Enriching Data with Google Threat Intelligence
Google Threat Intelligence (GTI) analyzes domains, hashes, IPs, and URLs to detect malware, malicious behavior, and other security threats.
After activating the Google Threat Intelligence enrichment, you can leverage Google Threat Intelligence data on Explore.
Google Threat Intelligence enables the following data transformations:
- C2Host to Hash
- C2IP to Hash
- Domain to Detected URL
- Domain to IP
- Domain to Subdomain
- Enrich Domain
- Enrich Hash
- Enrich IP
- Enrich URL
- Hash to AV Detection
- Hash to Behavior
- Hash to C2Host
- Hash to C2IP
- Hash to C2URL
- Hash to Carbonblack Parent
- Hash to Compressed Parent
- Hash to Emailparent
- Hash to Embedded URLs, Domains, and IPs
- Hash to Execution Parent
- Hash to Filename
- Hash to Filesize
- Hash to Filetype
- Hash to First Seen
- Hash to Import
- Hash to ITW
- Hash to MD5
- Hash to Mutex
- Hash to PE Debug
- Hash to Peresource
- Hash to Rescan
- Hash to Section
- Hash to SHA1
- Hash to SHA256
- Hash to Submission
- Hash to Submitter ID
- Hash to Tag
- Hash to Timestamp
- Hash to Total Votes
- Hash to Useragent
- Hash to VHash
- Host to Downloaded Hash
- Imphash to Hash
- IP to Detected URL
- IP to Domain
- IP to Downloaded Hash
- URL to Analysis
- URL to Communicating Files
- URL to Contacted Domains
- URL to Contacted IPs
- URL to Downloaded Files
- URL to Embedded JS Files
- URL to Last Serving IP
- URL to Redirecting URLs
- URL to Redirects to URLs
- URL to Referrer Files
- URL to Referrer URLs
- URL to Submitter ID
- URL to Total Votes
Enrichment data and threat insights are also displayed in the Enrichments section on observable details pages.
(Click the image to enlarge it)
Where data is available, the Google Threat Intelligence enrichment returns the following information for each observable type:
| Observable Type | Enrichment Data |
|---|---|
| Domains |
GTI Assessment, Last Analysis Stats, Community Score, Last Analysis Results, Passive DNS Replication, Observed Subdomains, Downloaded Files, Communicating Files, and URLs. |
| Hashes | GTI Assessment, Basic Properties, Other Hashes, History, Last Analysis Stats, Community Score, and Last Analysis Results. |
| IP |
GTI Assessment, Autonomous System, Communicating Files, Country, Domain Replication, Downloaded Files, Passive DNS Replication, and URLs. |
| URLs | GTI Assessment, Last Analysis Stats, Community Score, and Last Analysis Results. |
To activate the Google Threat Intelligence enrichment:
- Navigate to ThreatStream > APP STORE > APP Store.
- Click Get Access on the Google Threat Intelligence tile.
- Click I have credentials.
- In the Limit field, enter a maximum number of entities that you want to be returned per a transform request.
- Enter your GTI API Key. Refer to How to get Google Threat Intelligence API Keys for details on how to obtain your GTI API Key.
- Click Activate.
The Google Threat Intelligence enrichment is now active.
