Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Triggered by a Microsoft Sentinel incident, extracts URL entities, submits each to the GTI private API, polls analysis with progressive back-off (30s→60s→120s, max 30 min), retrieves the full URL report using the URL ID from the analysis meta, ingests the complete data object into GTI_URLScan_CL via DCE/DCR, then calls GTIAddCommentToIncident with the full response and playbook name.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 1 |
keyvault |
Managed | 1 | 1 |
http |
Built-in | 0 | 4 |
workflow |
Built-in | 0 | 2 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_URL_Entities | post | /entities/url |
— |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Secret | get | [concat('/secrets/@{encodeURIComponent(''', parameters('KeyVaultSecretName'), ''')}/value')] |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Submit_Uri | POST | @{concat(parameters('GTIBaseUri'), '/api/v3/private/urls')} |
— |
| Get_Analysis | GET | @{concat(parameters('GTIBaseUri'), '/api/v3/private/analyses/', variables('AnalysisId'))} |
— |
| Get_URL_Report | GET | @{concat(parameters('GTIBaseUri'), '/api/v3/private/urls/', variables('UrlId'))} |
— |
| Ingest_URL_Scan_Result | POST | @parameters('DCEIngestionEndpoint') |
— |
workflow (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Call_GTIAddCommentToIncident | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Logic/workflows/', parameters('GTIAddCommentPlaybookName'))]triggerName= manual |
| Call_GTIAddCommentToIncident_Error | — | — | workflowId=[concat('/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/providers/Microsoft.Logic/workflows/', parameters('GTIAddCommentPlaybookName'))]triggerName= manual |
📄 Source: GTIURLScanIncidentEnrichment/readme.md
This playbook is triggered manually or automatically from an incident in Microsoft Sentinel. It extracts all URL entities from the incident and, for each URL, submits it to the Google Threat Intelligence (GTI) private API for scanning, polls the analysis until completion, and retrieves the full URL report. The complete scan result is ingested into the GTI_URLScan_CL table via a Data Collection Endpoint/Rule, and a consolidated enrichment comment is posted on the incident via the GTIAddCommentToIncident sub-playbook.
Once deployment is complete, authorize each connection.
Add access policy for the playbook's managed identity to read secrets from Key Vault.
Configure how this playbook will be triggered:
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊