Skip to content

Threat intelligence API / integrations

Tines

Three importable Tines stories built on the ThreatCluster API. Each one is a working starting point, not a demo: point it at your Slack, ticketing system or SIEM and it runs. Every API call in them was executed against the live API and every field path verified.

StoriesSource on GitHubMIT

Prerequisites

  1. A ThreatCluster API key. Every plan, including Free, has one: sign in, open Settings → API and select Generate API Key.
  2. A Tines tenant, any plan. The stories use only HTTP Request, Event Transform and Trigger actions, so nothing paid is needed.

Setup

  1. In Tines, add a Text credential named threatcluster containing the key. The stories reference it as {{ CREDENTIAL.threatcluster }}, so nothing is hard-coded in the story JSON.
  2. Download a story from the repository and import it: Stories → Import → paste the JSON.
  3. Set the schedule on the first action, then edit the last action to point at your own tool.

The stories

  1. Ransomware sector watch (ransomware-sector-watch.json): posts to Slack when a ransomware group lists a new victim in your sector. Daily, 1 credit a run. Calls GET /darkweb/ransomware/victims with sector and a one-day since.
  2. Exploited CVE triage (exploited-cve-triage.json): opens a ticket for each critical or high CVE that gained a public exploit. Daily, 1 credit a run. Calls GET /vulnerabilities with has_exploit=true.
  3. IOC blocklist sync (ioc-blocklist-sync.json): pushes validated indicators into a firewall, proxy or SIEM lookup. Every 4 hours, 3 credits a run. Calls GET /iocs/feed with confidence=confirmed.

Each is scheduled so its window matches its cadence: a daily run asks for one day of data. That keeps each listing seen once without client-side deduplication.

Worked example: the sector watch

The HTTP Request action in the first story:

URL     https://threatcluster.io/api/public/v1/darkweb/ransomware/victims
Method  GET
Headers X-API-Key: {{ CREDENTIAL.threatcluster }}
Query   sector=Healthcare
        since={{ DATE("now - 1 day", "%Y-%m-%dT%H:%M:%SZ") }}
        limit=100

The response is a victims array. The Event Transform that follows explodes it to one event per listing, and the Slack action sends name, group, sector, country and url. The message says "listed by", not "breached by": a leak-site listing is the group's claim.

Worth knowing

  1. Leak-site listings are claims, not confirmed breaches. Keep that wording if you forward them outside the security team.
  2. The IOC feed defaults to confidence=confirmed, which excludes unreviewed indicators. Do not loosen it on a feed you block on.
  3. Free keys get 100 credits a day and read the last seven days. All three stories fit comfortably inside that; together they spend about 20 credits a day.
  4. The victims endpoint returns group and name. The vulnerabilities list does not carry affected_vendors; that is on the detail record.

Building your own story? The curl guide documents every endpoint, header and status code, and the API reference has the response fields.