Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will enrich IP entities.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
googlethreatintelligence |
Managed | 0 | 1 |
GoogleThreatIntelligence-CustomConnector |
Custom | 1 | 0 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Add_comment_to_incident_(V3) | post | /Incidents/Comment |
— |
googlethreatintelligence (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_IP_Report | get | /ip_addresses/@{encodeURIComponent(triggerBody()?['Entity']?['properties']?['Address'])} |
— |
📄 Source: GTIEnrichment/GTI-EnrichEntity/GTI-EnrichIP/readme.md
This playbook is triggered from an IP entity in Microsoft Sentinel. It calls the Google Threat Intelligence custom connector to retrieve the IP address report, including reputation, last analysis stats, geolocation, ownership, community votes, and the GTI Assessment (threat score, verdict, and severity). If the entity is associated with an incident, the playbook formats this data and adds it as a comment on the incident, giving the analyst enrichment context without leaving Microsoft Sentinel.
Once deployment is complete, authorize each connection.
This playbook is triggered from an IP entity (/entity/IP), not run on a schedule.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊