Solution: Google Threat Intelligence
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | |
| Support Tier | Partner |
| Support Link | https://www.virustotal.com/gui/contact-us |
| Categories | Security - Threat Intelligence |
| Version | 3.3.0 |
| Author | |
| First Published | 2024-10-26 |
| Last Updated | 2026-09-01 |
| Solution Folder | Google Threat Intelligence |
| Marketplace | Azure Marketplace · Popularity: 🔵 Medium (61%) |
This Google Threat Intelligence Solution contains Playbooks that can help enrich incident information with threat information and intelligence for IPs, file hashes and URLs from Google Threat Intelligence. Enriched information can help drive focused investigations in Security Operations.
Important — Custom Connector prerequisite: The Playbooks in this solution depend on the Google Threat Intelligence custom Logic Apps connector, which is not deployed automatically when you install the solution from Content Hub. Before running any of the Playbooks, you must manually deploy the custom connector into the same resource group and region as the Playbooks, using the Deploy to Azure button in the connector's readme. Without it, the Playbooks will fail to authenticate to the Google Threat Intelligence API.
This solution provides 2 data connector(s):
This solution uses 4 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
GTI_FileScan_CL |
- | Workbooks |
GTI_URLScan_CL |
- | Workbooks |
GTI_Vulnerabilities_CL |
Google Threat Intelligence Vulnerabilities (CCF) | Analytics, Workbooks |
RelevanceSystemAlerts_CL |
Google Threat Intelligence Relevance System Alerts | Analytics |
The following 1 table(s) are used internally by this solution's content items:
| Table | Used By Connectors | Used By Content |
|---|---|---|
ThreatIntelIndicators |
- | Analytics, Hunting |
This solution includes 36 content item(s):
| Content Type | Count |
|---|---|
| Playbooks | 15 |
| Analytic Rules | 14 |
| Hunting Queries | 4 |
| Parsers | 2 |
| Workbooks | 1 |
| Name | Tactics | Tables Used |
|---|---|---|
| Google Threat Intelligence - Threat Hunting Domain | - | Internal use:ThreatIntelIndicators |
| Google Threat Intelligence - Threat Hunting Hash | - | Internal use:ThreatIntelIndicators |
| Google Threat Intelligence - Threat Hunting IP | - | Internal use:ThreatIntelIndicators |
| Google Threat Intelligence - Threat Hunting Url | - | Internal use:ThreatIntelIndicators |
| Name | Tables Used |
|---|---|
| GoogleThreatIntelligence | GTI_FileScan_CLGTI_URLScan_CLGTI_Vulnerabilities_CL |
| Name | Description | Tables Used |
|---|---|---|
| Google Threat Intelligence - Add Comment To Incident | Utility sub-playbook called by GTIURLScanIncidentEnrichment and GTIURLScanEntityEnrichment. Receives... | - |
| Google Threat Intelligence - Domain Enrichment | This playbook will enrich Domain entities. | - |
| Google Threat Intelligence - FileHash Enrichment | This playbook will enrich FileHash entities. | - |
| Google Threat Intelligence - FileScan Blob Enrichment | This playbook monitors an Azure Blob Storage container and automatically submits newly added or modi... | - |
| Google Threat Intelligence - FileScan Enrichment | This playbook accepts a blob path posted from an Azure Workbook, retrieves the file from Azure Blob ... | - |
| Google Threat Intelligence - IOC Enrichment | This playbook will enrich IP, Hash, URL & Domain entities found in alerts. | - |
| Google Threat Intelligence - IOC Enrichment | This playbook will enrich IP, Hash, URL & Domain entities found in incidents. | - |
| Google Threat Intelligence - IP Enrichment | This playbook will enrich IP entities. | - |
| Google Threat Intelligence - IoC Stream | This playbook will ingest Google Threat Intelligence from your IoC Streams into Threat Intelligence ... | - |
| Google Threat Intelligence - Threat List | This playbook will ingest Google Threat Intelligence into Threat Intelligence Sentinel. | - |
| Google Threat Intelligence - URL Enrichment | This playbook will enrich URL entities. | - |
| Google Threat Intelligence - URLScan Enrichment | Accepts a URL via HTTP POST, optionally with a custom user_agent and storage_region, submits it to t... | - |
| Google Threat Intelligence - URLScan Entity Enrichment | Triggered by a Microsoft Sentinel URL entity, submits the URL to the GTI private API, polls analysis... | - |
| Google Threat Intelligence - URLScan Incident Enrichment | Triggered by a Microsoft Sentinel incident, extracts URL entities, submits each to the GTI private A... | - |
| Google Threat Intelligence - Vulnerability Enrichment | Retrieves vulnerability intelligence from Google Threat Intelligence for a given CVE ID and returns ... | - |
| Name | Description | Tables Used |
|---|---|---|
| GTIRelevanceSystemAlerts | - | RelevanceSystemAlerts_CL (read) |
| GTIVulnerabilities | - | GTI_Vulnerabilities_CL (read) |
📄 Source: Google Threat Intelligence/README.md
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.3.0 | 23-07-2026 | - Added Data Connector GTI Vulnerabilities (Codeless Connector Framework, Log Ingestion API). - Added Parser GTIVulnerabilities, Analytics Rules, Playbooks and Workbook Google Threat Intelligence. |
| 3.2.3 | 04-06-2026 | - Added Data Connector GTI Relevance System Alerts (Azure Function App, Log Ingestion API). - Added Parser GTIRelevanceSystemAlerts. - Added Analytics Rules: GTI High Relevance Alerts, GTI High & Critical Priority Alerts, GTI Data Leak Alerts, GTI Initial Access Broker Alerts, GTI Insider Threat Alerts, GTI Relevance System Alerts Incident by Alert ID. - Added Custom Connector manual prerequisite for Playbooks. |
| 3.2.2 | 02-12-2025 | - Included new Analytics Rules and Hunting Queries to improve detection capabilities and support proactive investigation. - Filtering threat lists - Migrating to Upload STIX Objects |
| 3.2.1 | 25-08-2025 | Fix IoC Stream ingestion bug for results with more than 40 items due to a cursor iteration error. |
| 3.2.0 | 20-05-2025 | New Playbook added IoC Stream Threat Intelligence. Added x-tool header in Playbook Customer Connector. |
| 3.1.0 | 29-01-2025 | New Threat Intelligence Ingestion Playbook added. |
| 3.0.0 | 05-12-2024 | Initial Solution Release. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊