From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence
ID: 679dddfa-e7ec-5735-9e14-f3d0debe84bf
STIX ID: report--679dddfa-e7ec-5735-9e14-f3d0debe84bf
Feed Name: Elastic Security Labs
This report is an overview of Elastic Security's Google Threat Intelligence (GTI) integration, explaining how GTI indicators (IPs, domains, URLs, file hashes) are ingested into Elasticsearch using two data streams (Threat List and IOC Stream), normalized to ECS, and used for indicator-match detections, threat hunting, dashboards, and AI-driven enrichment via Elastic Workflows and Agent Builder; it is a feature/integration guide, not an incident or threat report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
