• Last Updated
    Sep 3, 2025
  • Version
    1.1.0
  • Compatibility
    ThreatQ Versions >= 6.0.0
  • Google SecOps IOC Exporter Action

    ThreatQuotient

    Overview

    The Google SecOps IOC Exporter Action for ThreatQ enables the automatic dissemination of IOCs from a ThreatQ data collection to Google SecOps. The exported IOCs are exported in the UDM format, as entities. The UDM format is a universal JSON format that is compatible with SecOps’ API. These entities can then be used within SecOps’s rules editor (YARA-L) to create rules to trigger alerts.
     
    The integration provides the following action:
    • Google SecOps IOC Exporter - enables the automatic dissemination of IOCs from a ThreatQ data collection to Google SecOps.
    The action is compatible with the following indicator types:
    • Email Address
    • FQDN
    • IP Address
    • IPv6 Address
    • MD5
    • SHA-1
    • SHA-256
    • URL
    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy