Google Threat Intelligence for SecOps
by Google LLC
GTI: Unified threat intelligence from Mandiant, VirusTotal & Google.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 5 | -5 |
| 146 days of no change | ||
| 2025-12-01 | 4 | +1 |
| 6 days of no change | ||
| 2025-11-24 | 3 | +1 |
| 35 days of no change | ||
| 2025-10-19 | 2 | +1 |
| 3 days of no change | ||
| 2025-10-15 | 1 | +1 |
| 1 days of no change | ||
| 2025-10-13 | 0 | +1 |
About
The Google Threat Intel & SIR Integration for ServiceNow brings alert ingestion, security incident automation, and observable enrichment into a single, unified workflow. It enables security teams to ingest high-fidelity DTM (Detection & Threat Management), ASM (Attack Surface Management) alerts and RSA (Relevance System Alerts) from Google Threat Intelligence (GTI)—which blends Mandiant's frontline insights, VirusTotal's vast malware data, and broader Google visibility—and automatically create Security Incidents in ServiceNow for streamlined triage.
The integration also supports scheduled fetching of Indicators of Compromise (IoCs) from GTI, created as observables within ServiceNow. Analysts can enrich these observables with unparalleled context, perform threat lookups, and submit files for sandbox analysis without switching platforms. Additionally, security incident state updates in ServiceNow automatically sync back to the GTI platform for full lifecycle management.
This app reduces manual investigation, provides unparalleled visibility across threat data, and enables faster detection-to-resolution workflows—ideal for SOC teams, threat intel analysts, and incident responders seeking an actionable, intelligence-led defense.
Key Features
- Ingest filtered DTM, ASM and RSA alerts from GTI into ServiceNow
- Create custom table records for each DTM/ASM/RSA alert
- Automatically generate Security Incidents and link them to the respective custom DTM/ASM/RSA records
- Scheduled fetching of IoC streams and automatic creation of observables
- Run threat lookups, enrichment, and sandbox submissions directly in ServiceNow
- Sync incident state changes back to GTI for lifecycle alignment