GoogleThreatIntelligence (v3.0.3)

Analyzes suspicious hashes, URLs, domains, and IP addresses, and fetch incidents as DTM Alerts or ASM Issues from the Google Threat Intelligence platform.

Author
Google
Support
partner
URL
https://www.virustotal.com
Default data source
GoogleThreatIntelligenceDTMAlerts
Categories
Data Enrichment & Threat Intelligence

Incident fields (95)

Indicator fields (3)

Integrations (6)

Layouts (3)

Playbooks (12)

README

What. Google Threat Intelligence provides unparalleled visibility into the global threat landscape. We offer deep insights from Mandiant’s leading incident response and threat research team, and combine them with our massive user and device footprint and VirusTotal’s broad crowdsourced malware database.

Why. Security teams are often confronted with an unknown file/URL/domain/IP address and asked to make sense of an attack. Without further context, it is virtually impossible to determine attribution, build effective defenses against other strains of the attack, or understand the impact of a given threat in your organization. Through API and web based interaction with Google Threat Intelligence, security analysts can rapidly build a picture of an incident and then use those insights to neutralize other attacks.

Outcome. Faster, more confident, more accurate and more cost-effective security operations.

Where. On-premise, in the cloud, in your hosting, in your corporate network, everywhere.

What we solve for leaders.

Security team challenges Solving with Google Threat Intelligence + XSOAR
Alert fatigue + quality & speed of IR handling. PANW survey data shows that SOC analysts are only able to handle 14% of alerts generated by security tools. Eradicate analyst burnout through automation. Automate false positive discarding and alert prioritization, optimize SOC resources. Malicious+Benign info.
Lack of context & missed threats. Reliance on reactive threat feeds. Only information about internal systems and users, no in-the-wild contextual details. Improved and early detection. Track threats going forward with YARA. Crowdsourced threat reputation for files/hashes, domains, IPs and URLs coming from over 90 security vendors.
Finding and maintaining security talent. There is a shortage of qualified security candidates; recruiting + retaining these is an endemic challenge Juniors operating as advanced threat hunters. Automate repetitive tasks with playbooks, elevate SOC Level 1 effectiveness. Faster, more confident and more accurate decisions. Greater productivity.
Budget constraints. Cybersecurity isn’t top of mind at many organizations when budget line items are getting funded. Difficult to prove ROI. Condense & lower costs + Increase toolset ROI. One-stop-shop for everything threat intelligence related (domains, IPs, URLs, files). Take your SIEM, IDS, EDR, Firewall, etc. to the next level.

Use cases.

Example questions we answer.

Technical capabilities

Popular tasks

Additional information