Group-IB Threat Intelligence (TI) is a system for analyzing and attributing cyberattacks, threat hunting, and protecting network infrastructure based on data relating to adversary tactics, tools, and activity. Read more on the Group-IB website: https://www.group-ib.com/products/threat-intelligence.
Threat Intelligence combines unique data sources and experience in investigating high-tech crimes and responding to complex multi-stage attacks worldwide. The system stores data on threat actors and related infrastructures collected since 2003, including those that criminals attempted to wipe out. This application integrates Group-IB Threat Intelligence with Splunk to consume TI feeds, run targeted detections, and pivot from a single indicator across all Group-IB collections.
This Splunk integration allows you to:
- Import and process Threat Intelligence feeds directly into Splunk as structured events, across 30+ Group-IB collections.
- Search and correlate IoCs from Group-IB collections against your own data.
- Score and enrich indicators (IP, domain, hash, URL) on demand with live Group-IB risk scores and threat context.
- Run targeted detections and pivot from any indicator across all granted collections in real time.
- Enrich internal alerts with external intelligence, and sync attacker infrastructure to Splunk Enterprise Security.
To use this integration, you must have an active Group-IB Threat Intelligence license and API access.
Need automated response actions? Pair this application with the Group-IB Threat Intelligence app for Splunk SOAR - https://splunkbase.splunk.com/app/5968.
The SOAR connector covers playbook-driven enrichment, case management, and bidirectional updates against the Group-IB portal.