Google Threat Intelligence - Vulnerability Enrichment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Retrieves vulnerability intelligence from Google Threat Intelligence for a given CVE ID and returns enrichment to the workbook.

Attribute Value
Type Playbook
Solution Google Threat Intelligence
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
keyvault Managed 1 1
http Built-in 0 2
Action parameters (URLs, paths, function IDs)

keyvault (Managed)

Action Method Endpoint Other
Get_Secret get [concat('/secrets/@{encodeURIComponent(''', parameters('KeyVaultSecretName'), ''')}/value')] —

http (Built-in)

Action Method Endpoint Other
Call_GTI_API GET @{concat(parameters('GTIBaseUrl'), '/api/v3/collections/vulnerability--', toLower(triggerBody()?['cveId']))} —
Ingest_Vuln_Enrichment POST @parameters('DCEIngestionEndpoint') —

Additional Documentation

📄 Source: GTIVulnerabilityEnrichment/readme.md

Summary

This playbook is triggered via an HTTP request containing a CVE ID (for example, from the Google Threat Intelligence workbook). It looks up the CVE in GTI's vulnerability collection (/api/v3/collections/vulnerability--<cveId>), retrying automatically if the API returns a 429 rate-limit response. On a successful lookup it ingests the full vulnerability record — severity, exploitation state, CVSS/EPSS scores, CISA KEV status, description, and related metadata — into a custom Log Analytics table via a Data Collection Endpoint/Rule, and returns the same data in the HTTP response. This gives analysts a single call that both persists GTI vulnerability intelligence for a CVE and returns it immediately for use in a workbook or another automation.

Prerequisites

  1. Obtain a Google Threat Intelligence API key and store it in Azure Key Vault as a secret (default secret name: GTIApiKey).
  2. Create or identify an Azure Key Vault to hold the secret, and ensure it is reachable by the Logic App's managed identity.
  3. Ensure you have a Log Analytics Workspace configured for Microsoft Sentinel.

Deployment Instructions

  1. To deploy the Playbook, click the Deploy to Azure button. This will launch the ARM Template deployment wizard.
  2. Fill in the required parameters:
    • PlaybookName: Enter the playbook name here (default: GTIVulnerabilityEnrichment).
    • KeyVaultName: Name of the Key Vault that contains the GTI API key secret (required).
    • KeyVaultSecretName: Name of the Key Vault secret that holds the GTI API key (default: GTIApiKey).
    • WorkspaceName: Name of the Log Analytics workspace to ingest GTI vulnerability enrichment data (required).
    • TableName: Target custom table name. Use GTI_Vulnerabilities_CL (default) to share the data connector table, or provide a different name to create a dedicated enrichment table.

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

a. Grant Key Vault access to the Logic App identity

The Key Vault connection authenticates using the Logic App's system-assigned Managed Identity, so no manual "Authorize" sign-in step is required in API connections. Instead, grant the identity the Key Vault Secrets User RBAC role on the Key Vault.

  1. Go to logic app → your logic app → identity → System assigned Managed identity and copy Object (principal) ID.
  2. Go to keyvaults → your keyvault → Access control (IAM) → Add role assignment.
  3. Select the Key Vault Secrets User role. Click Next.
  4. In Members, select Managed identity, choose the Logic App, and search by the copied object ID. Click Next.
  5. Click Review + assign.

b. Wire Up the Trigger

This playbook is triggered by an HTTP Request, not an entity or incident trigger.

  1. Go to Logic App → your Logic App → Logic app designer → trigger, and copy the HTTP POST callback URL (also available as the PlaybookEndpoint deployment output).
  2. Configure the caller (workbook, another playbook, or a manual test call) to POST a JSON body containing the CVE ID, e.g. { "cveId": "CVE-2021-44228" }, to this URL.
  3. The playbook responds with the enriched GTI vulnerability record and also writes it to the configured Log Analytics table for later querying.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Playbooks · Back to Google Threat Intelligence