---
title: "Google Threat Intelligence in Elastic Security — Elastic Security Labs"
url: https://daily.dev/posts/google-threat-intelligence-in-elastic-security-elastic-security-labs-y7jy3yh81
source_url: https://www.elastic.co/security-labs/elastic-security-google-threat-intelligence
type: article
source: "Elastic Security Labs"
published: 2026-06-02T00:10:34.133Z
updated: 2026-06-02T00:10:56.804Z
tags: ["security", "elk"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Threat Intelligence in Elastic Security — Elastic Security Labs

**[Elastic Security Labs](https://daily.dev/sources/elastic-security-labs)** · 6 min read · 0 upvotes · 0 comments

## Summary

Elastic Security now natively integrates Google Threat Intelligence (GTI), enabling SOC teams to match known-malicious IPs, domains, URLs, and file hashes against their telemetry in real time. Setup requires only a GTI API key and configuring two data streams — a curated Threat List for high-confidence detections and an IOC Stream for broader threat hunting. Indicators are standardized via ECS and enriched with verdicts, severity ratings, and 0–100 threat scores. Prebuilt indicator match rules and dashboards activate automatically. For ambiguous indicators, Elastic Workflows and Agent Builder can query VirusTotal live, enrich alerts, correlate with telemetry, and summarize findings. The integration covers 14 threat categories including ransomware, phishing, infostealers, and threat actors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.elastic.co/security-labs/elastic-security-google-threat-intelligence>

## Similar posts on daily.dev

- [Turning Indicators into Intelligence in OpenCTI with Criminal IP](https://daily.dev/posts/turning-indicators-into-intelligence-in-opencti-with-criminal-ip-3w8hjczcs) · BleepingComputer · 0 upvotes · 0 comments
- [Intelligent threat detection for defence SOCs](https://daily.dev/posts/intelligent-threat-detection-for-defence-socs-fn9ynschv) · elastic · 0 upvotes · 0 comments
- [Introducing the Emerging Threats Center in Google Security Operations](https://daily.dev/posts/introducing-the-emerging-threats-center-in-google-security-operations-iplzmx4ad) · Google Cloud · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#elk](https://daily.dev/tags/elk)

[View this post on daily.dev](https://daily.dev/posts/google-threat-intelligence-in-elastic-security-elastic-security-labs-y7jy3yh81)
