↳ GitHub sourceSolution

Google Threat Intelligence

Description

This Google Threat Intelligence Solution contains Playbooks that can help enrich incident information with threat information and intelligence for IPs, file hashes and URLs from Google Threat Intelligence. Enriched information can help drive focused investigations in Security Operations.<br><br><b>Important — Custom Connector prerequisite:</b> The Playbooks in this solution depend on the <b>Google Threat Intelligence custom Logic Apps connector</b>, which is <b>not deployed automatically</b> when you install the solution from Content Hub. Before running any of the Playbooks, you must manually deploy the custom connector into the same resource group and region as the Playbooks, using the Deploy to Azure button in the connector's <a href="https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/Google%20Threat%20Intelligence/Playbooks/CustomConnector/GTICustomConnector">readme</a>. Without it, the Playbooks will fail to authenticate to the Google Threat Intelligence API.
Version
3.3.0
Declared author / publisher
Google
Support tier
Partner

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-google
Additional source files 2Solutions/Google Threat Intelligence/Data/Solution_GoogleThreatIntelligence.jsonsolution-manifest ↗Solutions/Google Threat Intelligence/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.