware, threat actor, etc.).
      type: String
    - contextPath: GIBTIA.CompromisedSPD.sources
      description: Sources.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.malware
      description: Associated malware.
      type: String
    - contextPath: GIBTIA.CompromisedSPD.threatActor
      description: Associated threat actor.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 50a3b4abbfca5dcbec9c8b3a110598f61ba93r33.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/mule collection with provided ID.
    name: gibti-get-compromised-mule-info
    outputs:
    - contextPath: GIBTIA.CompromisedMule.account
      description: Account number (card/phone), which was used by threat actor to cash out.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.asn
      description: CNC ASN.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.countryName
      description: Country name.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.ip
      description: Victim IP address.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.ipv4.region
      description: Region name.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.CompromisedMule.cnc.domain
      description: CNC domain.
      type: String
    - contextPath: GIBTIA.CompromisedMule.dateAdd
      description: Date of detection.
      type: Date
    - contextPath: GIBTIA.CompromisedMule.malware.name
      description: Malware name.
      type: String
    - contextPath: GIBTIA.CompromisedMule.portalLink
      description: Link to GIB incident.
      type: String
    - contextPath: GIBTIA.CompromisedMule.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.CompromisedMule.threatActor.id
      description: Threat actor GIB ID.
      type: String
    - contextPath: GIBTIA.CompromisedMule.threatActor.isAPT
      description: Is threat actor APT group.
      type: Boolean
    - contextPath: GIBTIA.CompromisedMule.id
      description: Group IB incident ID.
      type: String
    - contextPath: GIBTIA.CompromisedMule.sourceType
      description: Information source.
      type: String
    - contextPath: GIBTIA.CompromisedMule.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 6fd344f340f4bdc08548cb36ded62bdf.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/breached collection with provided ID.
    name: gibti-get-compromised-breached-info
    outputs:
    - contextPath: GIBTIA.DataBreach.email
      description: List of breached emails.
      type: String
    - contextPath: GIBTIA.DataBreach.leakName
      description: Name of the leak.
      type: String
    - contextPath: GIBTIA.DataBreach.password
      description: List of breached passwords.
      type: String
    - contextPath: GIBTIA.DataBreach.uploadTime
      description: Date of breached data upload.
      type: Date
    - contextPath: GIBTIA.DataBreach.id
      description: Group IB incident ID.
      type: String
    - contextPath: GIBTIA.DataBreach.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: f201c253ac71f7d78db39fa111a2af9d7ee7a3f7.
      name: id
      required: true
    description: Command performs Group IB event lookup in osi/git_leak collection with provided ID.
    name: gibti-get-osi-git-leak-info
    outputs:
    - contextPath: GIBTIA.GitLeak.dateDetected
      description: Leak detection date.
      type: Date
    - contextPath: GIBTIA.GitLeak.matchesType
      description: List of matches type.
      type: String
    - contextPath: GIBTIA.GitLeak.name
      description: GIT filename.
      type: String
    - contextPath: GIBTIA.GitLeak.repository
      description: GIT repository.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.file
      description: Leaked file link.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.fileDiff
      description: Leaked file diff.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.info.authorName
      description: Revision author.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.info.authorEmail
      description: Author name.
      type: String
    - contextPath: GIBTIA.GitLeak.revisions.info.dateCreated
      description: Revision creation date.
      type: Date
    - contextPath: GIBTIA.GitLeak.source
      description: Source(github/gitlab/etc.)
      type: String
    - contextPath: GIBTIA.GitLeak.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: a9a5b5cb9b971a2a037e3a0a30654185ea148095.
      name: id
      required: true
    description: Command performs Group IB event lookup in osi/public_leak collection with provided ID.
    name: gibti-get-osi-public-leak-info
    outputs:
    - contextPath: GIBTIA.PublicLeak.created
      description: Leak event detection date.
      type: Date
    - contextPath: GIBTIA.PublicLeak.data
      description: Leaked data.
      type: String
    - contextPath: GIBTIA.PublicLeak.hash
      description: Leak data hash.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.author
      description: Leak entry author.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.dateDetected
      description: Leak detection date.
      type: Date
    - contextPath: GIBTIA.PublicLeak.linkList.datePublished
      description: Leak publish date.
      type: Date
    - contextPath: GIBTIA.PublicLeak.linkList.hash
      description: Leak hash.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.link
      description: Leak link.
      type: String
    - contextPath: GIBTIA.PublicLeak.linkList.source
      description: Leak source.
      type: String
    - contextPath: GIBTIA.PublicLeak.matches
      description: Matches.
      type: String
    - contextPath: GIBTIA.PublicLeak.portalLink
      description: Group IB portal link.
      type: String
    - contextPath: GIBTIA.PublicLeak.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.

        e.g.: CVE-2021-27152.
      name: id
      required: true
    description: Command performs Group IB event lookup in osi/vulnerability collection with provided ID.
    name: gibti-get-osi-vulnerability-info
    outputs:
    - contextPath: GIBTIA.OSIVulnerability.affectedSoftware.name
      description: Affected software name.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.affectedSoftware.operator
      description: Affected software version operator( ex. le=less or equal).
      type: String
    - contextPath: GIBTIA.OSIVulnerability.affectedSoftware.version
      description: Affected software version.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.bulletinFamily
      description: Bulletin family.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.cvss.score
      description: CVSS score.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.cvss.vector
      description: CVSS vector.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.dateLastSeen
      description: Date last seen.
      type: Date
    - contextPath: GIBTIA.OSIVulnerability.datePublished
      description: Date published.
      type: Date
    - contextPath: GIBTIA.OSIVulnerability.description
      description: Vulnerability description.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.id
      description: Vulnerability ID.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.reporter
      description: Vulnerability reporter.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.title
      description: Vulnerability title.
      type: String
    - contextPath: GIBTIA.OSIVulnerability.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 26a05baa4025edff367b058b13c6b43e820538a5.
      name: id
      required: true
    description: Command performs Group IB event lookup in attacks/ddos collection with provided ID.
    name: gibti-get-attacks-ddos-info
    outputs:
    - contextPath: GIBTIA.AttacksDDoS.cnc.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.domain
      description: CNC domain.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.asn
      description: CNC ASN.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.countryName
      description: CNC IP country name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.ip
      description: CNC IP address.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.cnc.ipv4.region
      description: CNC region name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.asn
      description: DDoS target ASN.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.countryName
      description: DDoS target country name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.ip
      description: DDoS target IP address.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.ipv4.region
      description: DDoS target region name.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.category
      description: DDoS target category.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.target.domain
      description: DDoS target domain.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.threatActor.id
      description: Associated threat actor ID.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.AttacksDdos.threatActor.isAPT
      description: Is threat actor APT.
      type: Boolean
    - contextPath: GIBTIA.AttacksDDoS.id
      description: GIB incident ID.
      type: String
    - contextPath: GIBTIA.AttacksDDoS.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 6009637a1135cd001ef46e21.
      name: id
      required: true
    description: Command performs Group IB event lookup in attacks/deface collection with provided ID.
    name: gibti-get-attacks-deface-info
    outputs:
    - contextPath: GIBTIA.AttacksDeface.date
      description: Date of deface.
      type: Date
    - contextPath: GIBTIA.AttacksDeface.id
      description: GIB incident ID.
      type: String
    - contextPath: GIBTIA.AttacksDeface.targetIp.asn
      description: Victim ASN.
      type: String
    - contextPath: GIBTIA.AttacksDeface.targetIp.countryName
      description: Victim country name.
      type: String
    - contextPath: GIBTIA.AttacksDeface.targetIp.region
      description: Victim IP region name.
      type: String
    - contextPath: GIBTIA.AttacksDeface.threatActor.id
      description: Associated threat actor ID.
      type: String
    - contextPath: GIBTIA.AttacksDeface.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.AttacksDeface.threatActor.isAPT
      description: Is threat actor APT.
      type: Boolean
    - contextPath: GIBTIA.AttacksDeface.url
      description: URL of compromised resource.
      type: String
    - contextPath: GIBTIA.AttacksDeface.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 1b09d389d016121afbffe481a14b30ea995876e4.
      name: id
      required: true
    - name: isAPT
      auto: PREDEFINED
      predefined:
      - "true"
      - "false"
      description: Is threat APT.
      defaultValue: "false"
    description: Command performs Group IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.
    name: gibti-get-threat-info
    outputs:
    - contextPath: GIBTIA.Threat.contacts.account
      description: Threat accounts found in this threat action.
      type: String
    - contextPath: GIBTIA.Threat.contacts.flag
      description: Is account fake or not.
      type: String
    - contextPath: GIBTIA.Threat.contacts.service
      description: Account service.
      type: String
    - contextPath: GIBTIA.Threat.contacts.type
      description: Type of account(social_network/email/wallet etc.)
      type: String
    - contextPath: GIBTIA.Threat.countries
      description: Affected countries.
      type: String
    - contextPath: GIBTIA.Threat.createdAt
      description: Threat report creation date.
      type: Date
    - contextPath: GIBTIA.Threat.cveList.name
      description: List of abused CVE.
      type: String
    - contextPath: GIBTIA.Threat.dateFirstSeen
      description: Attack first seen date.
      type: Date
    - contextPath: GIBTIA.Threat.dateLastSeen
      description: Attack last seen date.
      type: Date
    - contextPath: GIBTIA.Threat.datePublished
      description: Date published.
      type: Date
    - contextPath: GIBTIA.Threat.description
      description: Threat description.
      type: String
    - contextPath: GIBTIA.Threat.forumsAccounts.url
      description: Related forum URL.
      type: String
    - contextPath: GIBTIA.Threat.forumsAccounts.nickname
      description: Related forums account.
      type: String
    - contextPath: GIBTIA.Threat.forumsAccounts.registeredAt
      description: Related forums account registration date.
      type: Date
    - contextPath: GIBTIA.Threat.forumsAccounts.messageCount
      description: Related forums messages count.
      type: Number
    - contextPath: GIBTIA.Threat.id
      description: GIB internal threat ID.
      type: String
    - contextPath: GIBTIA.Threat.indicators
      description: Can be either network or file indicators.
      type: String
    - contextPath: GIBTIA.Threat.langs
      description: Languages actors related.
      type: String
    - contextPath: GIBTIA.Threat.malwareList.name
      description: Related Malware Name.
      type: String
    - contextPath: GIBTIA.Threat.malwareList.id
      description: Related malware GIB internal ID.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.attackPatternId
      description: MITRE attack pattern ID.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.attackTactic
      description: MITRE attack tactic name.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.attackType
      description: MITRE attack type.
      type: String
    - contextPath: GIBTIA.Threat.mitreMatrix.id
      description: MITRE attack id.
      type: String
    - contextPath: GIBTIA.Threat.regions
      description: Regions affected by attack.
      type: String
    - contextPath: GIBTIA.Threat.reportNumber
      description: GIB report number.
      type: String
    - contextPath: GIBTIA.Threat.sectors
      description: Affected sectors.
      type: String
    - contextPath: GIBTIA.Threat.shortDescription
      description: Short description.
      type: String
    - contextPath: GIBTIA.Threat.title
      description: Threat title.
      type: String
    - contextPath: GIBTIA.Threat.targetedCompany
      description: Targeted company name.
      type: String
    - contextPath: GIBTIA.Threat.ThreatActor.name
      description: Threat actor name.
      type: String
    - contextPath: GIBTIA.Threat.ThreatActor.id
      description: Threat actor ID.
      type: String
    - contextPath: GIBTIA.Threat.ThreatActor.isAPT
      description: Is threat actor APT group.
      type: Boolean
    - contextPath: GIBTIA.Threat.sources
      description: Sources links.
      type: String
    - contextPath: GIBTIA.Threat.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB internal threatActor ID.
        e.g.: 0d4496592ac3a0f5511cd62ef29887f48d9cb545.
      name: id
      required: true
    - name: isAPT
      auto: PREDEFINED
      predefined:
      - "true"
      - "false"
      description: Is threat actor APT group.
      defaultValue: "false"
    description: Command performs Group IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.
    name: gibti-get-threat-actor-info
    outputs:
    - contextPath: GIBTIA.ThreatActor.aliases
      description: Threat actor aliases.
      type: String
    - contextPath: GIBTIA.ThreatActor.country
      description: Threat actor country.
      type: String
    - contextPath: GIBTIA.ThreatActor.createdAt
      description: Threat actor record creation time.
      type: Date
    - contextPath: GIBTIA.ThreatActor.description
      description: Threat actor description.
      type: String
    - contextPath: GIBTIA.ThreatActor.goals
      description: Threat actor goals sectors(financial, diplomatic, etc.)
      type: String
    - contextPath: GIBTIA.ThreatActor.id
      description: Threat actor id.
      type: String
    - contextPath: GIBTIA.ThreatActor.isAPT
      description: Threat actor is APT.
      type: Boolean
    - contextPath: GIBTIA.ThreatActor.labels
      description: GIB internal threat actor labels(hacker, nation-state, etc.)
      type: String
    - contextPath: GIBTIA.ThreatActor.langs
      description: Threat actor communication language.
      type: String
    - contextPath: GIBTIA.ThreatActor.name
      description: Threat actor name.
      type: String
    - contextPath: GIBTIA.ThreatActor.roles
      description: Threat actor roles.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.countries
      description: Threat actor countries activity found in.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.dateFirstSeen
      description: Date first seen.
      type: Date
    - contextPath: GIBTIA.ThreatActor.stat.dateLastSeen
      description: Date last seen.
      type: Date
    - contextPath: GIBTIA.ThreatActor.stat.regions
      description: Threat actor activity regions.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.reports.datePublished
      description: Related threat report publishing date.
      type: Date
    - contextPath: GIBTIA.ThreatActor.stat.reports.id
      description: Related threat report id.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.reports.name.en
      description: Related threat report language.
      type: String
    - contextPath: GIBTIA.ThreatActor.stat.sectors
      description: Sectors attacked by threat actor.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 109.70.100.46.
      name: id
      required: true
    description: Command performs Group IB event lookup in suspicious_ip/tor_node collection with provided ID.
    name: gibti-get-suspicious-ip-tor-node-info
    outputs:
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.asn
      description: Tor node ASN.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.countryName
      description: Tor node IP country name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.ip
      description: Tor node IP address.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.ipv4.region
      description: Tor node IP region name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.id
      description: GIB id.
      type: String
    - contextPath: GIBTIA.SuspiciousIPTorNode.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: cc6a2856da2806b03839f81aa214f22dbcfd7369.
      name: id
      required: true
    description: Command performs Group IB event lookup in suspicious_ip/open_proxy collection with provided ID.
    name: gibti-get-suspicious-ip-open-proxy-info
    outputs:
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.asn
      description: Proxy ASN.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.countryName
      description: Proxy IP country name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.ip
      description: Proxy IP address.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.region
      description: Proxy IP region name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.port
      description: Proxy port.
      type: Number
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.source
      description: Information source.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.ipv4.anonymous
      description: Proxy anonymous level.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.id
      description: GIB event ID.
      type: String
    - contextPath: GIBTIA.SuspiciousIPOpenProxy.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
        e.g.: 02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e.
      name: id
      required: true
    description: Command performs Group IB event lookup in suspicious_ip/socks_proxy collection with provided ID.
    name: gibti-get-suspicious-ip-socks-proxy-info
    outputs:
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.asn
      description: Proxy IP ASN.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.countryName
      description: Proxy IP country name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.ip
      description: Proxy IP address.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.ipv4.region
      description: Proxy IP region name.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.id
      description: GIB ID.
      type: String
    - contextPath: GIBTIA.SuspiciousIPSocksProxy.evaluation.severity
      description: Event severity.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments: []
    description: Returns list of available collections.
    name: gibti-get-available-collections
    outputs:
    - contextPath: GIBTIA.OtherInfo.collections
      description: List of availiable collections.
      type: String
  - arguments:
    - description: |-
        GIB event id.
        e.g.: aeed277396e27e375d030a91533aa232444d0089.
      name: id
      required: true
    description: Command performs Group IB event lookup in malware/cnc collection by provided ID.
    name: gibti-get-malware-cnc-info
    outputs:
    - contextPath: GIBTIA.MalwareCNC.dateDetected
      description: Date CNC detected.
      type: Date
    - contextPath: GIBTIA.MalwareCNC.dateLastSeen
      description: Date CNC last seen.
      type: Date
    - contextPath: GIBTIA.MalwareCNC.url
      description: CNC URL.
      type: String
    - contextPath: GIBTIA.MalwareCNC.domain
      description: CNC domain.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.asn
      description: CNC ASN.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.countryName
      description: CNC IP country name.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.ip
      description: CNC IP address.
      type: String
    - contextPath: GIBTIA.MalwareCNC.ipv4.region
      description: CNC region name.
      type: String
    - contextPath: GIBTIA.MalwareCNC.malwareList.name
      description: Associated malware.
      type: String
    - contextPath: GIBTIA.MalwareCNC.threatActor.id
      description: Associated threat actor ID.
      type: String
    - contextPath: GIBTIA.MalwareCNC.threatActor.name
      description: Associated threat actor.
      type: String
    - contextPath: GIBTIA.MalwareCNC.threatActor.isAPT
      description: Is APT or not.
      type: Boolean
    - contextPath: GIBTIA.MalwareCNC.id
      description: GIB event ID.
      type: String
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        Query you want to search.
        e.g.: 8.8.8.8.
      name: query
      required: true
    description: Command performs global Group IB search.
    name: gibti-global-search
    outputs:
    - contextPath: apiPath
      description: Name of collection in which found matches.
      type: String
    - contextPath: count
      description: Count of feeds matching this query.
      type: Number
    - contextPath: GIBLink
      description: Link to GIB TI&A interface.
      type: String
  - arguments:
    - description: |-
        Collection you want to search.
      name: collection_name
      required: true
      auto: PREDEFINED
      predefined:
      - compromised/account_group
      - compromised/bank_card_group
      - compromised/masked_card
      - compromised/breached
      - compromised/mule
      - compromised/spd
      - osi/git_repository
      - osi/public_leak
      - osi/vulnerability
      - attacks/ddos
      - attacks/deface
      - attacks/phishing_group
      - attacks/phishing_kit
      - suspicious_ip/tor_node
      - suspicious_ip/open_proxy
      - suspicious_ip/socks_proxy
      - suspicious_ip/vpn
      - suspicious_ip/scanner
      - malware/cnc
      - malware/malware
      - hi/threat
      - hi/threat_actor
      - apt/threat_actor
      - apt/threat
    - name: query
      required: true
      description: |-
        Query you want to search.
        e.g.: 8.8.8.8.
    - name: date_from
      description: Start date of search session.
    - name: date_to
      description: End date of search session.
    - name: requests_limit
      description: |-
        Maximum number of API requests (pages) sent to the collection.
        Default is 1 to keep the command deterministic and avoid long-running executions.
      defaultValue: "1"
    - name: page_size_limit
      description: |-
        Maximum number of entries per API response (page size).
        If not set, the service default will be used.
      defaultValue: "100"
    - name: seq_update
      description: |-
        Optional starting seqUpdate for update-based iteration.
        Warning: providing an old seqUpdate (or using 0) can cause very long executions.
    - name: include_raw_feed
      description: |-
        If set to true, include the full parsed feed object in outputs as 'raw_feed'.
        Use with caution: can increase context size.
      defaultValue: "false"
    description: Command performs Group IB search in selected collection.
    name: gibti-local-search
    outputs:
    - contextPath: GIBTI.search.local.id
      description: Id of a feed that matches a query.
      type: String
    - contextPath: GIBTI.search.local.additional_info
      description: Additional info about feed.
      type: String
    - contextPath: GIBTI.search.local.seqUpdate
      description: seqUpdate value of the page/portion that returned the feed.
      type: Number
    - contextPath: GIBTI.search.local.raw_feed
      description: One-line JSON string of the full feed for War Room rendering (only when include_raw_feed=true).
      type: String
  - arguments:
    - description: 'GIB event id.e.g.: 192.168.0.1.'
      name: id
    description: Command performs Group IB event lookup in suspicious_ip/vpn collection by provided ID.
    name: gibti-get-suspicious-ip-vpn-info
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - description: Command performs Group IB event lookup in suspicious_ip/scanner collection by provided ID.
    name: gibti-get-suspicious-ip-scanner-info
    arguments:
    - name: id
      description: 'GIB event id.e.g.: 192.168.0.1.'
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: 'GIB event id.e.g.: 653654fb986b47a31c73d92f4a20a273acd2f779.'
      name: id
    description: Command performs Group IB event lookup in malware/malware collection by provided ID.
    name: gibti-get-malware-malware-info
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/bank_card_group collection by provided ID.
    name: gibti-get-compromised-card-group-info
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: |-
        GIB event id.
      name: id
      required: true
    description: Command performs Group IB event lookup in compromised/masked_card collection by provided ID.
    name: gibti-get-compromised-masked-card-info
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  - arguments:
    - description: GIB event id.
      name: id
      required: true
    description: Command performs Group IB event lookup in attacks/phishing_group collection by provided ID.
    name: gibti-get-phishing-group-info
    compliantpolicies:
    - EndPoint Isolation
    - User Hard Remediation
  dockerimage: demisto/vendors-sdk:1.0.0.10120494
  feed: false
  isfetch: true
  longRunning: false
  longRunningPort: false
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- Group-IB Threat Intelligence -Test
fromversion: 6.0.0
sectionorder:
- Connect
- Collect