Forum Discussion
Ingest IOC from Google Threat Intelligence into Sentinel
Hello HA13029 ,
Were you able to resolve this issue?
I attempted to look at the documentation here -Google Threat Intelligence for MSFT Sentinel and the Documentation read that - "The API key used for the connection is user-specific. The IoC Stream is tied to a particular user's subscriptions in Google Threat Intelligence (such as collections, threat actors, and hunting rulesets)."
This should mean that The API key used for the connection is user specific. The IoC Stream is tied to a particular user's subscriptions in Google Threat Intelligence (such as collections, threat actors, and hunting rulesets).
The 403 Forbidden error would be happening because the free/public VirusTotal (Google Threat Intelligence) API key does not have permission to access the endpoints used by the Sentinel ingestion playbooks. This integration requires a paid Google Threat Intelligence (VirusTotal Intelligence) subscription, not the free public API.