Group-IB Threat Intelligence & Attribution Feed
Use Group-IB Threat Intelligence Feed integration to fetch IOCs from various Group-IB collections.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- GroupIB_ThreatIntelligenceAttribution
Configuration parameters
- url — GIB TI URL (required)
- credentials — Username (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feedIncremental — Incremental feed
- feed — Fetch indicators
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- feedFetchInterval — Feed Fetch Interval
- feedBypassExclusionList — Bypass exclusion list
- indicator_collections — Indicator collections
- indicators_first_fetch — Indicator first fetch
- requests_count — Number of requests per collection
- feedTags — Tags
- tlp_color — Traffic Light Protocol Color
- use_tlp_from_source — Use TLP from source (per indicator)
- limit — Limit (items per request)
- feedExpirationPolicy —
- feedExpirationInterval —
Commands (1)
- gibtia-get-indicators — Get limited count of indicators for specified collection and get all indicators from particular events by id.