logo

NJP

Google Threat Intelligence for SecOps

Google Threat Intelligence for SecOps

by Google LLC

GTI: Unified threat intelligence from Mandiant, VirusTotal & Google.

0 installs 0 reviews v2.0.0 Scoped Application Free (integration tables[10] not counted) 10 tables

Install Trend

First tracked: 2025-10-02 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 5 -5
146 days of no change
2025-12-01 4 +1
6 days of no change
2025-11-24 3 +1
35 days of no change
2025-10-19 2 +1
3 days of no change
2025-10-15 1 +1
1 days of no change
2025-10-13 0 +1

About

The Google Threat Intel & SIR Integration for ServiceNow brings alert ingestion, security incident automation, and observable enrichment into a single, unified workflow. It enables security teams to ingest high-fidelity DTM (Detection & Threat Management), ASM (Attack Surface Management) alerts and RSA (Relevance System Alerts) from Google Threat Intelligence (GTI)—which blends Mandiant's frontline insights, VirusTotal's vast malware data, and broader Google visibility—and automatically create Security Incidents in ServiceNow for streamlined triage.

The integration also supports scheduled fetching of Indicators of Compromise (IoCs) from GTI, created as observables within ServiceNow. Analysts can enrich these observables with unparalleled context, perform threat lookups, and submit files for sandbox analysis without switching platforms. Additionally, security incident state updates in ServiceNow automatically sync back to the GTI platform for full lifecycle management.

This app reduces manual investigation, provides unparalleled visibility across threat data, and enables faster detection-to-resolution workflows—ideal for SOC teams, threat intel analysts, and incident responders seeking an actionable, intelligence-led defense.

 

Key Features

- Ingest filtered DTM, ASM and RSA alerts from GTI into ServiceNow
- Create custom table records for each DTM/ASM/RSA alert
- Automatically generate Security Incidents and link them to the respective custom DTM/ASM/RSA records
- Scheduled fetching of IoC streams and automatic creation of observables
- Run threat lookups, enrichment, and sandbox submissions directly in ServiceNow
- Sync incident state changes back to GTI for lifecycle alignment

 

Version History (2)
v2.0.0 2026-09-07 13:25:56
ServiceNow Australia support Relevance System Alerts support
v1.0.0 2025-10-02 08:17:31
Brand new integration to ingest filtered DTM and ASM alerts from Google Threat Intelligence into ServiceNow by creating records in custom table and...
ID: 94ebc2281b0d66104694a932604bcb14 · Published: Sep 2026 · Updated: Sep 09, 2026