It depends what you have in the group claims in your response.
If it is just the group names as shown then you can not set extractionRegEx at all (it defaults to null) or you can set it to an empty string ''.
What we’ve seen for some IdPs is that they return an LDAP-style cn=name,ou=unit,dc=domain style group name, in which case the regex would be something like: