Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Accepts a URL via HTTP POST, optionally with a custom user_agent and storage_region, submits it to the GTI private API, polls analysis with progressive back-off (30s→60s→120s, max 30 min), retrieves the full URL report using the URL ID from the analysis meta, ingests the complete data object into GTI_URLScan_CL via DCE/DCR, and returns the verdict to the caller.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 2 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
keyvault |
Managed | 1 | 1 |
http |
Built-in | 0 | 4 |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Secret | get | [concat('/secrets/@{encodeURIComponent(''', parameters('KeyVaultSecretName'), ''')}/value')] |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Submit_Uri | POST | @{concat(parameters('GTIBaseUri'), '/api/v3/private/urls')} |
— |
| Get_Analysis | GET | @{concat(parameters('GTIBaseUri'), '/api/v3/private/analyses/', variables('AnalysisId'))} |
— |
| Get_URL_Report | GET | @{concat(parameters('GTIBaseUri'), '/api/v3/private/urls/', variables('UrlId'))} |
— |
| Ingest_URL_Scan_Result | POST | @parameters('DCEIngestionEndpoint') |
— |
📄 Source: GTIURLScanEnrichment/readme.md
This playbook is triggered by an HTTP POST request, typically invoked manually, from a workbook, or from another playbook, with a URL to analyze. It submits the URL to the GTI (VirusTotal) private scanning API, then polls the analysis status with a progressive back-off (30s → 60s → 120s, up to 30 minutes) until the scan completes. Once complete, it retrieves the full URL report using the URL ID returned in the analysis metadata and ingests the complete report data into the custom GTI_URLScan_CL table via a Data Collection Endpoint/Rule. This gives analysts a persisted, queryable GTI verdict, threat score, and full scan detail for any URL submitted for investigation, without leaving Sentinel.
GTIApiKey).enabledForTemplateDeployment set to true.GTI_URLScan_CL custom table in this workspace.GTI_URLScan_CL ingestion (no default — must be provided).Once deployment is complete, authorize the connection.
The playbook's managed identity must be able to read the GTI API key secret.
Note: the 'Monitoring Metrics Publisher' role required on the Data Collection Rule (for ingestion into GTI_URLScan_CL) is assigned automatically by this template — no manual action is needed for that role.
This playbook is triggered by an HTTP Request, so it must be called explicitly.
url (required), and optionally user_agent and storage_region (one of "", "US", "CA", "EU", "GB").Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊