Google SecOps - GCTI Threat Intelligence Finding

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates incidents in Microsoft Sentinel when Google Security Operations raises an active threat intelligence alert (GCTI_FINDING). These alerts are generated by Google's global threat intel corpus and represent high-confidence threats, distinct from customer-authored rule detections.

Attribute Value
Type Analytic Rule
Solution GoogleSecOps
ID b3e7f921-5c4a-4d8e-a2f9-7b1d3e6c9a5f
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess, Execution, CommandAndControl, Exfiltration
Techniques T1078, T1566, T1071, T1048
Required Connectors GSDetectionAlerts
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DetectionAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to GoogleSecOps