Threat intelligence API / integrations
Tines
Three importable Tines stories built on the ThreatCluster API. Each one is a working starting point, not a demo: point it at your Slack, ticketing system or SIEM and it runs. Every API call in them was executed against the live API and every field path verified.
StoriesSource on GitHubMIT
Prerequisites
- A ThreatCluster API key. Every plan, including Free, has one: sign in, open Settings → API and select Generate API Key.
- A Tines tenant, any plan. The stories use only HTTP Request, Event Transform and Trigger actions, so nothing paid is needed.
Setup
- In Tines, add a Text credential named
threatclustercontaining the key. The stories reference it as{{ CREDENTIAL.threatcluster }}, so nothing is hard-coded in the story JSON. - Download a story from the repository and import it: Stories → Import → paste the JSON.
- Set the schedule on the first action, then edit the last action to point at your own tool.
The stories
- Ransomware sector watch (
ransomware-sector-watch.json): posts to Slack when a ransomware group lists a new victim in your sector. Daily, 1 credit a run. CallsGET /darkweb/ransomware/victimswithsectorand a one-daysince. - Exploited CVE triage (
exploited-cve-triage.json): opens a ticket for each critical or high CVE that gained a public exploit. Daily, 1 credit a run. CallsGET /vulnerabilitieswithhas_exploit=true. - IOC blocklist sync (
ioc-blocklist-sync.json): pushes validated indicators into a firewall, proxy or SIEM lookup. Every 4 hours, 3 credits a run. CallsGET /iocs/feedwithconfidence=confirmed.
Each is scheduled so its window matches its cadence: a daily run asks for one day of data. That keeps each listing seen once without client-side deduplication.
Worked example: the sector watch
The HTTP Request action in the first story:
URL https://threatcluster.io/api/public/v1/darkweb/ransomware/victims
Method GET
Headers X-API-Key: {{ CREDENTIAL.threatcluster }}
Query sector=Healthcare
since={{ DATE("now - 1 day", "%Y-%m-%dT%H:%M:%SZ") }}
limit=100 The response is a victims array. The Event Transform that follows explodes it to one event per listing, and the Slack action sends name, group, sector, country and url. The message says "listed by", not "breached by": a leak-site listing is the group's claim.
Worth knowing
- Leak-site listings are claims, not confirmed breaches. Keep that wording if you forward them outside the security team.
- The IOC feed defaults to
confidence=confirmed, which excludes unreviewed indicators. Do not loosen it on a feed you block on. - Free keys get 100 credits a day and read the last seven days. All three stories fit comfortably inside that; together they spend about 20 credits a day.
- The victims endpoint returns
groupandname. The vulnerabilities list does not carryaffected_vendors; that is on the detail record.
Building your own story? The curl guide documents every endpoint, header and status code, and the API reference has the response fields.