Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will ingest Google Threat Intelligence from your IoC Streams into Threat Intelligence Sentinel.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
azuretables |
Managed | 1 | 3 |
googlethreatintelligence |
Managed | 0 | 1 |
GoogleThreatIntelligence-CustomConnector |
Custom | 1 | 0 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Threat_Intelligence_-Upload_STIX_Objects(Preview) | post | /ThreatIntelligence/@{encodeURIComponent('')}/UploadStixObjects/ |
— |
azuretables (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Update_last_execution | put | /v2/storageAccounts/@{encodeURIComponent(encodeURIComponent(variables('account_name')))}/tables/@{encodeURIComponent(variables('table_name'))}/entities(PartitionKey='@{encodeURIComponent('IoCStream-',workflow().name)}',RowKey='@{encodeURIComponent('LastExTimestamp')}') |
— |
| Create_table_(V2) | post | /v2/storageAccounts/@{encodeURIComponent(encodeURIComponent(variables('account_name')))}/tables |
— |
| Get_last_execution | get | /v2/storageAccounts/@{encodeURIComponent(encodeURIComponent(variables('account_name')))}/tables/@{encodeURIComponent(variables('table_name'))}/entities(PartitionKey='@{encodeURIComponent('IoCStream-',workflow().name)}',RowKey='@{encodeURIComponent('LastExTimestamp')}') |
— |
googlethreatintelligence (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_IoC_Stream_list | get | /ioc_stream |
— |
📄 Source: GTIIocStream/readme.md
This playbook runs automatically on a Recurrence trigger (every 60 minutes) and does not require manual invocation from the workbook. On each run it queries the Google Threat Intelligence /ioc_stream API (filtered by the timestamp of the last successful run, output_format=stix) and pages through results using the returned cursor until the API stops returning one. Each page of STIX objects is uploaded into Microsoft Sentinel Threat Intelligence via the "Upload STIX Objects" action, so the indicators from your GTI IoC Stream become available as threat intelligence indicators in Sentinel. An Azure Table is used to persist the last-execution timestamp between runs so each recurrence only pulls new IoCs.
GTICustomConnector) first — it authenticates to the GTI API using an API key sent in the x-apikey header.Once deployment is complete, authorize each connection.
This playbook is Recurrence-triggered (default: every 60 minutes) and requires no additional wiring to the Google Threat Intelligence workbook.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊