
Jul 30, 2025
2.0.0
ThreatQ versions >= 5.12.1
Google Threat Intelligence CDF
Overview
Google is on a mission to make every organization secure from cyber threats and confident in its readiness. They deliver dynamic cyber defense solutions powered by industry-leading expertise, intelligence, and innovative technology.
The Google Threat Intelligence CDF integration provides the following feeds:
- Google Threat Intelligence - ingests compromised Adversaries objects and any related Indicators, Malware, Vulnerabilities, Attack Patterns, and Tags.
- Google Threat Intelligence Related Malware (Supplemental) - returns associated collections of malware family objects.
- Google Threat Intelligence Related Attack Pattern (Supplemental) - fetches related attack patterns.
- Google Threat Intelligence Related Vulnerabilities (Supplemental) - fetches related CVEs.
- Google Threat Intelligence Related Campaigns (Supplemental) - returns associated collections of campaign objects.
- Google Threat Intelligence Related IOC (Supplemental) - fetches related indicators to threat actors.
- Google Threat Intelligence Related Adversaries (Supplemental) - fetches related adversaries.
- Google Threat Intelligence Campaigns - ingests a list of campaigns tracked by Google Threat Intelligence.
- Google Threat Intelligence Indicators - ingests a list of indicators tracked by Google Threat Intelligence.
- Google Threat Intelligence Malware - ingests a list of malware tracked by Google Threat Intelligence.
- Google Vulnerability Intelligence - ingests a list of vulnerabilities tracked by Google Threat Intelligence.
The integration ingests the following system objects:
- Adversaries
- Attack Patterns
- Campaigns
- Indicators
- Malware
- Vulnerabilities