Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Triggered by a Microsoft Sentinel URL entity, submits the URL to the GTI private API, polls analysis with progressive back-off (30s→60s→120s, max 30 min), retrieves the full URL report using the URL ID from the analysis meta, ingests the complete data object into GTI_URLScan_CL via DCE/DCR, then calls GTIAddCommentToIncident with the full response and playbook name.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 0 |
keyvault |
Managed | 1 | 1 |
http |
Built-in | 0 | 4 |
workflow |
Built-in | 0 | 2 |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Secret | get | [concat('/secrets/@{encodeURIComponent(''', parameters('KeyVaultSecretName'), ''')}/value')] |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Submit_Uri | POST | @{concat(parameters('GTIBaseUri'), '/api/v3/private/urls')} |
— |
| Get_Analysis | GET | @{concat(parameters('GTIBaseUri'), '/api/v3/private/analyses/', variables('AnalysisId'))} |
— |
| Get_URL_Report | GET | @{concat(parameters('GTIBaseUri'), '/api/v3/private/urls/', variables('UrlId'))} |
— |
| Ingest_URL_Scan_Result | POST | @parameters('DCEIngestionEndpoint') |
— |
workflow (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Call_GTIAddCommentToIncident | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Logic/workflows/', parameters('GTIAddCommentPlaybookName'))]triggerName= manual |
| Call_GTIAddCommentToIncident_Error | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Logic/workflows/', parameters('GTIAddCommentPlaybookName'))]triggerName= manual |
📄 Source: GTIURLScanEntityEnrichment/readme.md
This playbook is triggered from a URL entity on a Microsoft Sentinel incident. It submits the URL to the Google Threat Intelligence (GTI) private API for scanning, polls the analysis until it completes, and retrieves the full URL report. The report is ingested into the GTI_URLScan_CL custom table via a DCE/DCR, and an enrichment comment is posted on the associated incident through the GTIAddCommentToIncident sub-playbook.
Once deployment is complete, authorize each connection.
Add access policy for the playbook's managed identity to read secrets from Key Vault.
This playbook runs against a URL entity on an incident.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊