OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ

Enrichment of low-score IPv4 addresses

Detection & Response Enablement
A picture of RG9jdW1lbnQ6YWY3M2E5Y2EtOThiYS00ZTllLTlhNmItNWRhNmUyYWRlYTI2

概要

This playbook automates the enrichment and promotion of IPv4 addresses derived from low-confidence indicators.

Overview

This playbook automates the enrichment and promotion of IPv4 addresses derived from low-confidence indicators. It continuously monitors indicators scored between 20 and 25 — sitting in a grey zone where threat relevance is uncertain — resolves their underlying observables, isolates IPv4 addresses, enriches them via VirusTotal, and promotes the results back as formal indicators ready for operational use.

Use case: Reduce analyst workload on low-score indicator triage by automatically enriching and surfacing IPv4-based threats that may have been underscored at ingestion time.


Dependencies

TypeDetail
ConnectorVirusTotal enrichment connector — must be deployed and active in the target OpenCTI instance
Connector UUIDHardcoded as eff6a87a-0132-4c9a-80c4-51e6ddd699bemust be updated to match the client's connector instance ID
OpenCTI versionBuilt on 7.260609.0 — verify compatibility with the target instance version
Data streamRequires the internal OpenCTI data stream to be enabled and running
IndicatorsExisting or incoming indicators with x_opencti_score between 20 and 25, based on IPv4 observables

How to Use It

Setup:

  1. Import the .json file via Playbooks → Import in OpenCTI.
  2. Navigate to the playbook and open the VirusTotal enrichment step (Step 4).
  3. Replace the connector UUID with the one from your own VirusTotal connector instance — found under Data → Connectors.
  4. Review the score range (20–25) and adjust the gte/lte filter values if your scoring policy differs.
  5. Decide whether to enable create: true on the trigger if you also want to catch newly created indicators (currently only update events fire the playbook).
  6. Enable and start the playbook.

What to verify after importing:

  • The VirusTotal connector is running and its UUID matches the one set in Step 4.
  • The data stream is active and processing events.
  • canEnrollManually is set to true — use this to backfill existing low-score indicators on demand.
  • wrap_in_container is set to false — if your organisation tracks enrichment activity in reports or cases, consider switching this to true.

Expected Outcome

Once active, confirm the playbook is working by checking:

  • Playbook execution logs show triggered runs for indicators in the 20–25 score range.
  • IPv4 observables linked to those indicators appear with VirusTotal enrichment data (new relationships, labels, external references).
  • New Indicators of type IPv4-Addr are created or updated in the platform following enrichment.
  • The ingestion step completes without errors, making enriched indicators visible across the platform, exports, and downstream integrations.

Additional Detail

  • Manual enrollment (canEnrollManually: true) lets analysts push any existing indicator into the playbook on demand — useful for retroactive enrichment campaigns.
  • No container wrapping — enriched indicators land directly in the global dataset. If traceability matters (e.g. for audit or SOC workflows), wrap results in a report or case by toggling wrap_in_container: true.
  • Scope is intentionally narrow — only IPv4 addresses are processed. To extend coverage to IPv6, domains, or URLs, duplicate the filter and enrichment branch for each additional type.
  • Score range 20–25 targets the ambiguous middle ground — high enough to warrant investigation, low enough to not yet be actionable. Adjust to fit your confidence model.

基本情報

Filigran
Enzo Queiros Martins
2026年7月01日
10+
4

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。