Group-IB Threat Intelligence & Attribution
Pack helps to integrate Group-IB Threat Intelligence and get incidents directly into Cortex XSOAR. The list of included collections: Compromised Accounts, Compromised Cards, Compromised Masked Cards, Brand Protection Phishing, Brand Protection Phishing Kit, OSI Git Leak, OSI Public Leak, Targeted Malware.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- GroupIB_ThreatIntelligenceAttribution
Configuration parameters
- url — GIB TI URL (required)
- credentials — Username (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- integration_reliability — Source Reliability (required)
- disable_integration_reliability_override — Ignore Source Reliability override
- enabled_reputation_commands — Enable reputation commands
- isFetch — Fetch incidents
- incident_collections — Collections to fetch
- first_fetch — Incidents first fetch
- exclude_combolist — Exclude All with Combolist type
- combolist — Include combolist type in data
- unique — Include unique type in data
- enable_probable_corporate_access — Enable filter "Probable Corporate Access"
- max_fetch — Number of requests per collection
- skip_updated_incidents — Skip updated incidents (prevent duplicates)
- dedup_lookback_days — Deduplication lookback (days)
- limit — Limit (items per request)
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- hunting_rules — Hunting Rules
Commands (51)
- domain — Runs reputation on domains.
- file — Runs reputation on files.
- gibti-get-attacks-ddos-info — Command performs Group IB event lookup in attacks/ddos collection with provided ID.
- gibti-get-attacks-deface-info — Command performs Group IB event lookup in attacks/deface collection with provided ID.
- gibti-get-available-collections — Returns list of available collections.
- gibti-get-compromised-account-info — Command performs Group IB event lookup in compromised/account collection with provided ID.
- gibti-get-compromised-breached-info — Command performs Group IB event lookup in compromised/breached collection with provided ID.
- gibti-get-compromised-card-group-info — Command performs Group IB event lookup in compromised/bank_card_group collection by provided ID.
- gibti-get-compromised-masked-card-info — Command performs Group IB event lookup in compromised/masked_card collection by provided ID.
- gibti-get-compromised-mule-info — Command performs Group IB event lookup in compromised/mule collection with provided ID.
- gibti-get-compromised-spd-info — Command performs Group IB event lookup in compromised/spd (suspicious payment details) collection with provided ID.
- gibti-get-malware-cnc-info — Command performs Group IB event lookup in malware/cnc collection by provided ID.
- gibti-get-malware-malware-info — Command performs Group IB event lookup in malware/malware collection by provided ID.
- gibti-get-osi-git-leak-info — Command performs Group IB event lookup in osi/git_leak collection with provided ID.
- gibti-get-osi-public-leak-info — Command performs Group IB event lookup in osi/public_leak collection with provided ID.
- gibti-get-osi-vulnerability-info — Command performs Group IB event lookup in osi/vulnerability collection with provided ID.
- gibti-get-phishing-group-info — Command performs Group IB event lookup in attacks/phishing_group collection by provided ID.
- gibti-get-suspicious-ip-open-proxy-info — Command performs Group IB event lookup in suspicious_ip/open_proxy collection with provided ID.
- gibti-get-suspicious-ip-scanner-info — Command performs Group IB event lookup in suspicious_ip/scanner collection by provided ID.
- gibti-get-suspicious-ip-socks-proxy-info — Command performs Group IB event lookup in suspicious_ip/socks_proxy collection with provided ID.
- gibti-get-suspicious-ip-tor-node-info — Command performs Group IB event lookup in suspicious_ip/tor_node collection with provided ID.
- gibti-get-suspicious-ip-vpn-info — Command performs Group IB event lookup in suspicious_ip/vpn collection by provided ID.
- gibti-get-threat-actor-info — Command performs Group IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.
- gibti-get-threat-info — Command performs Group IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.
- gibti-global-search — Command performs global Group IB search.
- gibti-ip-scoring — Returns Group-IB scoring for IPs (numeric and DBotScore).
- gibti-local-search — Command performs Group IB search in selected collection.
- gibtia-get-attacks-ddos-info — Command performs Group IB event lookup in attacks/ddos collection with provided ID.
- gibtia-get-attacks-deface-info — Command performs Group IB event lookup in attacks/deface collection with provided ID.
- gibtia-get-available-collections — Returns list of available collections.
- gibtia-get-compromised-account-info — Command performs Group IB event lookup in compromised/account collection with provided ID.
- gibtia-get-compromised-breached-info — Command performs Group IB event lookup in compromised/breached collection with provided ID.
- gibtia-get-compromised-card-group-info — Command performs Group IB event lookup in compromised/bank_card_group collection by provided ID.
- gibtia-get-compromised-mule-info — Command performs Group IB event lookup in compromised/mule collection with provided ID.
- gibtia-get-compromised-spd-info — Command performs Group IB event lookup in compromised/spd (suspicious payment details) collection with provided ID.
- gibtia-get-malware-cnc-info — Command performs Group IB event lookup in malware/cnc collection by provided ID.
- gibtia-get-malware-malware-info — Command performs Group IB event lookup in malware/malware collection by provided ID.
- gibtia-get-osi-git-leak-info — Command performs Group IB event lookup in osi/git_leak collection with provided ID.
- gibtia-get-osi-public-leak-info — Command performs Group IB event lookup in osi/public_leak collection with provided ID.
- gibtia-get-osi-vulnerability-info — Command performs Group IB event lookup in osi/vulnerability collection with provided ID.
- gibtia-get-phishing-group-info — Command performs Group IB event lookup in attacks/phishing_group collection by provided ID.
- gibtia-get-suspicious-ip-open-proxy-info — Command performs Group IB event lookup in suspicious_ip/open_proxy collection with provided ID.
- gibtia-get-suspicious-ip-scanner-info — Command performs Group IB event lookup in suspicious_ip/scanner collection by provided ID.
- gibtia-get-suspicious-ip-socks-proxy-info — Command performs Group IB event lookup in suspicious_ip/socks_proxy collection with provided ID.
- gibtia-get-suspicious-ip-tor-node-info — Command performs Group IB event lookup in suspicious_ip/tor_node collection with provided ID.
- gibtia-get-suspicious-ip-vpn-info — Command performs Group IB event lookup in suspicious_ip/vpn collection by provided ID.
- gibtia-get-threat-actor-info — Command performs Group IB event lookup in hi/threat_actor (or in apt/threat_actor if the APT flag is true) collection with provided ID.
- gibtia-get-threat-info — Command performs Group IB event lookup in hi/threat (or in apt/threat if the APT flag is true) collection with provided ID.
- gibtia-global-search — Command performs global Group IB search.
- gibtia-local-search — Command performs Group IB search in selected collection.
- ip — Runs reputation on IPs.