Explore OpenCTI or OpenAEV product with 30 days Free Trial!
XTM Hub by Filigran
LoginSign Up
Group-IB Threat Intelligence logo

Group-IB Threat Intelligence

Supported by community
Adversary & Campaign Insights
Vulnerability & Exploit Awareness
Fraud, Financial Crime & Cryptocurrency Monitoring

Overview

Imports Group-IB Threat Intelligence into OpenCTI: threat actor and APT profiles, malware and C2 infrastructure, IOCs, vulnerabilities, attack activity, compromised credentials and cards, and dark-web leaks.

The Group-IB connector imports threat intelligence from the Group-IB Threat Intelligence platform into OpenCTI via its API. It collects data on threat actors, intrusion sets, campaigns, malware and its command-and-control infrastructure, IOCs, vulnerabilities, phishing and DDoS activity, compromised credentials and payment cards, and dark-web and public-source leaks, built from 22+ years of cybercrime investigation and incident response. The connector pushes structured STIX objects into OpenCTI, enabling attribution, threat hunting, fraud monitoring and network protection workflows. Each collection is enabled and tuned independently, so a deployment ingests only the feeds it is licensed for. To use the integration, please ensure that you have an active Threat Intelligence license covering the API endpoints you intend to reach. Documentation can be found here - https://tap.group-ib.com/hc/api?scope=integrations&q=en%2FIntegrations%2FStarting%20Guide%2FInitial%20Steps%2FInitial%20Steps

Basic information

Group-IB Threat Intelligence
Vendor Contact
Connectors
7.260910.0
0
integration@group-ib.com

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".