Google Threat Intelligence - IOC Enrichment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This playbook will enrich IP, Hash, URL & Domain entities found in incidents.

Attribute Value
Type Playbook
Solution Google Threat Intelligence
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 5
googlethreatintelligence Managed 0 4
GoogleThreatIntelligence-CustomConnector Custom 1 0
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_IPs post /entities/ip —
Entities_-_Get_FileHashes post /entities/filehash —
Entities_-_Get_URLs post /entities/url —
Entities_-_Get_DNS post /entities/dnsresolution —
Add_comment_to_incident_(V3) post /Incidents/Comment —

googlethreatintelligence (Managed)

Action Method Endpoint Other
Get_IP_Report get /ip_addresses/@{encodeURIComponent(item()?['Address'])} —
Get_File_Report get /files/@{encodeURIComponent(item()?['Value'])} —
Get_URL_Report get /urls/@{encodeURIComponent(replace(base64(item()?['Url']),'=',''))} —
Get_Domain_Report get /domains/@{encodeURIComponent(item()?['DomainName'])} —

Additional Documentation

📄 Source: GTIEnrichment/GTI-EnrichIncident/readme.md

Summary

This playbook triggers automatically when a Microsoft Sentinel incident is created. It retrieves the IP address, file hash, URL, and DNS resolution (domain) entities related to the incident, then queries the Google Threat Intelligence (GTI) API for each entity to pull its reputation, threat score, severity, and verdict. The results are formatted into HTML summaries and posted back onto the incident as comments, giving analysts GTI threat context for every IOC without leaving Sentinel.

Prerequisites

  1. Deploy the GTICustomConnector custom connector before deploying this playbook.
  2. Register for a Google Threat Intelligence account to obtain an API key, and configure it on the GTICustomConnector API connection.
  3. Ensure you have a Log Analytics Workspace configured for Microsoft Sentinel.

Deployment Instructions

  1. To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
  2. Fill in the required parameters:
    • PlaybookName: Enter the playbook name here (default: GTI-IOCEnrichmentIncident).
    • ConnectorName: Name of the deployed Google Threat Intelligence custom connector (API connection) used for the enrichment lookups (default: GoogleThreatIntelligence-CustomConnector).

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

a. Authorize connections

Once deployment is complete, authorize each connection.

  1. Go to your logic app → API connections → Select Microsoft Sentinel connection resource.
  2. Go to General → edit API connection.
  3. Click Authorize.
  4. Sign in.
  5. Click Save.
  6. Repeat steps for the Google Threat Intelligence connection.

b. Attach to Automation Rule or Manual Trigger

This playbook fires on the Microsoft Sentinel incident-creation trigger, so it can run automatically or be invoked manually:

  1. For Automatic Enrichment: Create an automation rule in Microsoft Sentinel that runs when an incident is created, and add this playbook (GTI-IOCEnrichmentIncident) as its action.
  2. For Manual Enrichment: Open the incident in Microsoft Sentinel, select "Run playbook", and choose GTI-IOCEnrichmentIncident from the list.
  3. Once triggered, the playbook iterates over all entities associated with the incident, adding enrichment comments to the incident.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Google Threat Intelligence