list_ioc_groups
Identify ransomware groups with indicators of compromise (IOCs) on file and view per-type counts. Filter by IOC type such as IP or domain to target specific threat intelligence.
Instructions
List ransomware groups that have IOCs on file, with per-type counts.
Common IOC types: md5, sha256, ip, domain, email, btc, url.
Args: ioc_type: Only return groups holding this IOC type, e.g. "ip".
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ioc_type | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||