Group-IB Threat Intelligence & Attribution Feed

Use Group-IB Threat Intelligence Feed integration to fetch IOCs from various Group-IB collections.

Data Enrichment & Threat Intelligence · Group-IB Threat Intelligence · Feed

Details

IDGroup-IB Threat Intelligence & Attribution Feed
ProviderGroup IB
CategoryData Enrichment & Threat Intelligence
From Version6.0.0
Docker Imagedemisto/vendors-sdk:1.0.0.10120494
Supported ModulesAgentix XSIAM

README

Group-IB Threat Intelligence Feed

Use Group-IB Threat Intelligence Feed integration to fetch IOCs (Indicators of Compromise) from various Group-IB collections. The integration supports multiple collections - see the Data Collections Overview section below for the complete list with descriptions and recommended date ranges (indicator first fetch).

Prerequisites

  1. Access Group-IB Threat Intelligence (TI) Web Interface
  2. Generate API Credentials
    • In the web interface, click your name in the upper right corner
    • Select ProfileSecurity and Access tab
    • Click Personal token and follow the instructions to generate your API token
    • Note: The API token serves as your password for authentication
  3. Network Configuration
    • Important: Contact Group-IB support to add your Cortex XSOAR server’s IP address to the allow list
    • If you are using a proxy, provide the public IP address of the proxy server instead
    • Make sure you have added Group-IB API IPs/URLs to your FW/Proxy rules.

Important Notes

Limit Parameter

The Limit (items per request) parameter specifies the number of records requested per API page. This limit applies to all collections configured in the integration instance.

Important considerations:

  • The limit determines how many records are fetched in a single API request. For example, if “Number of requests per collection” is set to 2 and the limit is 100, the integration will make 2 requests per collection, each requesting up to 100 records, resulting in up to 200 records per collection per fetch cycle.
  • Different collections may have different optimal limit values based on their data structure and API recommendations. We strongly recommend consulting the official API Limitations documentation for specific limit recommendations for each collection.
  • Best practice: Create separate integration instances for different collections or groups of collections that share similar optimal limit values. This allows you to optimize performance for each collection type.

Data Collections Overview

Once the configuration is complete, the following collections become available in Cortex XSOAR. For detailed information about each collection, its structure, and available fields, please refer to the official Collections Details documentation.

Note: If you’re using a POC or partner license, access to data is limited to 30 days. The recommended date ranges below are guidelines and can be adjusted according to your needs.

Collection Description Recommended Date Range
compromised/account_group In your compromised accounts, there CNCs in place which can be used as IOCs. Usually included in IOC Common. 2-4 years
compromised/bank_card_group In your compromised cards, there CNCs in place which can be used as IOCs. Usually included in IOC Common. 2 years
compromised/masked_card In masked card records, top-level CNC domain and IP values can be used as IOCs similarly to other compromised card collections. 2 years
compromised/mule Information on compromised accounts used by threat actors for money laundering and fund transfers. Collection is currently deprecated - only legacy information is available 90 days
attacks/ddos Data on Distributed Denial of Service (DDoS) attacks, including targeted resources and attack durations. 5-10 days
attacks/deface Records of defacement attacks, highlighting compromised websites and related actors. 5-10 days
attacks/phishing_group Information on phishing attacks, including URLs of phishing websites. Note: Do not use IPs for detection - it may cause many false positives. Focus only on URLs. 3-5 days
attacks/phishing_kit Collections of phishing website templates, scripts, and configurations used by attackers. 30 days
apt/threat IOCs only from APT reports. 2-4 years
hi/threat IOCs only from Cybercriminals reports. 2-4 years
ioc/common General indicators of Compromise (IoCs) from threat reports (Cybercriminals and APT) and Malware sections. Consists of Hashes (MD5, SHA1, SHA256), IPs, domains and URLs. Major source of IOCs. Contains: malware/malware, malware/cnc, hi/threat, apt/threat, hi/threat_actor, apt/threat_actor. 90 days
malware/cnc Information on malware Command-and-Control (C&C) servers used for data exfiltration and command distribution. This feed is also part of IOC Common. 90 days
osi/vulnerability Information on software vulnerabilities, associated exploits, and available proof-of-concept details. 90 days
suspicious_ip/tor_node Data about known Tor exit nodes used as anonymity relays. 5 days
suspicious_ip/open_proxy Information on publicly available proxy servers, including potentially misconfigured proxies. 5 days
suspicious_ip/scanner IP addresses identified as scanning or probing corporate networks. 5 days
suspicious_ip/socks_proxy IP addresses of infected hosts configured as SOCKS proxies used for anonymized attacks. 5 days
suspicious_ip/vpn Information about public and private VPN servers identified as potentially malicious or suspicious. 5 days

Configure Group-IB Threat Intelligence Feed in Cortex

Parameter Description Required
GIB TI URL The FQDN/IP the integration should connect to (default: https://tap.group-ib.com/api/v2/). True
Username Enter the email address you use to log into the web interface. The API token serves as your password for authentication. True
Trust any certificate (not secure) Whether to allow connections without verifying SSL certificates validity. False
Use system proxy settings Whether to use XSOAR system proxy settings to connect to the API. False
Fetches indicators Enable to fetch indicators from the feed (default: enabled). False
Indicator Reputation Select the default reputation for indicators from this feed (default: Suspicious). Options: Unknown, Benign, Suspicious, Malicious. As an example, it is recommended to use Malicious for IOC common and Suspicious for Suspicious IP collections. False
Source Reliability Select the reliability rating for the source (required, default: A - Completely reliable). Options: A - Completely reliable, B - Usually reliable, C - Fairly reliable, D - Not usually reliable, E - Unreliable, F - Reliability cannot be judged. True
Feed Fetch Interval Configure how often to fetch indicators (hours and minutes, default: 1 minute). False
Bypass exclusion list When enabled, bypasses the exclusion list for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. False
Indicator collections Select the collections you want to fetch indicators from. Read more about collections here. False
Indicator first fetch Specify the date range for initial data fetch (default: “3 days”). False
Number of requests per collection Number of API requests per collection in each fetch iteration (default: 2). Each request picks up to 100 (limit) objects with different amount of indicators. If you face runtime errors, lower the value. False
Limit (items per request) Specifies the number of records fetched per API request (default: 100). This limit applies to all collections in the instance. For optimal performance, check the official API Limitations documentation for recommended limit values per collection. Best practice: create separate integration instances for different collections or groups of collections with similar optimal limit values. False
Tags Enter tags for indicators if needed. False
Traffic Light Protocol Color Select the Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. Options: RED, AMBER, GREEN, WHITE. When Use TLP from source is disabled, this value is applied to all indicators. When Use TLP from source is enabled, this value is used only as a fallback when Group-IB does not provide TLP for an indicator. False
Use TLP from source (per indicator) When enabled, each indicator gets its TLP from Group-IB when the source provides it (see TLP per indicator for the list of collections). For ioc/common, TLP is always set to AMBER. The Traffic Light Protocol Color setting is then used only as a fallback when the source has no TLP. When disabled, all indicators use the single Traffic Light Protocol Color selected above. False
Indicator Expiration Method Configure how indicators expire. Options: Time Interval, Never Expire, When removed from the feed. False

Additional Resources

For detailed information about collections, their structure, available fields, and recommended date ranges, refer to the official Collections Details documentation.

For step-by-step configuration instructions including classifier and mapper setup, refer to the integration description file.

Traffic Light Protocol (TLP) per indicator

By default, the integration applies a single Traffic Light Protocol Color to all indicators (the one selected in the integration settings). If you want each indicator to keep the TLP value provided by Group-IB for that record, enable Use TLP from source (per indicator).

When Use TLP from source is enabled:

  • Collections that receive TLP from Group-IB (when the source provides it): compromised/account_group, compromised/bank_card_group, compromised/masked_card, attacks/ddos, attacks/deface, attacks/phishing_kit, attacks/phishing_group, apt/threat, hi/threat, osi/vulnerability, osi/git_repository, suspicious_ip/tor_node, suspicious_ip/open_proxy, suspicious_ip/socks_proxy, suspicious_ip/vpn, suspicious_ip/scanner.
  • ioc/common: TLP is always set to AMBER (Group-IB does not provide TLP for this collection).
  • If Group-IB does not provide TLP for an indicator, the Traffic Light Protocol Color setting is used as fallback for that indicator. So the integration-level TLP applies only when the source has no TLP for the given record.

When Use TLP from source is disabled: All indicators receive the same TLP from the Traffic Light Protocol Color setting.

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

gibti-get-indicators


Get a limited count of indicators for a specified collection and get all indicators from particular events by ID.

Base Command

gibti-get-indicators

Legacy alias gibtia-get-indicators remains available for backward compatibility.

Input

Argument Name Description Required
collection GIB Collection to get indicators from. Possible values are: compromised/mule, compromised/masked_card, compromised/imei, attacks/ddos, attacks/deface, attacks/phishing, attacks/phishing_kit, hi/threat, apt/threat, osi/vulnerability, suspicious_ip/tor_node, suspicious_ip/open_proxy, suspicious_ip/socks_proxy, malware/cnc. Required
id Incident ID to get indicators. If set, all indicators will be provided from the particular incident. Optional
limit Limit of indicators to display in War Room. Possible values are: 10, 20, 30, 40, 50. Default is 50. Optional

Command Example

!gibti-get-indicators collection=ioc/common

Configuration parameters

  • url — GIB TI URL (required)
  • credentials — Username (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • feedIncremental — Incremental feed
  • feed — Fetch indicators
  • feedReputation — Indicator Reputation
  • feedReliability — Source Reliability (required)
  • feedFetchInterval — Feed Fetch Interval
  • feedBypassExclusionList — Bypass exclusion list
  • indicator_collections — Indicator collections
  • indicators_first_fetch — Indicator first fetch
  • requests_count — Number of requests per collection
  • feedTags — Tags
  • tlp_color — Traffic Light Protocol Color
  • use_tlp_from_source — Use TLP from source (per indicator)
  • limit — Limit (items per request)
  • feedExpirationPolicy
  • feedExpirationInterval

Commands (1)

  • gibtia-get-indicators

    Get limited count of indicators for specified collection and get all indicators from particular events by id.

category: Data Enrichment & Threat Intelligence
provider: Group IB
commonfields:
  id: Group-IB Threat Intelligence & Attribution Feed
  version: -1
configuration:
- additionalinfo: The FQDN/IP the integration should connect to.
  defaultvalue: https://tap.group-ib.com/api/v2/
  display: GIB TI URL
  name: url
  required: true
  type: 0
  section: Connect
- additionalinfo: The API Key and Username required to authenticate to the service.
  display: Username
  name: credentials
  required: true
  type: 9
  section: Connect
- additionalinfo: Whether to allow connections without verifying SSL certificates validity.
  display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
  section: Connect
- additionalinfo: Whether to use XSOAR system proxy settings to connect to the API.
  display: Use system proxy settings
  name: proxy
  type: 8
  required: false
  section: Connect
- additionalinfo: Incremental feeds pull only new or modified indicators that have been sent from the integration. The determination if the indicator is new or modified happens on the 3rd-party vendor's side, so only indicators that are new or modified are sent to Cortex XSOAR. Therefore, all indicators coming from these feeds are labeled new or modified.
  defaultvalue: 'true'
  display: Incremental feed
  hidden: true
  name: feedIncremental
  type: 8
  required: false
  section: Collect
- defaultvalue: 'true'
  display: Fetch indicators
  name: feed
  type: 8
  required: false
  section: Collect
- additionalinfo: Indicators from this integration instance will be marked with this reputation
  defaultvalue: Suspicious
  display: Indicator Reputation
  name: feedReputation
  options:
  - None
  - Good
  - Suspicious
  - Bad
  type: 18
  required: false
  section: Collect
- additionalinfo: Reliability of the source providing the intelligence data
  defaultvalue: A - Completely reliable
  display: Source Reliability
  name: feedReliability
  options:
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  required: true
  type: 15
  section: Collect
- defaultvalue: '1'
  display: Feed Fetch Interval
  name: feedFetchInterval
  type: 19
  required: false
  section: Collect
- additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system.
  display: Bypass exclusion list
  name: feedBypassExclusionList
  type: 8
  required: false
  section: Collect
- additionalinfo: Collections List to include for fetching.
  display: Indicator collections
  name: indicator_collections
  options:
  - compromised/account_group
  - compromised/bank_card_group
  - compromised/masked_card
  - compromised/mule
  - attacks/ddos
  - attacks/deface
  - attacks/phishing_kit
  - attacks/phishing_group
  - hi/threat
  - apt/threat
  - osi/vulnerability
  - osi/git_repository
  - suspicious_ip/tor_node
  - suspicious_ip/open_proxy
  - suspicious_ip/socks_proxy
  - suspicious_ip/vpn
  - suspicious_ip/scanner
  - malware/cnc
  - ioc/common
  type: 16
  required: false
  hidden: false
  section: Collect
- additionalinfo: Date to start fetching indicators from.
  defaultvalue: 3 days
  display: Indicator first fetch
  name: indicators_first_fetch
  type: 0
  required: false
  hidden: false
  section: Collect
- additionalinfo: A number of requests per collection that integration sends in one fetch iteration (each request picks up to 200 objects with different amount of indicators). If you face some runtime errors, lower the value.
  defaultvalue: '2'
  display: Number of requests per collection
  section: Collect
  name: requests_count
  options:
  - '1'
  - '2'
  - '3'
  - '4'
  - '5'
  type: 15
  required: false
  hidden: false
- additionalinfo: Supports CSV values.
  display: Tags
  section: Collect
  name: feedTags
  type: 0
  required: false
- additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed
  display: Traffic Light Protocol Color
  name: tlp_color
  section: Collect
  options:
  - RED
  - AMBER
  - GREEN
  - WHITE
  type: 15
  required: false
- display: 'Use TLP from source (per indicator)'
  name: use_tlp_from_source
  type: 8
  section: Collect
  defaultvalue: 'false'
  required: false
  additionalinfo: When enabled, each indicator gets its TLP from Group-IB when the source provides it. For ioc/common, TLP defaults to AMBER. The Traffic Light Protocol Color setting is then used only as a fallback when the source has no TLP. When disabled, all indicators use the selected Traffic Light Protocol Color.
- display: 'Limit (items per request)'
  name: limit
  type: 0
  section: Collect
  defaultvalue: '100'
  required: false
  additionalinfo: Number of items requested per API page. Larger values reduce API round-trips but may increase response size. Server-side caps may apply.
- display: ''
  name: feedExpirationPolicy
  type: 17
  section: Collect
  options:
  - never
  - interval
  - indicatorType
- display: ''
  name: feedExpirationInterval
  type: 1
  required: false
  section: Collect
description: Use Group-IB Threat Intelligence Feed integration to fetch IOCs from various Group-IB collections.
display: Group-IB Threat Intelligence Feed
name: Group-IB Threat Intelligence & Attribution Feed
script:
  commands:
  - arguments:
    - auto: PREDEFINED
      description: GIB Collection to get indicators from.
      name: collection
      predefined:
      - compromised/account_group
      - compromised/bank_card_group
      - compromised/masked_card
      - compromised/mule
      - attacks/ddos
      - attacks/deface
      - attacks/phishing_kit
      - attacks/phishing_group
      - hi/threat
      - apt/threat
      - osi/vulnerability
      - osi/git_repository
      - suspicious_ip/tor_node
      - suspicious_ip/open_proxy
      - suspicious_ip/socks_proxy
      - suspicious_ip/vpn
      - suspicious_ip/scanner
      - malware/cnc
      - ioc/common
      required: true
      default: false
      isArray: false
      secret: false
    - description: Incident Id to get indicators(if set, all the indicators will be provided from particular incident).
      name: id
      default: false
      isArray: false
      required: false
      secret: false
    - auto: PREDEFINED
      default: true
      defaultValue: '50'
      description: Limit of indicators to display in War Room.
      name: limit
      predefined:
      - '10'
      - '20'
      - '30'
      - '40'
      - '50'
      isArray: false
      required: false
      secret: false
    description: Get limited count of indicators for specified collection and get all indicators from particular events by id.
    name: gibtia-get-indicators
    deprecated: false
    execution: false
  dockerimage: demisto/vendors-sdk:1.0.0.10120494
  feed: true
  runonce: false
  script: '-'
  subtype: python3
  type: python
  isfetch: false
  longRunning: false
  longRunningPort: false
tests:
- No tests (auto formatted)
fromversion: 6.0.0
sectionorder:
- Connect
- Collect