Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will ingest Google Threat Intelligence into Threat Intelligence Sentinel.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
googlethreatintelligence |
Managed | 0 | 1 |
GoogleThreatIntelligence-CustomConnector |
Custom | 1 | 0 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Threat_Intelligence_-Upload_STIX_Objects(Preview) | post | /ThreatIntelligence/@{encodeURIComponent('')}/UploadStixObjects/ |
— |
googlethreatintelligence (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| get_threat_list | get | /threat_lists/@{encodeURIComponent('ransomware')}/@{encodeURIComponent(convertTimeZone(utcNow(), 'UTC', 'Mid-Atlantic Standard Time','yyyyMMddHH'))} |
— |
📄 Source: GTIThreatList/readme.md
This playbook runs automatically on a Recurrence schedule (every 60 minutes) and calls the Google Threat Intelligence Threat List API for the ransomware category to retrieve the current STIX indicators for that period. The returned indicators are chunked into batches of 100 and uploaded to Microsoft Sentinel Threat Intelligence via the Upload STIX Objects action, so no manual trigger or workbook wiring is required.
GTICustomConnector) in the same resource group, and configure its API connection with the GTI API key.Once deployment is complete, authorize each connection.
This playbook runs automatically on the configured Recurrence interval once enabled — no manual trigger wiring is required.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊