Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Retrieves vulnerability intelligence from Google Threat Intelligence for a given CVE ID and returns enrichment to the workbook.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | Google Threat Intelligence |
| Source | View on GitHub |
This playbook uses 2 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
keyvault |
Managed | 1 | 1 |
http |
Built-in | 0 | 2 |
keyvault (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Get_Secret | get | [concat('/secrets/@{encodeURIComponent(''', parameters('KeyVaultSecretName'), ''')}/value')] |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Call_GTI_API | GET | @{concat(parameters('GTIBaseUrl'), '/api/v3/collections/vulnerability--', toLower(triggerBody()?['cveId']))} |
— |
| Ingest_Vuln_Enrichment | POST | @parameters('DCEIngestionEndpoint') |
— |
📄 Source: GTIVulnerabilityEnrichment/readme.md
This playbook is triggered via an HTTP request containing a CVE ID (for example, from the Google Threat Intelligence workbook). It looks up the CVE in GTI's vulnerability collection (/api/v3/collections/vulnerability--<cveId>), retrying automatically if the API returns a 429 rate-limit response. On a successful lookup it ingests the full vulnerability record — severity, exploitation state, CVSS/EPSS scores, CISA KEV status, description, and related metadata — into a custom Log Analytics table via a Data Collection Endpoint/Rule, and returns the same data in the HTTP response. This gives analysts a single call that both persists GTI vulnerability intelligence for a CVE and returns it immediately for use in a workbook or another automation.
GTIApiKey).The Key Vault connection authenticates using the Logic App's system-assigned Managed Identity, so no manual "Authorize" sign-in step is required in API connections. Instead, grant the identity the Key Vault Secrets User RBAC role on the Key Vault.
This playbook is triggered by an HTTP Request, not an entity or incident trigger.
PlaybookEndpoint deployment output).{ "cveId": "CVE-2021-44228" }, to this URL.Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊