Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | GTIVulnerabilitiesConnector |
| Publisher | |
| Used in Solutions | Google Threat Intelligence |
| Collection Method | CCF |
| Connector Definition Files | GTIVulnerabilities_ConnectorDefinition.json |
| DCR Definition Files | GTIVulnerabilities_DCR.json |
| CCF Configuration | GTIVulnerabilities_PollerConfig.json |
| CCF Capabilities | APIKey, Paging |
The Google Threat Intelligence (GTI) Vulnerabilities data connector ingests Vulnerability collection objects from the Google Threat Intelligence (VirusTotal) Collections API into Microsoft Sentinel using the Codeless Connector Framework (CCF) — no Azure Function or agent to deploy.
The connector authenticates with your GTI API key (sent in the x-apikey header), always scopes the query to collection_type:vulnerability, sorts by last modification date ascending (firstly-modified objects first), and polls on a rolling time window so each cycle only retrieves vulnerabilities modified since the previous poll. An optional free-form filter can be supplied to refine the search (for example risk_rating:Critical, cvss_3x_base_score:4+).
Ingested data lands in the GTI_Vulnerabilities_CL table and supports DCR-based ingestion-time transformations so enriched fields (risk rating, CVSS scores, exploitation state) are available for fast querying.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
GTI_Vulnerabilities_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Prerequisites
Before you connect, make sure the following are in place.
x-apikey header on every request.1. Generate your Google Threat Intelligence API key
Obtain the API key the connector uses to authenticate.
The same key is documented in the GTI reference under List vulnerabilities.
ℹ️ Keep your API key secret. Anyone with the key can query the GTI API as you and consume your quota. If a key is exposed, regenerate it from the API key page and update the connector. The connector stores the key as a securestring — it is not displayed again after you connect.
ℹ️ API quota & rate limits: GTI/VirusTotal enforces per-minute and daily request quotas tied to your subscription tier. The connector requests up to 40 objects per page and throttles itself (~4 requests/second). If you hit HTTP 429 (rate limit) errors, choose a longer Polling interval below and/or narrow the result set with the Vulnerability filter.
2. Connect Google Threat Intelligence Vulnerabilities to Microsoft Sentinel
Provide the values below and select Connect. The connector always scopes the query to collection_type:vulnerability and sorts by last-modification-date ascending (firstly-modified objects first).
ℹ️ Required. The API key copied from the GTI / VirusTotal API key page. It is sent in the 'x-apikey' header on every request.
ℹ️ Optional. A GTI search expression appended to the mandatory 'collection_type:vulnerability' filter to narrow ingestion. Examples: 'risk_rating:Critical', 'cvss_3x_base_score:4+', 'exploitation_state:Confirmed'. Leave blank to ingest all vulnerability objects. Separate multiple conditions with spaces.
ℹ️ Required. How often Sentinel queries the GTI API. Each poll uses a rolling time window equal to this interval, so no vulnerabilities are skipped or double-counted. Choose a longer interval if you are rate-limited or only need periodic updates.
3. Verify data is flowing
After connecting, confirm vulnerabilities are being ingested.
Data can take up to ~30 minutes to appear after the first successful poll. Once it does:
On this page, the GTI_Vulnerabilities_CL data type shows a recent Last data received timestamp and the status turns green.
Run this query in Logs to confirm rows are arriving:
GTI_Vulnerabilities_CL | summarize Count = count(), Latest = max(TimeGenerated)
Inspect a sample of the enriched fields:
GTI_Vulnerabilities_CL | project TimeGenerated, Name, RiskRating, ExploitationState, Cvss3xBaseScore | sort by TimeGenerated desc | take 20
Optional — connector health: enable Microsoft Sentinel → Settings → Health and Audit to log per-poll status. Then run:
SentinelHealth | where TimeGenerated > ago(24h) | where SentinelResourceType == "Data connector" | project TimeGenerated, SentinelResourceName, Status, Description, Reason | order by TimeGenerated desc
ℹ️ No data after 30+ minutes? Check that: (1) the API key is valid and not rate-limited (HTTP 401/429), (2) your account has access to vulnerability collections, and (3) any Vulnerability filter you entered is not so narrow that it matches no objects. Disconnect and reconnect to retry after correcting the value.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊