Google Threat Intelligence - FileHash Enrichment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook will enrich FileHash entities.

Attribute Value
Type Playbook
Solution Google Threat Intelligence
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 1
googlethreatintelligence Managed 0 1
GoogleThreatIntelligence-CustomConnector Custom 1 0
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Add_comment_to_incident_(V3) post /Incidents/Comment —

googlethreatintelligence (Managed)

Action Method Endpoint Other
Get_File_Report get /files/@{encodeURIComponent(triggerBody()?['Entity']?['properties']?['Value'])} —

Additional Documentation

📄 Source: GTIEnrichment/GTI-EnrichEntity/GTI-EnrichFilehash/readme.md

Summary

This playbook is triggered manually from a FileHash entity in a Microsoft Sentinel incident. It calls the Google Threat Intelligence API to retrieve the file report for the selected hash, including its reputation, last-analysis statistics (harmless/malicious/suspicious/timeout/undetected), community votes, and GTI Assessment (threat score, verdict, severity). If the entity is associated with an incident, the playbook formats these details and adds them as a comment on the incident, giving the analyst enriched file context without leaving Microsoft Sentinel.

Prerequisites

  1. Deploy the Google Threat Intelligence Custom Connector (GTICustomConnector) before deploying this playbook, and note its resource name for the ConnectorName parameter.
  2. Register for a Google Threat Intelligence account and obtain an API key, then configure it on the Google Threat Intelligence Custom Connector's API connection.
  3. Ensure you have a Log Analytics Workspace configured for Microsoft Sentinel.

Deployment Instructions

  1. To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
  2. Fill in the required parameters:
    • PlaybookName: Enter the playbook name here (default: GTI-IOCEnrichmentFileHash).
    • ConnectorName: Name of the deployed Google Threat Intelligence Custom Connector resource (default: GoogleThreatIntelligence-CustomConnector).

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

a. Authorize connections

Once deployment is complete, authorize each connection.

  1. Go to your logic app → API connections → Select Microsoft Sentinel connection resource.
  2. Go to General → edit API connection.
  3. Click Authorize.
  4. Sign in.
  5. Click Save.
  6. Repeat steps for the Google Threat Intelligence Custom Connector connection.

b. Attach to FileHash Entity

This is an entity-triggered playbook that runs against a FileHash entity.

  1. Go to Microsoft Sentinel → Incidents, open an incident, and select the Entities tab.
  2. Right-click the FileHash entity you want to enrich.
  3. Select Run playbook.
  4. Choose GTI-IOCEnrichmentFileHash (or the PlaybookName you deployed) and run it.
  5. If the entity is linked to an incident, the enriched GTI File Report is added as a comment on that incident.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Google Threat Intelligence