Elastic Security now natively integrates Google Threat Intelligence (GTI), enabling SOC teams to match known-malicious IPs, domains, URLs, and file hashes against their telemetry in real time. Setup requires only a GTI API key and configuring two data streams — a curated Threat List for high-confidence detections and an IOC Stream for broader threat hunting. Indicators are standardized via ECS and enriched with verdicts, severity ratings, and 0–100 threat scores. Prebuilt indicator match rules and dashboards activate automatically. For ambiguous indicators, Elastic Workflows and Agent Builder can query VirusTotal live, enrich alerts, correlate with telemetry, and summarize findings. The integration covers 14 threat categories including ransomware, phishing, infostealers, and threat actors.