Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook will enrich URL entities.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 3 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
googlethreatintelligence |
Managed | 0 | 1 |
GoogleThreatIntelligence-CustomConnector |
Custom | 1 | 0 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Add_comment_to_incident_(V3) | post | /Incidents/Comment |
— |
googlethreatintelligence (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_URL_Report | get | /urls/@{encodeURIComponent(replace(base64(triggerBody()?['Entity']?['properties']?['Url']),'=',''))} |
— |
📄 Source: GTIEnrichment/GTI-EnrichEntity/GTI-EnrichURL/readme.md
This playbook is triggered by the Microsoft Sentinel entity trigger for a URL entity. When run, it calls the Google Threat Intelligence API to retrieve the URL report (reputation, harmless/malicious/suspicious/timeout/undetected detection counts, community votes, and the GTI Assessment threat score, verdict, and severity). If the trigger context includes an associated incident, the playbook formats these results into HTML and adds them as a comment on that incident, giving the analyst an at-a-glance threat assessment of the URL directly in the incident timeline.
Once deployment is complete, authorize each connection.
This playbook uses the Microsoft Sentinel entity trigger (path UrlEntity) and is intended to be run against a URL entity on an incident:
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊