Group-IB Threat Intelligence
概要
Imports Group-IB Threat Intelligence into OpenCTI: threat actor and APT profiles, malware and C2 infrastructure, IOCs, vulnerabilities, attack activity, compromised credentials and cards, and dark-web leaks.
The Group-IB connector imports threat intelligence from the Group-IB Threat Intelligence platform into OpenCTI via its API. It collects data on threat actors, intrusion sets, campaigns, malware and its command-and-control infrastructure, IOCs, vulnerabilities, phishing and DDoS activity, compromised credentials and payment cards, and dark-web and public-source leaks, built from 22+ years of cybercrime investigation and incident response. The connector pushes structured STIX objects into OpenCTI, enabling attribution, threat hunting, fraud monitoring and network protection workflows. Each collection is enabled and tuned independently, so a deployment ingests only the feeds it is licensed for. To use the integration, please ensure that you have an active Threat Intelligence license covering the API endpoints you intend to reach. Documentation can be found here - https://tap.group-ib.com/hc/api?scope=integrations&q=en%2FIntegrations%2FStarting%20Guide%2FInitial%20Steps%2FInitial%20Steps