logo

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

ID: 679dddfa-e7ec-5735-9e14-f3d0debe84bf

STIX ID: report--679dddfa-e7ec-5735-9e14-f3d0debe84bf

Feed Name: Elastic Security Labs

Date Published: 2026-06-02

Date Updated: 2026-06-03

...
...

This report is an overview of Elastic Security's Google Threat Intelligence (GTI) integration, explaining how GTI indicators (IPs, domains, URLs, file hashes) are ingested into Elasticsearch using two data streams (Threat List and IOC Stream), normalized to ECS, and used for indicator-match detections, threat hunting, dashboards, and AI-driven enrichment via Elastic Workflows and Agent Builder; it is a feature/integration guide, not an incident or threat report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.