OpenCTI and Google SecOps SOAR: Threat Intel Flows Both Ways

- Bi-directional integration: connects OpenCTI and Google SecOps SOAR so threat intel and case data flow automatically between platforms, cutting manual switching between tools.
- Enrich cases instantly: analysts can pull relevant OpenCTI threat intelligence (actors, TTPs, related indicators) directly into a Google SecOps case in seconds, no manual cross-referencing required.
- Sync findings back automatically: indicators, observables, incidents, and relationships discovered during SecOps investigations are pushed back into OpenCTI, continuously enriching the knowledge base.
- Completes the loop with existing connectors: combined with the Google SecOps SIEM Incidents (Import) and SIEM (Stream) integrations, Filigran now offers a full bi-directional flow across detection, hunting, and response.
- Built for automation: exposed as atomic actions, the integration can be wired into existing SOAR playbooks for hands-off enrichment and sync at scale.
An analyst spots a suspicious indicator in Google SecOps. Understanding it costs a tab switch, a manual search in OpenCTI, and a few minutes they don't get back. The new Google SecOps and OpenCTI integration, built jointly by Filigran and Google, closes that gap: a bi-directional connection that moves threat intelligence and case data automatically in both directions. Context now surfaces right where the analyst is already working, as part of the same investigation.
Google SecOps unifies Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) into a single cloud-native platform. It ingests enterprise telemetry, normalizes it through a Unified Data Model (UDM), runs threat detections against the normalized data, and automates incident response workflows. That combination, detection and response in one place, is exactly why bringing OpenCTI's intelligence directly into the platform has such an outsized impact on investigation speed and quality.
Bi-Directional OpenCTI and Google SecOps Integration
Filigran provides an application that deploys directly within the Google SecOps environment and connects it to OpenCTI. Once deployed, it exposes a set of atomic actions that analysts can trigger manually, or that can be orchestrated automatically through Google SecOps SOAR playbooks.
With these actions, teams can:
- Enrich case data with threat intelligence: query OpenCTI directly from within a Google SecOps case to pull in relevant threat intel and contextual information: no need to switch platforms mid-investigation.
- Push case findings back into OpenCTI: automatically create or update OpenCTI objects including indicators, observables, incidents, and their relationships, based on events, alerts, or case data originating in Google SecOps SOAR.
OpenCTI enrichment surfaced directly inside a Google SecOps case, no tab-switching required
The result: analysts get rich context instantly, and the intelligence generated during incident response flows straight back into OpenCTI, strengthening the knowledge base for future investigations.
Investigating a Suspicious IP: An OpenCTI and Google SecOps Example
A SecOps case is opened after a detection rule flags outbound traffic to an unfamiliar IP address. Instead of manually pivoting to threat intel sources, the analyst triggers an OpenCTI enrichment action directly from the case. Within seconds, OpenCTI returns:
- The IP is a known command-and-control (C2) server linked to a specific threat actor (such as an advanced persistent threat (APT) group tracked in OpenCTI).
- Related indicators, including associated domains, file hashes, and malware families seen in past campaigns.
- The Tactics, Techniques, and Procedures (TTPs) typically used by that actor, mapped to MITRE ATT&CK.
- Any prior incidents or cases where this actor or infrastructure appeared.
An OpenCTI-enriched indicator, viewed directly from within Google SecOps
With this context surfaced directly within the Google SecOps case, the analyst can immediately assess severity, escalate appropriately, and check for related activity elsewhere in the environment, without cross-referencing intel manually. And if the investigation confirms malicious activity, the new observable and any newly identified relationships are synced back into OpenCTI automatically, enriching the platform for the next analyst who encounters that actor or infrastructure.
Bridging Detection and Intelligence Between OpenCTI and Google SecOps
SOC teams live in their SIEM/SOAR platform. If threat intelligence isn't available where analysts are already working, it slows investigations down and creates gaps between what's known (in OpenCTI) and what's happening (in Google SecOps). This integration removes that friction:
- Faster triage: analysts get OpenCTI context (actors, campaigns, TTPs, related indicators) directly inside a case, without leaving Google SecOps.
- Higher-fidelity intelligence: observables and incidents discovered during real investigations flow back into OpenCTI automatically, improving the platform's accuracy over time.
- Automation at scale: because the actions are exposed atomically, they can be wired into existing SOAR playbooks, so enrichment and sync happen without manual analyst effort.
Wiring OpenCTI enrichment into an automated Google SecOps SOAR playbook
In short, this puts OpenCTI's threat intelligence to work directly inside SecOps workflows, turning cyber threat intelligence (CTI) from a reference tool into an active part of detection and response.
Two More Ways OpenCTI Connects to Google SecOps
The new SOAR integration builds on two connectors Filigran already provides for Google SecOps SIEM:
- Google SecOps SIEM Incidents (Import): this connector automatically imports SIEM rule alerts as incidents in OpenCTI, enriched with related observables (IPs, host names, user accounts, files, URLs) and STIX relationships.
- Google SecOps SIEM (Stream): this connector streams OpenCTI threat intelligence indicators into Google SecOps SIEM in real time. It consumes indicators from an OpenCTI stream, converts them into UDM entities, and pushes them into Google SecOps SIEM via the entities.import API, enabling detection rule management and indicator-based threat hunting.
The full bi-directional flow: intelligence and case data moving both ways between OpenCTI and Google SecOps
Together, these three integrations create a full loop across the Google SecOps stack:
- SIEM Incidents (Import)
- Direction: Google SecOps to OpenCTI
- What it does: Imports SIEM alerts as enriched incidents
- SIEM (Stream)
- Direction: OpenCTI to Google SecOps
- What it does: Streams indicators into SecOps for detection and hunting
- SOAR (new)
- Direction: Bi-directional
- What it does: Enriches cases with CTI; syncs indicators, observables, and incidents back into OpenCTI
Get Started With OpenCTI and Google SecOps
Technical details on deployment and the available atomic actions are documented on OpenCTI’s Google SecOps connector page. If your team is running Google SecOps and OpenCTI, this is a great way to bring intelligence and operations closer together, reducing manual work for analysts while improving the depth and accuracy of every investigation.
Have questions about deploying this integration in your environment? Reach out to your Filigran account team or book a demo to see it in action.
続きを読む
関連トピックとインサイトをご覧ください

OpenAEV v3: Adversarial Exposure Validation Goes Autonomous with Attack Chaining
