Enriching Data with Google Threat Intelligence

Google Threat Intelligence (GTI) analyzes domains, hashes, IPs, and URLs to detect malware, malicious behavior, and other security threats.

After activating the Google Threat Intelligence enrichment, you can leverage Google Threat Intelligence data on Explore.

Enrichment data and threat insights are also displayed in the Enrichments section on observable details pages.

(Click the image to enlarge it)

Where data is available, the Google Threat Intelligence enrichment returns the following information for each observable type:

Observable Type Enrichment Data
Domains

GTI Assessment, Last Analysis Stats, Community Score, Last Analysis Results, Passive DNS Replication, Observed Subdomains, Downloaded Files, Communicating Files, and URLs.

Hashes GTI Assessment, Basic Properties, Other Hashes, History, Last Analysis Stats, Community Score, and Last Analysis Results.
IP

GTI Assessment, Autonomous System, Communicating Files, Country, Domain Replication, Downloaded Files, Passive DNS Replication, and URLs.

URLs GTI Assessment, Last Analysis Stats, Community Score, and Last Analysis Results.
Note: An Enterprise+ subscription to Google Threat Intelligence is required to view GTI Assessment details.

To activate the Google Threat Intelligence enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.
  2. Click Get Access on the Google Threat Intelligence tile.
  3. Click I have credentials.
  4. In the Limit field, enter a maximum number of entities that you want to be returned per a transform request.
  5. Enter your GTI API Key. Refer to How to get Google Threat Intelligence API Keys for details on how to obtain your GTI API Key.
  6. Click Activate.

The Google Threat Intelligence enrichment is now active.