Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will enrich Domain entities.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
googlethreatintelligence |
Managed | 0 | 1 |
GoogleThreatIntelligence-CustomConnector |
Custom | 1 | 0 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Add_comment_to_incident_(V3) | post | /Incidents/Comment |
— |
googlethreatintelligence (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Domain_Report | get | /domains/@{encodeURIComponent(triggerBody()?['Entity']?['properties']?['DomainName'])} |
— |
📄 Source: GTIEnrichment/GTI-EnrichEntity/GTI-EnrichDomain/readme.md
This playbook is triggered by a Microsoft Sentinel Domain entity (DNS) trigger, either manually from an incident or via automation. When triggered, it calls the Google Threat Intelligence API to retrieve a domain report, including reputation, last analysis statistics (harmless/malicious/suspicious/timeout/undetected), community votes, and the GTI Assessment (threat score, verdict, severity). If the entity is associated with an incident, the playbook formats these findings and adds them as a comment to the corresponding Microsoft Sentinel incident, giving analysts immediate threat context on the domain without leaving the incident view.
Once deployment is complete, authorize each connection.
This is an entity-triggered playbook (Domain/DNS entity kind) that adds a comment to the incident associated with the corresponding entity.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊