GTI Relevance System Alert - Incident by Alert ID

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates a Microsoft Sentinel incident for each unique Google Threat Intelligence (GTI) Alert ID. Multiple ingestion records sharing the same Alert ID (e.g. updated snapshots of the same alert) are grouped into a single incident. The rule surfaces the most recent snapshot of each alert and maps severity from the GTI severity analysis field.

Attribute Value
Type Analytic Rule
Solution Google Threat Intelligence
ID a1b2c3d4-e5f6-7890-abcd-ef1234567891
Severity Medium
Status Available
Kind Scheduled
Tactics InitialAccess, Reconnaissance, Impact, CredentialAccess
Techniques T1566, T1078, T1552, T1486, T1595
Required Connectors GoogleThreatIntelligenceRelevanceSystemAlertsAPI
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
RelevanceSystemAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Google Threat Intelligence