NEW RESEARCH! From WordPress Patch to Mass Exploitation in 2 days. Read here.
Product Updates

ELLIO for Google SecOps: Visibility into Live Attacker Recon and Exploitation

6 min read

ELLIO provides two integrations for Google Security Operations that incorporate its external reconnaissance, internet-wide scanning, and mass exploitation intelligence into Google Security Operations workflows.

Logo ELLIO and logo Google SecOps on dark blue background
  • ELLIO Threat Intelligence Content Pack adds reconnaissance and exploitation intelligence to entity context, IoC matching, detection content, and dashboards. The content pack enables detections and investigations to be correlated with observed attacker reconnaissance and exploitation activity.
  • ELLIO SecOps Response Integration, available through the Google Security Operations  Content Hub, provides enrichment and response actions that can be used directly in cases and playbooks. Analysts can query external intelligence during investigations or automate enrichment as part of response workflows.

The two integrations address different parts of the investigation lifecycle and can be deployed independently. When used together, reconnaissance and exploitation intelligence becomes available from initial detection through investigation and response, allowing increased correlation between internal telemetry and externally observed attacker activity.

Start Free Trial

No credit card required.

Start free trial

1. ELLIO Threat Intelligence Content Pack 

The ELLIO Threat Intelligence Content Pack integrates continuously maintained reconnaissance, scanning, and mass exploitation intelligence into Google Security Operations.

 Content Pack Components:

  • UDM Parser for ingesting ELLIO threat intelligence into the Google Security Operations  Unified Data Model (UDM).
  • Six reference YARA-L rules covering reconnaissance and exploitation with severity logic, tuning guidance, and CVE watchlist support.
  • Google Security Operations  dashboard providing operational visibility into indicator ingestion and intelligence distribution.

1.1 Indicators as UDM Entities 

ELLIO indicators are ingested as IP_ADDRESS UDM entities, making its external intelligence available directly during investigations, rule execution, and entity lookups.

Each entity includes enriched context such as:

  • Threat verdict
  • Risk score
  • Associated CVEs
  • Behavior tags
  • MuonFP fingerprints
  • JA3/JA4 fingerprints

This context lets you quickly understand whether an external IP address has been associated with reconnaissance or exploitation activity, assess the relevance of a match, and add evidence to investigations without manually querying external intelligence sources.

The indicator set is continuously maintained and integrated with the Google Security Operations  indicator lifecycle. Indicators automatically expire when they no longer represent relevant activity, reducing stale intelligence while preserving high-confidence context.

1.2 Reference Detection Rules, Severity-Graded

The content pack includes six reference YARA-L detection rules designed to identify reconnaissance, scanning, and exploitation activity.

The rules help you distinguish routine internet background noise from activity that warrants investigation. They include tuning guidance and optional CVE watchlist support, allowing you to adapt detection logic to your environment and prioritize exploitation attempts targeting vulnerabilities that matter to your organization.

Severity reflects both observed behavior and confidence:

  • LOW - reconnaissance and scanning activity
  • MEDIUM - exploitation-related activity where malicious intent is clearer but compromise is not yet confirmed
  • HIGH - high-confidence activity, including exploitation attempts against CVEs on the watchlist, communication with persistent malicious infrastructure, or outbound connections from internal assets to known attacker infrastructure.

1.3 Dashboards Answering Daily Questions

The content pack includes a Google Security Operations  dashboard that provides operational visibility into current ELLIO intelligence activity without requiring you to build custom queries.

The dashboard helps you understand the scope and characteristics of observed attacker infrastructure, track changes in the active indicator set, and monitor intelligence ingestion status.

You gain visibility into the current intelligence state without requiring custom queries:

  • Active indicators and current intelligence coverage
  • Threat classification distribution
  • Risk score distribution
  • Geographic distribution of observed infrastructure
  • Feed health and ingestion status

This allows you to quickly assess the current threat landscape represented by ELLIO intelligence and verify that indicators are being continuously ingested into Google Security Operations .

Image includes the google secops dashboard with real-time threat intelligence context provided by ELLIO Reconnnaissance and mass exploitation threat intelligence.

1.4 IoC Matches, Hands-free

For Google Security Operations  Enterprise deployments, ELLIO indicators participate in native IoC Matching.

Events matching active indicators appear in the IoC Matches view with attribution to the ELLIO feed, allowing you to pivot directly from a matching event to the associated intelligence during investigations.

Google SecOps ELLIO IoC Matches

1.5 Configurable Indicator Decay

Organizations can control which indicators are imported into Google Security Operations .

During deployment, indicators can be filtered by their classification:

  • Malicious
  • Promiscuous
  • Unknown
  • Benign
Google SecOps Configurable Indicator Decay

Risk scores assigned to each category are also configurable, allowing you to align imported intelligence with your existing scoring model, alert thresholds, and detection priorities.

Google SecOps ELLIO Risk Scoring

2. ELLIO SecOps Response Integration 

The integration, available through the Google Security Operations  Content Hub, adds ELLIO investigation and response actions directly into Google Security Operations  cases.

ELLIO SecOps Response Integration for Google Security Operations

You gain access to external attacker context during investigations without leaving the case workflow, including threat intelligence details, infrastructure information, and response options. Enriched entity context can also be used during investigation analysis and referenced by case summaries generated by Google’s Gemini models.

ELLIO SecOps Response Integration for Google Security Operations

2.1 Investigation and Response Actions

  • Enrich IP - Adds ELLIO threat context to an entity, including threat verdict, risk information, suspicious activity classification, and recommended case priority.
  • CBS Lookup - Provides infrastructure context to distinguish cloud, CDN, and SaaS services from potentially attacker-controlled hosts.
  • Add IP to Blocklist - Sends selected IP addresses to an ELLIO Blocklist Automation ruleset for enforcement workflows.

If you use playbooks to automatically enrich your alerts and cases, Gemini models can  use the ELLIO enrichment when generating summaries and investigation context.

2.2 Blocklist Automation Integration

If you use ELLIO Blocklist Automation, you can use the Response Integration to push IP addresses from Google Security Operations  into the enforcement workflows. Pushed indicator name is automatically enriched with related SecOps case and alert. This maintains traceability between the original investigation and the resulting block action.

3. Combined Investigation Workflow

Using security event management and response integrations provides external attacker context across the full SecOps lifecycle. It combines internal security telemetry with externally observed attacker activity, from initial detection through investigation and response.

A typical workflow combining both security event management and response releases:

  1. A security event contains communication with an external IP address.
  2. The event management  content pack evaluates the event against active ELLIO intelligence through entity context, YARA-L rules, or IoC matching.
  3. An ELLIO match provides context about observed reconnaissance and exploitation activity associated with the IP address.
  4. The response integration enriches the entity and/or case with additional extended intelligence, automatically through playbooks or on demand.
  5. Response actions, such as adding the IP address to an ELLIO Blocklist Automation ruleset, can be initiated based on investigation findings.

4. Choosing the Right Integration

Use the Response Integration when you need to:

  • Enrich existing alerts and cases with reconnaissance and exploitation intelligence.
  • Provide additional context for investigations and case summaries generated by Gemini models.
  • Trigger response actions from cases, alerts, or playbooks.
  • Automate IP blocking workflows through ELLIO Blocklist Automation.

Use the Event Mangement Content Pack when you need to:

  • Create detections based on reconnaissance and exploitation activity.
  • Identify reconnaissance waves targeting your infrastructure.
  • Detect communication with persistent malicious infrastructure.
  • Use ELLIO intelligence in entity context, IoC matching, dashboards, and YARA-L rules.

5. Getting Started

Both releases  require access to Google Security Operations and an ELLIO API key.

  • Event Management Content Pack: Configure the ELLIO feed in the ELLIO Platform and import the content pack to enable entity enrichment, detection rules, and dashboards.
  • Response Integration: Install the integration from the Google Security Operations  Content Hub to enable case actions and automated enrichment playbooks.

6. Support



Written by

ELLIO Product Team
ELLIO Product Team

A team of product specialists and innovative engineers building solutions that turn ELLIO’s research and intelligence on mass exploitation and network reconnaissance into real-world tools.