Threat Intelligence overview

Supported in:

Google Threat Intelligence provides a comprehensive and proactive approach to identifying, analyzing, and mitigating security threats. It uses Google's vast infrastructure, global telemetry, and advanced analytics to deliver useful insights and improve your organization's security.

Google Threat Intelligence includes threat detection, analysis of malware and phishing campaigns, real-time threat alerts, and intelligence feeds that integrate seamlessly with security tools such as Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms.

You can integrate and use Google Threat Intelligence within Google SecOps using the following integration methods:

Applied Threat Intelligence (ATI)

This fully managed, native pipeline automatically curates and applies Google's threat intelligence.

  • License:
    • Google SecOps Enterprise+
  • Features:
    • Provides advanced automated threat intelligence capabilities.
    • Includes a fully built-in and managed integration that automatically uses the complete spectrum of Google, Mandiant, and VirusTotal intelligence to provide automated context, enrichment, and alerting without manual pipeline configuration.
    • Combines frontline expertise with the breadth of Google's visibility to deliver a unified view of the threat landscape.
    • Lets security teams contextualize alerts, understand threat actor tactics, and use intelligence directly within their workflows.
  • Integration steps: See Applied Threat Intelligence overview.

Bring your own license (BYOL) Google Threat Intelligence integration

This customer-deployed pipeline ingests licensed Google Threat Intelligence (GTI) data (Threat Lists, IoC Streams, and adversary context) into Google SecOps. This method lets you deploy and manage resources (such as Cloud Run functions, Cloud Scheduler, Secret Manager) in your Google SecOps environment to fetch data from the Chronicle API and stream it to Google SecOps.

  • License:
    • Google SecOps Standard or Enterprise.
    • An active Google Threat Intelligence license to use the Bring Your Own License (BYOL) integration.
    • The Enterprise+ license includes permissions for the BYOL integration.
  • Features:
    • Lets you use a customer-deployed pipeline to ingest your data into Google SecOps for enhanced detection and threat hunting.
    • Replaces legacy fragmented connectors with a single, unified solution.
  • Integration steps: See BYOL Threat Intelligence integration.

Integrate your own threat intelligence feeds

This integration method lets you ingest custom or third-party Indicators of Compromise (IoCs) and threat intelligence feeds (such as MISP, STIX/TAXII, commercial threat intelligence providers, or custom CSV and JSON lists) directly into Google SecOps. Google SecOps parses incoming feeds into the Unified Data Model (UDM) Entity Context Graph (ECG) to support automated IoC matching against event telemetry, retrohunting across up to 30 days of data, and custom YARA-L rule detections.

  • License:
    • Available across Google SecOps license tiers.
  • Features:
    • Ingests third-party threat feeds using native Google SecOps feeds (such as Cloud Storage, HTTPS, Amazon S3, STIX/TAXII, and MISP).
    • Normalizes threat indicators and contextual metadata directly into UDM entity records (such as DOMAIN_NAME, IP_ADDRESS, FILE, and URL) with interval validity windows.
    • Correlates incoming telemetry against your custom threat intelligence feeds in near-real time and retroactively.
    • Supports threat detection through automatic IoC matching and custom YARA-L correlation rules.
  • Integration steps: See Integrate your own threat intelligence feeds.

Need more help? Get answers from Community members and Google SecOps professionals.