Elastic Security now natively integrates Google Threat Intelligence (GTI), enabling SOC teams to match known-malicious IPs, domains, URLs, and file hashes against their telemetry in real time. Setup requires only a GTI API key and configuring two data streams — a curated Threat List for high-confidence detections and an IOC Stream for broader threat hunting. Indicators are standardized via ECS and enriched with verdicts, severity ratings, and 0–100 threat scores. Prebuilt indicator match rules and dashboards activate automatically. For ambiguous indicators, Elastic Workflows and Agent Builder can query VirusTotal live, enrich alerts, correlate with telemetry, and summarize findings. The integration covers 14 threat categories including ransomware, phishing, infostealers, and threat actors.

6m read timeFrom elastic.co
Post cover image
Table of contents
How threat intelligence works in Elastic SecurityWhat Google Threat Intelligence providesHow the Google Threat Intelligence integration works in Elastic SecurityUsing Google Threat Intelligence for indicator match detectionsThreat hunting with GTI indicators in Elastic SecurityMonitoring threat intelligence activity with GTI dashboardsAgentic enrichment and real-time triage with Elastic WorkflowsGetting started with Google Threat Intelligence in Elastic SecurityTying it all together
218 Impressions