Skip to content

Add GTI/VirusTotal enrichment helpers - #2118

Merged
arielkr256 merged 5 commits into
developfrom
add-gti-virustotal-helpers
Jul 6, 2026
Merged

arielkr256 merged 5 commits into
developfrom
add-gti-virustotal-helpers

Conversation

@arielkr256

@arielkr256 arielkr256 commented Jul 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds panther_gti_helpers, a reusable enrichment helper for Google Threat Intelligence / VirusTotal lookup-table data (vt_iocs_iocstream), mirroring the existing panther_otx_helpers pattern (built on the shared LookupTableMatches base).
  • LUT auto-detection is signature-based (looks for gti_url/last_analysis_stats on matched values) since the VT LUT name is user-customizable.
  • Adds a companion Standard.GTI.MaliciousIndicator detection (created disabled/experimental) that flags events whose IP/domain/file-hash indicators match a malicious GTI/VT verdict.
  • 37 new unit tests for the helper (global_helpers/global_helpers_test.py::TestGTIIntelligence) plus 5 redacted rule tests (3 positive, 2 negative).

Test plan

  • make fmt && make lint && make test — all pass (1074 pat tests + global helper unit tests, 0 failures)
  • pipenv run python -m unittest global_helpers.global_helpers_test.TestGTIIntelligence — 37/37 pass
  • pipenv run panther_analysis_tool test --filter RuleID=Standard.GTI.MaliciousIndicator — 5/5 pass

THREAT-691

Adds panther_gti_helpers, a reusable enrichment helper for Google Threat
Intelligence / VirusTotal lookup-table data, mirroring the existing
panther_otx_helpers pattern. Includes a companion Standard.GTI.MaliciousIndicator
detection (disabled/experimental) and unit tests.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@arielkr256
arielkr256 requested review from a team as code owners July 1, 2026 17:05
@cursor

cursor Bot commented Jul 1, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Medium risk because this adds new threat-intelligence detection logic and changes matching behavior for GreyNoise/OTX multi-match enrichments. The new GTI rule is disabled and experimental, which limits immediate production impact.

Overview
Adds panther_gti_helpers for Google Threat Intelligence / VirusTotal lookup-table enrichment, including LUT auto-detection, verdict accessors, severity derivation, GTI links, alert context, and multi-match support.

Adds a disabled experimental Standard.GTI.MaliciousIndicator rule that alerts on malicious IPs, domains, and file hashes across common log types, with indexes and detection coverage updated to include it.

Also fixes list-shaped enrichment handling for GreyNoise and OTX: LUT auto-detection now recognizes multi-match entries, GreyNoise boolean fields no longer treat any non-empty list as true, and the GreyNoise malicious IP rule can alert when any matched classification is malicious or unknown.

Reviewed by Cursor Bugbot for commit b89e798. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread global_helpers/panther_gti_helpers.py Outdated
Comment thread rules/standard_rules/gti_malicious_indicator.py
- Auto-detect lookup-table enrichments even when Panther stores a
  matched value as a list of dicts (multiple LUT hits), not just a
  single dict. Backported the same fix to the OTX and GreyNoise
  helpers, which had the identical gap.
- Gate Standard.GTI.MaliciousIndicator on actual malicious signal
  (detection count or GTI threat severity) instead of mere presence
  in the GTI/VirusTotal feed, so known-benign indicators no longer
  trigger the rule.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Comment thread global_helpers/panther_greynoise_helpers.py
@arielkr256 arielkr256 added enhancement New feature or request lookup_table LookUpTables provide enrichment for Rules labels Jul 1, 2026
…stead of

  bool()) and routing all 7 call sites through it. Added regression tests confirming
  found()/is_bot()/etc. return False when every list entry is False, and True when
  any entry is True.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1464b21. Configure here.

Comment thread global_helpers/panther_greynoise_helpers.py
@arielkr256
arielkr256 enabled auto-merge July 6, 2026 15:22
@arielkr256
arielkr256 added this pull request to the merge queue Jul 6, 2026
Merged via the queue into develop with commit ae194f2 Jul 6, 2026
16 checks passed
@arielkr256
arielkr256 deleted the add-gti-virustotal-helpers branch July 6, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request lookup_table LookUpTables provide enrichment for Rules

3 participants