What Changed

Added filter query parameter support to the Google Threat Intelligence custom connector, enabling users to apply specific filters when retrieving threat lists and IoC streams.

Enhanced Capabilities

  • Threat List queries now support optional filter parameters for more targeted data retrieval
  • IoC Stream functionality introduced with filter-based searching and pagination support
  • Maintains backward compatibility with existing playbook implementations

Security Impact

Improves threat intelligence precision by allowing filtered queries instead of bulk data retrieval. Organizations can now target specific threat categories, reduce noise, and focus on relevant indicators for their environment.

Affected Files

Solutions/Google Threat Intelligence/Playbooks/CustomConnector/GTICustomConnector/azuredeploy.json Solutions/Google Threat Intelligence/Playbooks/CustomConnector/GTICustomConnector/readme.md (packaging artefacts: mainTemplate.json, Solution metadata, ReleaseNotes.md)