Add GTI/VirusTotal enrichment helpers - #2118
Conversation
Adds panther_gti_helpers, a reusable enrichment helper for Google Threat Intelligence / VirusTotal lookup-table data, mirroring the existing panther_otx_helpers pattern. Includes a companion Standard.GTI.MaliciousIndicator detection (disabled/experimental) and unit tests. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
PR SummaryMedium Risk Overview Adds a disabled experimental Also fixes list-shaped enrichment handling for GreyNoise and OTX: LUT auto-detection now recognizes multi-match entries, GreyNoise boolean fields no longer treat any non-empty list as true, and the GreyNoise malicious IP rule can alert when any matched classification is Reviewed by Cursor Bugbot for commit b89e798. Bugbot is set up for automated code reviews on this repo. Configure here. |
- Auto-detect lookup-table enrichments even when Panther stores a matched value as a list of dicts (multiple LUT hits), not just a single dict. Backported the same fix to the OTX and GreyNoise helpers, which had the identical gap. - Gate Standard.GTI.MaliciousIndicator on actual malicious signal (detection count or GTI threat severity) instead of mere presence in the GTI/VirusTotal feed, so known-benign indicators no longer trigger the rule. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…stead of bool()) and routing all 7 call sites through it. Added regression tests confirming found()/is_bot()/etc. return False when every list entry is False, and True when any entry is True.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 1464b21. Configure here.

Summary
panther_gti_helpers, a reusable enrichment helper for Google Threat Intelligence / VirusTotal lookup-table data (vt_iocs_iocstream), mirroring the existingpanther_otx_helperspattern (built on the sharedLookupTableMatchesbase).gti_url/last_analysis_statson matched values) since the VT LUT name is user-customizable.Standard.GTI.MaliciousIndicatordetection (created disabled/experimental) that flags events whose IP/domain/file-hash indicators match a malicious GTI/VT verdict.global_helpers/global_helpers_test.py::TestGTIIntelligence) plus 5 redacted rule tests (3 positive, 2 negative).Test plan
make fmt && make lint && make test— all pass (1074 pat tests + global helper unit tests, 0 failures)pipenv run python -m unittest global_helpers.global_helpers_test.TestGTIIntelligence— 37/37 passpipenv run panther_analysis_tool test --filter RuleID=Standard.GTI.MaliciousIndicator— 5/5 passTHREAT-691