Overview
Group-IB Threat Intelligence introduction
Group-IB Threat Intelligence introduction

Product video
Group-IB Threat Intelligence
Group-IB Threat Intelligence is a cyber threat intelligence platform that combines automated collection across open, technical, and criminal sources with human analyst intelligence gained through formal cooperation agreements with INTERPOL, Europol, and AFRIPOL. Delivered through the Group-IB Unified Risk Platform, it aggregates intelligence from ISP-level sensors, honeypot networks, dark web forums, instant messaging channels (Telegram, Discord), malware detonation infrastructure, C&C server tracking, and compromised data repositories.
Intelligence Layers
Strategic Intelligence Informs executive decision-making and long-term threat landscape understanding through regular analyst-written reports tailored to your industry and region.
Operational Intelligence Covers threat actor profiles, attack campaigns, and kill chain reconstruction in MITRE ATT&CK format - enabling security teams to build detection logic and response playbooks aligned with real adversary behaviors.
Tactical Intelligence Delivers continuously updated indicators of compromise (IPs, domains, file hashes, URLs) that can be automatically ingested into network and endpoint controls to block threats at the moment of first observation worldwide.
Prevyn AI - Agentic Intelligence
Group-IB's agentic AI solution, Prevyn AI, is an orchestrated multi-agent system consisting of 11 specialized, domain-expert agents that autonomously conduct adversary-focused research, malware attribution, and dark web monitoring. Prevyn AI Command orchestrates these agents to execute complex, multi-step threat research, identify attacker intent, and track infrastructure staging automatically. The system evaluates campaign indicators and maps them to active adversarial TTPs to predict threats before they launch. An integrated AI Assistant allows analysts to instantly query CVEs, track emerging threat actor profiles, and map indicators to the MITRE ATT&CK framework.
Key Capabilities
- Structured threat actor attribution with full TTP and infrastructure profiling
- Dark web monitoring across forums, markets, paste sites, and messenger channels
- Compromised credential and payment card detection with automated alerts before data is weaponized
- Suspicious IP intelligence covering VPN, proxy, SOCKS, Tor, and scanner nodes used by adversaries, for attribution and enrichment of internal alerts
- Suspicious payment details (SPD) feeds for integration with transaction-monitoring systems to detect fraud
- Investigative Graph interface for mapping relationships between actors, tools, and infrastructure
- Incident Management Center for structuring external threats into a trackable workflow: define incidents, automate detection rules, and manage threats end-to-end within the platform
- Malware file detonation and reverse engineering
- Vulnerability tracking cross-referenced against active exploitation activity targeting your industry
Security and Compliance
Group-IB Global Private Limited holds ISO/IEC 27001:2022 certification issued by TUV AUSTRIA GMBH (Certificate Registration No. TA420243018927, valid until 2027-07-01). The certification scope covers the Threat Intelligence solution, Fraud Protection platform, and information security Audit and Consulting services. For certificate details, visit https://www.group-ib.com/resources/certificates/
Industry Use Case: Financial Services
A financial services SOC subscribes to Group-IB Threat Intelligence and configures Threat Hunting Rules for their card BIN ranges and corporate domains. When compromised payment card data linked to their institution appears on a dark web market, the platform generates an automated alert. The SOC analyst uses the Graph interface to trace the breach to a specific JS-sniffer campaign, reviews the threat actor profile mapped to MITRE ATT&CK techniques, and deploys blocking rules to their SIEM. CERT-GIB initiates a takedown of the phishing domains used in the campaign.
Integrations and Deployment
Group-IB Threat Intelligence supports unlimited users and API calls under a single annual subscription. Out-of-the-box integrations support SIEM, SOAR, EDR, and TIP platforms including Splunk, with STIX/TAXII data transfer for custom integrations. Available via AWS Marketplace, the platform is suited for organizations running security operations on AWS infrastructure.
Analyst Recognition
The platform is recognized by Gartner (included in the 2023 Market Guide for Security Threat Intelligence Products and Services), Forrester, IDC, Datos Insights, KuppingerCole, and Frost & Sullivan.
Evaluation
For a proof of concept or personalized demo showing intelligence relevant to your industry and region, contact the Group-IB team through the AWS Marketplace listing or visit https://www.group-ib.com/products/threat-intelligence/ to learn more.
Highlights
- Intelligence from inside the adversary's world: Proprietary, closed-source data gathered by human experts through years of embedded access to criminal communities, undercover sources, malware analysis, and law enforcement collaboration. This is the foundation for attribution and adversary tracking of exceptional depth.
- Know your adversary, mapped to MITRE ATT&CK: Structured profiles of the threat actors targeting your industry, covering their tools, tactics, techniques, and infrastructure, reconstructed across the full kill chain and mapped to MITRE ATT&CK for direct use in detection and response.
- Enterprise scale, no per-seat limits: A single subscription covers unlimited users, out-of-the-box SIEM, SOAR, EDR, and TIP integrations including Splunk, and STIX/TAXII transfer, backed by a dedicated team of Group-IB analysts.
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/36 months |
|---|---|---|
Group-IB Threat Intelligence | Modules and terms defined in private offer | $1,830,000.00 |
Vendor refund policy
Parties will negotiate in good faith any necessary amendments to this Agreement to address the change. If the Parties are unable to reach an agreement, and a governmental or regulatory authority has determined that continuing to perform as currently required would violate the law then either Party may upon written notice terminate this Agreement without penalty
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Group-IB provides 24/7 global support for Threat Intelligence customers, with direct access to product specialists, threat analysts, and a dedicated account team across all regions.
Support Channels:
- APAC: +65 3159 4398
- Europe and North America: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
- Email: info@group-ib.com
- Slack: Dedicated channel with your support team (provisioned at onboarding)
- Website: https://www.group-ib.com/products/threat-intelligence/
Onboarding Process and Time-to-Value:
- Subscribe via AWS Marketplace and receive platform credentials instantly
- Provide your monitored domains, BIN ranges, and SIEM/SOAR endpoint details
- Onboarding team configures Threat Hunting Rules tailored to your organization
- Integration support connects your SIEM, SOAR, TIP, or custom STIX/TAXII feeds
- Ongoing refinement of intelligence filters with your dedicated analyst team
Buyer prerequisites: Prepare a list of monitored domains, card BIN ranges (if applicable), and integration endpoint URLs or API tokens for your SIEM/SOAR/TIP platforms before onboarding begins.
What is Included:
- Onboarding assistance and integration configuration support
- Analyst access for custom intelligence requests and briefings
- Threat Hunting Rule creation and continuous refinement
- Managed Threat Intelligence Specialist Service for custom RFIs, malware reverse engineering, threat enrichment, and ransomware data analysis
- Dark Web Feed Monitoring Service with customized reports
Requesting Assistance: For product issues, integration troubleshooting, custom intelligence requests, or subscription and billing inquiries including refunds, contact the support team via phone, email, or your dedicated Slack channel. Your dedicated account team is available to assist with any platform-related needs.
For a proof of concept or demo, contact the sales team through the AWS Marketplace listing or the website link above.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Completely satisfied with the way the report is prepared and easy to setup
What is our primary use case?
I used it to build the strategic threat forecast. The annual forecast for clients.
How has it helped my organization?
We did use it for threat detection, but not directly. I analyze multiple reports, including this one, and assess my client's infrastructure. I identify threats outlined in the reports that may be relevant to the client's infrastructure, and then I help them build detection use cases.
There's no automation. We don't do anything automatically at this point. It's all manual and based on analysis. I can't integrate it into automatic feeds because the report outlines threats that may not be relevant to the client's infrastructure. So, I do the analysis and integrate it manually.
I'm completely satisfied with the way the report is prepared. It's a good report.
What is most valuable?
The totality of the recordings is quite important. The networks, the new threat actors, the new methods, tactics, techniques, and procedures. The most important is the forecast. It's how the reports depict what's coming.
What needs improvement?
As the landscape evolves, they could provide a little more detail or specificity to map it to the MITRE ATT&CK framework. Even though it is done in the report, it could be done better.
For how long have I used the solution?
I used it for four years, since 2020. But recently, I stopped using it.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten. Ten means outstanding, so I don't give ten for anything.
There is always some room for improvement, but I have had no big issues or troubles with stability.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. It is quite good. I would recommend it for medium and large-sized companies.
I wouldn't recommend it for small companies because their infrastructure is not large enough.
How are customer service and support?
I never needed it.
Which solution did I use previously and why did I switch?
I find it more relevant than others. Some reports are vague or irrelevant with too much information.
For example, I use CrowdStrike and some other vendors, but I think Group-IB's report is more specific. I am happy with the report.
How was the initial setup?
The initial setup is straightforward. I had no issues with that.
What's my experience with pricing, setup cost, and licensing?
The pricing is alright. It's right on the mark. It costs money, but it's not too high. It's reasonable.
For me, it's a reasonable price for the quality of the product.
What other advice do I have?
Overall, I would rate the solution a nine out of ten.
I would recommend using it.
Easy to setup, highly stable and scalable and efficiently tracks threat actors and analyze their tactics
What is our primary use case?
We use Group-IB Threat Intelligence to help us with threat hunting, incident response, and vulnerability management.
What is most valuable?
We have found the site intelligence features to be the most valuable. We are able to use these features to track threat actors and analyze their tactics, techniques, and procedures (TTPs).
What needs improvement?
The dark web intelligence could be improved. It is not as good as the intelligence from other solutions.
For how long have I used the solution?
I have about four months of experience with this solution. We use its XDR and Set Intelligence solutions.
We work with the latest version of Group-IB XDR. We are also using the cloud-based version of Set Intelligence.
What do I think about the stability of the solution?
I would rate the stability of Group-IB Threat Intelligence as a ten. It is very stable.
What do I think about the scalability of the solution?
I would rate the scalability of Group-IB Threat Intelligence as a ten. It is very scalable.
About ten users are using Group-IB Threat Intelligence in our company. It is used daily in our organization.
How are customer service and support?
It is very good.
Which solution did I use previously and why did I switch?
We switched to Group-IB Threat Intelligence because it is better than the other solutions we evaluated.
How was the initial setup?
I would rate my experience with the initial setup as a ten. It was very easy to set up.
It is a proof of concept (POC), so we have not deployed it for production yet.
Which other solutions did I evaluate?
What other advice do I have?
I would rate Group-IB Threat Intelligence as an eight out of ten. It is a very good solution.
Has sandbox features but needs to improve integration for SOAR and SEIM solutions
What is our primary use case?
The solution acts as a defense against cyber incidents.
What is most valuable?
The tool's most valuable feature is the sandbox.
What needs improvement?
Group-IB Threat Intelligence should improve integration for SIEM and SOAR solutions.
For how long have I used the solution?
I have been using the solution for four years.
What do I think about the stability of the solution?
Group-IB Threat Intelligence is very stable. I rate it a nine out of ten.
What do I think about the scalability of the solution?
We have an enterprise license and unlimited scalability. My company has 10 users.
How was the initial setup?
The tool's deployment is easy. I rate it an eight out of ten. The deployment took a day to complete. You need to feed the public IPs to get whitelisted.
What's my experience with pricing, setup cost, and licensing?
Group-IB Threat Intelligence's pricing is reasonable.
What other advice do I have?
I rate the tool an eight out of ten.