Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook monitors an Azure Blob Storage container and automatically submits newly added or modified files to Google Threat Intelligence (GTI/VirusTotal) for scanning. Analysis results are ingested into a custom Log Analytics table (GTI_FileScan_CL) via the Log Ingestion API for further investigation in Microsoft Sentinel.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azureblob |
Managed | 1 | 2 |
keyvault |
Managed | 1 | 1 |
function |
Built-in | 0 | 1 |
http |
Built-in | 0 | 4 |
azureblob (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Blob_Content | get | /v2/datasets/@{encodeURIComponent(encodeURIComponent(parameters('StorageAccountName')))}/files/@{encodeURIComponent(encodeURIComponent(triggerBody()?['Path']))}/content |
— |
| When_a_blob_is_added_or_modified | get | /v2/datasets/@{encodeURIComponent(encodeURIComponent(parameters('StorageAccountName')))}/triggers/batch/onupdatedfile |
— |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Secret | get | /secrets/@{encodeURIComponent(parameters('KeyVaultSecretName'))}/value |
— |
function (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Upload_Large_File_Via_Function | — | — | functionId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Web/sites/', variables('FunctionAppResourceName'), '/functions/GTIUploadLargeFile')] |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Submit_File | POST | @{variables('GTIBaseUrl')}/api/v3/private/files |
— |
| Get_Analysis_Status | GET | @{concat(variables('GTIBaseUrl'), '/api/v3/private/analyses/', variables('AnalysisId'))} |
— |
| Get_File_Report | GET | @{concat(variables('GTIBaseUrl'), '/api/v3/private/files/', variables('SHA256'))} |
— |
| Ingest_To_LogAnalytics | POST | @parameters('DCEIngestionEndpoint') |
— |
📄 Source: GTIFileScanBlobEnrichment/readme.md
This playbook is triggered when a file is added or modified in a monitored Azure Blob Storage container (When_a_blob_is_added_or_modified). Files up to 32MB are read directly and submitted to Google Threat Intelligence (GTI/VirusTotal) for file scanning; files larger than 32MB are handed off to the shared GTIFileUpload Azure Function, which uploads them to GTI on the playbook's behalf. The playbook then polls the analysis until it completes, retrieves the file report, and ingests the results into the custom Log Analytics table GTI_FileScan_CL via a Data Collection Endpoint/Data Collection Rule (DCE/DCR) for further investigation in Microsoft Sentinel.
Solutions/Google Threat Intelligence/Playbooks/CustomConnector/GTIFileUpload_FunctionAppConnector/azuredeploy.json) to this resource group before deploying this playbook, since files larger than 32MB are uploaded to GTI by that Function rather than by this Logic App.GTIApiKey).GTI_FileScan_CL custom table and its DCE/DCR are created automatically by this template.azureblob connection uses Managed Identity authentication) and the 'Key Vault Secrets User' role on the Key Vault. The GTIFileUpload Function's managed identity also requires 'Storage Blob Data Reader' on the Storage Account.Once deployment is complete, authorize each connection.
Add access policy for the playbook's managed identity to read secrets from Key Vault.
The ARM template grants the Logic App's managed identity the Monitoring Metrics Publisher role on the Data Collection Rule automatically. This can take 1-3 minutes to propagate — if the first run returns a 403 on ingestion, wait a few minutes and retry.
[Content truncated...]
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊