Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook accepts a blob path posted from an Azure Workbook, retrieves the file from Azure Blob Storage, submits it to Google Threat Intelligence (VirusTotal) for scanning (handling both standard and large files >32 MB), polls until analysis is complete, ingests the result into GTI_FileScan_CL via DCE/DCR, and returns a verdict with threat assessment details.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azureblob |
Managed | 1 | 2 |
keyvault |
Managed | 1 | 1 |
function |
Built-in | 0 | 1 |
http |
Built-in | 0 | 4 |
azureblob (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Blob_Metadata | get | /v2/datasets/@{encodeURIComponent(encodeURIComponent(parameters('StorageAccountName')))}/files/@{encodeURIComponent(encodeURIComponent(concat('/', triggerBody()?['containerName'], '/', triggerBody()?['blobPath'])))} |
— |
| Get_Blob_Content | get | /v2/datasets/@{encodeURIComponent(encodeURIComponent(parameters('StorageAccountName')))}/files/@{encodeURIComponent(encodeURIComponent(concat('/', triggerBody()?['containerName'], '/', triggerBody()?['blobPath'])))}/content |
— |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Secret | get | [concat('/secrets/@{encodeURIComponent(''', parameters('KeyVaultSecretName'), ''')}/value')] |
— |
function (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Upload_Large_File_Via_Function | — | — | functionId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Web/sites/', variables('FunctionAppResourceName'), '/functions/GTIUploadLargeFile')] |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Submit_File | POST | @{variables('GTIBaseUrl')}/api/v3/private/files |
— |
| Get_Analysis | GET | @{variables('GTIBaseUrl')}/api/v3/private/analyses/@{variables('AnalysisId')} |
— |
| Get_File_Report | GET | @{variables('GTIBaseUrl')}/api/v3/private/files/@{body('Get_Analysis')?['meta']?['file_info']?['sha256']} |
— |
| Ingest_File_Scan_Result | POST | @parameters('DCEIngestionEndpoint') |
— |
📄 Source: GTIFileScanEnrichment/readme.md
This playbook is triggered via HTTP request from the Google Threat Intelligence Workbook and accepts a container name and blob path pointing to a file in Azure Blob Storage. It retrieves the file (uploading it through the shared GTIFileUpload Function App if larger than 32 MB), submits it to Google Threat Intelligence (VirusTotal) for scanning, and polls the analysis until it completes. The resulting file report, including the GTI threat verdict, severity, and contributing factors, is ingested into the GTI_FileScan_CL table via a Data Collection Endpoint/Rule, giving analysts an on-demand file reputation and threat assessment view directly in the workbook.
Once deployment is complete, authorize the connections that require sign-in.
Note: the azureblob connection authenticates via the Logic App's Managed Identity rather than OAuth sign-in, so it does not need to be authorized here; see step c below instead.
Configure the Google Threat Intelligence Workbook to call this playbook.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊