
Google Threat Intelligence ACT
Overview
The Google Threat Intelligence Action enables organizations to enrich supported indicators within ThreatQ by retrieving contextual intelligence from Google Threat Intelligence.
The integration provides the following action:
- Google Threat Intelligence - Enrich Indicators - enriches submitted indicators and fetches related Google Threat Intelligence context.
The integration is compatible with the following indicator types:
- FQDNs
- IP Address
- IPv6 Address
- MD5
- SHA-1
- SHA-256
- URL
The integration returns the following enriched object types:
- Adversaries
- Campaigns
- Indicators (IP, FQDN - WHOIS context attributes)
- Malware
- Reports
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.
index