LIVE · cybersecurity feed
Live wire
threat intelligencemedium

From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence

Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.

zeroday.news · 60d ago

Elastic Security now offers native integration with Google Threat Intelligence (GTI), allowing security teams to ingest known malicious indicators and leverage AI-driven workflows for real-time alert enrichment and investigation. This integration aims to streamline the process from initial setup to live threat detection within minutes.

The GTI integration brings curated threat intelligence directly into Elastic Security, providing actionable data for both detection and investigation. GTI combines Google's global security insights with VirusTotal data to offer context on indicators of compromise (IOCs) related to malware, ransomware, phishing, and other adversarial activities. Each indicator is furnished with a verdict (Malicious, Suspicious, or Undetected), a severity level, and a composite threat score ranging from 0 to 100. This score, derived from multiple signals, enables security teams to prioritize indicators based on confidence.

Setting up the integration is designed to be straightforward, requiring only a GTI API key. Once configured, ingestion begins automatically at a scheduled interval, without the need for additional infrastructure. The integration pulls data from two primary streams: the Threat List IOC Stream, intended for high-confidence detection and precision-critical alerting, and the Purpose IOC Stream, which offers broader coverage for threat hunting and early visibility into emerging threats.

As data is ingested, indicators are standardized using the Elastic Common Schema (ECS). This process includes GTI's contextual information, such as verdicts, severity, threat scores, malware families, and threat actor associations. This standardization allows GTI data to be searched and correlated seamlessly with other ECS-compliant intelligence sources, custom intelligence, and existing security telemetry within Elastic Security. Elastic also manages the lifecycle of these indicators, including their expiration and revocation, to prevent matches against outdated information.

With GTI data integrated, Elastic Security's indicator match rules can detect the presence of known malicious IP addresses, domains, URLs, or file hashes within security telemetry. This continuous correlation of intelligence against observed activity surfaces matches for investigation. Security teams can tune these detections based on the confidence provided by GTI's structured fields, allowing high-confidence indicators to trigger immediate escalations while lower-confidence ones can be routed for review.

For threat hunting, GTI metadata enables analysts to pivot from a single IOC to associated infrastructure and search historical telemetry. By enriching indicators with details like threat actor associations and malware family context, analysts can move beyond simple IOC searches and investigate entire campaigns or adversary activities. This capability allows for the identification of any past interactions between known malicious infrastructure and the organization's environment.

The integration also includes prebuilt dashboards that offer visibility into threat intelligence activity and the detections driven by GTI. These dashboards summarize observed threats across various categories, such as malware families, campaigns, and threat actors, helping Security Operations Center (SOC) teams understand prevalent threat types and how intelligence is being operationalized. GTI offers 14 categorized feed categories, including those for cryptominers, ransomware, phishing, and vulnerability exploitation, allowing organizations to tailor their coverage based on their subscription level and specific needs.

Complementing the ingestion of GTI data, Elastic Security supports AI-driven investigation through Agent Builder and Elastic Workflows. These features enable real-time enrichment and reasoning during an investigation, particularly for ambiguous or emerging indicators not yet present in indexed feeds. During alert triage, a workflow can query external services like VirusTotal for live context on IPs, domains, or file hashes, correlate this information with Elastic telemetry, and present a structured summary for analysts. Agent Builder further extends this by allowing teams to create reusable, task-specific capabilities for alert triage, enrichment, and case handling, enabling multi-step investigative tasks to be executed consistently. This dual approach of continuous detection via ingested intelligence and on-demand enrichment via agentic workflows aims to help teams detect known threats at scale and provide crucial context for investigations, enabling faster, more confident decision-making.

threat intelligenceelastic securitygooglesocdetection
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.