OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ

Label Indicators Unique and Shared

Data & Administration Health
A picture of RG9jdW1lbnQ6ZTM1MDRkYzctZTRiOS00ZTNkLWEzYjctMDFhMDRlYzU4MDQz

概要

Immediately highlight which IOCs have been ingested from a single source

  1. Overview

This playbook automatically classifies Indicators based on how many threat intelligence feeds contributed them. When a new or updated Indicator is ingested, the playbook checks whether it was created exclusively by one of up to four configured feeds. If so, it applies a unique label to that Indicator. If the Indicator was not exclusively created by any single feed — meaning it was seen across multiple feeds — it receives a shared-indicators label instead.

This supports feed quality analysis and deduplication workflows, allowing analysts and dashboards to quickly distinguish high-confidence, single-source indicators from those corroborated by multiple feeds.

  1. Dependencies

Detail

This playbook requires you to set the identity of your threat feeds that ingest IOCs.

This playbook (and accompanying dashboard and playbook) require you to have two labels in your platform.

  • 'unique' label - A label named unique must exist in the platform before activation.
  • 'shared-indicators' label - A label named shared-indicators must exist in the platform before activation.

Companion playbook (Remove Unique Label - Shared Indicator Clean up) is required to remove unique label when more than one feed creator is added to an IOC.

Companion custom dashboard Threat Intelligence Quality Dashboard - A custom dashboard that filters on the shared-indicators label is expected to accompany this playbook. The label name must be shared-indicators (plural) for the dashboard to function correctly.

  1. How to Use It

A. Import and Configure In OpenCTI, navigate to Automations → Playbooks and select Import. Upload the playbook JSON file. The playbook will import in a disabled state. Open the playbook and locate the four Apply Unique Label nodes (Feed 1 through Feed 4). In each node, replace the placeholder with the creator for your IOC feeds. In the same four nodes, replace the placeholder REPLACE-WITH-UNIQUE-LABEL-ID with your unique label.

Locate the Apply Shared-Indicators Label node. Replace the placeholder REPLACE-WITH-SHARED-INDICATORS-LABEL-ID with the shared-indicators label.

If you have more than four feeds please add additional 'Manipulate knowledge' and 'Send for ingestion' nodes to the playbook.

If you have fewer than four feeds, remove the unused Apply Unique Label and Send to Knowledge node pairs from the chain. Please be aware you will then need to recreate the remaining nodes in sequence so you may need to refer to the original file to set the

B. Activate the Playbook

Once all placeholders have been replaced, click Start to activate the playbook. No ongoing manual interaction is required. The playbook runs automatically on all new and updated Indicator events.

C. Expected Outcome Once active, every Indicator ingested or updated on the platform will be evaluated and labelled with either Unique or Shared-Indicators. This will enable you to be able to analyse in the accompanying dashboard the number of IOCs that are uniqure from each feed.

You can confirm the playbook is working by:

Opening a recently ingested Indicator and checking its Labels field for either unique or shared-indicators. Viewing the playbook's execution history in Automations → Playbooks to confirm nodes are being triggered. Checking the companion custom dashboard for populated shared-indicators data.

  1. Additional Detail

This playbook will also required

Indicators from unconfigured feeds: If an Indicator is created by a feed that is not one of the four configured feeds, it will pass through all four Manipulate Knowledge nodes unmodified and receive the shared-indicators label. This is by design — the catch-all path treats any unrecognised source as shared. Be aware that this means single-source indicators from feeds not included in the configuration will be incorrectly labelled as shared-indicators. To resolve this, simply extend the playbook to categorise those feeds correctly.

Performance Considerations This playbook triggers on all Indicator create and update events across the platform. In high-volume environments with large numbers of Indicator ingestion feeds, this may generate significant playbook execution volume. Consider whether the update trigger is necessary for your use case — disabling it (setting update: false on the trigger node) will reduce execution volume at the cost of not re-evaluating Indicators that are updated after initial ingestion.

基本情報

Filigran
Antoine Martins
2026年7月08日
10+
0

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。