ELLIO for Google SecOps: Visibility into Live Attacker Recon and Exploitation
ELLIO provides two integrations for Google Security Operations that incorporate its external reconnaissance, internet-wide scanning, and mass exploitation intelligence into Google Security Operations workflows.
ELLIO Threat Intelligence Content Packadds reconnaissance and exploitation intelligence to entity context, IoC matching, detection content, and dashboards. The content pack enables detections and investigations to be correlated with observed attacker reconnaissance and exploitation activity.ELLIO SecOps Response Integration, available through the Google Security Operations Content Hub, provides enrichment and response actions that can be used directly in cases and playbooks. Analysts can query external intelligence during investigations or automate enrichment as part of response workflows.
The two integrations address different parts of the investigation lifecycle and can be deployed independently. When used together, reconnaissance and exploitation intelligence becomes available from initial detection through investigation and response, allowing increased correlation between internal telemetry and externally observed attacker activity.
Start Free Trial
No credit card required.
1. ELLIO Threat Intelligence Content Pack
The ELLIO Threat Intelligence Content Pack integrates continuously maintained reconnaissance, scanning, and mass exploitation intelligence into Google Security Operations.
Content Pack Components:
UDM Parserfor ingesting ELLIO threat intelligence into the Google Security Operations Unified Data Model (UDM).Six reference YARA-L rulescovering reconnaissance and exploitation with severity logic, tuning guidance, and CVE watchlist support.Google Security Operations dashboardproviding operational visibility into indicator ingestion and intelligence distribution.
1.1 Indicators as UDM Entities
ELLIO indicators are ingested as IP_ADDRESS UDM entities, making its external intelligence available directly during investigations, rule execution, and entity lookups.
Each entity includes enriched context such as:
- Threat verdict
- Risk score
- Associated CVEs
- Behavior tags
- MuonFP fingerprints
- JA3/JA4 fingerprints
This context lets you quickly understand whether an external IP address has been associated with reconnaissance or exploitation activity, assess the relevance of a match, and add evidence to investigations without manually querying external intelligence sources.
The indicator set is continuously maintained and integrated with the Google Security Operations indicator lifecycle. Indicators automatically expire when they no longer represent relevant activity, reducing stale intelligence while preserving high-confidence context.
1.2 Reference Detection Rules, Severity-Graded
The content pack includes six reference YARA-L detection rules designed to identify reconnaissance, scanning, and exploitation activity.
The rules help you distinguish routine internet background noise from activity that warrants investigation. They include tuning guidance and optional CVE watchlist support, allowing you to adapt detection logic to your environment and prioritize exploitation attempts targeting vulnerabilities that matter to your organization.
Severity reflects both observed behavior and confidence:
LOW- reconnaissance and scanning activityMEDIUM- exploitation-related activity where malicious intent is clearer but compromise is not yet confirmedHIGH- high-confidence activity, including exploitation attempts against CVEs on the watchlist, communication with persistent malicious infrastructure, or outbound connections from internal assets to known attacker infrastructure.
1.3 Dashboards Answering Daily Questions
The content pack includes a Google Security Operations dashboard that provides operational visibility into current ELLIO intelligence activity without requiring you to build custom queries.
The dashboard helps you understand the scope and characteristics of observed attacker infrastructure, track changes in the active indicator set, and monitor intelligence ingestion status.
You gain visibility into the current intelligence state without requiring custom queries:
Active indicators and current intelligence coverageThreat classification distributionRisk score distributionGeographic distribution of observed infrastructureFeed health and ingestion status
This allows you to quickly assess the current threat landscape represented by ELLIO intelligence and verify that indicators are being continuously ingested into Google Security Operations .

1.4 IoC Matches, Hands-free
For Google Security Operations Enterprise deployments, ELLIO indicators participate in native IoC Matching.
Events matching active indicators appear in the IoC Matches view with attribution to the ELLIO feed, allowing you to pivot directly from a matching event to the associated intelligence during investigations.

1.5 Configurable Indicator Decay
Organizations can control which indicators are imported into Google Security Operations .
During deployment, indicators can be filtered by their classification:
MaliciousPromiscuousUnknownBenign

Risk scores assigned to each category are also configurable, allowing you to align imported intelligence with your existing scoring model, alert thresholds, and detection priorities.

2. ELLIO SecOps Response Integration
The integration, available through the Google Security Operations Content Hub, adds ELLIO investigation and response actions directly into Google Security Operations cases.

You gain access to external attacker context during investigations without leaving the case workflow, including threat intelligence details, infrastructure information, and response options. Enriched entity context can also be used during investigation analysis and referenced by case summaries generated by Google’s Gemini models.

2.1 Investigation and Response Actions
Enrich IP- Adds ELLIO threat context to an entity, including threat verdict, risk information, suspicious activity classification, and recommended case priority.CBS Lookup- Provides infrastructure context to distinguish cloud, CDN, and SaaS services from potentially attacker-controlled hosts.Add IP to Blocklist- Sends selected IP addresses to an ELLIO Blocklist Automation ruleset for enforcement workflows.
If you use playbooks to automatically enrich your alerts and cases, Gemini models can use the ELLIO enrichment when generating summaries and investigation context.
2.2 Blocklist Automation Integration
If you use ELLIO Blocklist Automation, you can use the Response Integration to push IP addresses from Google Security Operations into the enforcement workflows. Pushed indicator name is automatically enriched with related SecOps case and alert. This maintains traceability between the original investigation and the resulting block action.
3. Combined Investigation Workflow
Using security event management and response integrations provides external attacker context across the full SecOps lifecycle. It combines internal security telemetry with externally observed attacker activity, from initial detection through investigation and response.
A typical workflow combining both security event management and response releases:
- A security event contains communication with an external IP address.
- The event management content pack evaluates the event against active ELLIO intelligence through entity context, YARA-L rules, or IoC matching.
- An ELLIO match provides context about observed reconnaissance and exploitation activity associated with the IP address.
- The response integration enriches the entity and/or case with additional extended intelligence, automatically through playbooks or on demand.
- Response actions, such as adding the IP address to an ELLIO Blocklist Automation ruleset, can be initiated based on investigation findings.
4. Choosing the Right Integration
Use the Response Integration when you need to:
Enrich existing alerts and caseswith reconnaissance and exploitation intelligence.Provide additional contextfor investigations and case summaries generated by Gemini models.Trigger response actionsfrom cases, alerts, or playbooks.Automate IP blocking workflowsthrough ELLIO Blocklist Automation.
Use the Event Mangement Content Pack when you need to:
Create detectionsbased on reconnaissance and exploitation activity.Identify reconnaissance wavestargeting your infrastructure.Detect communicationwith persistent malicious infrastructure.- Use ELLIO intelligence in entity context, IoC matching, dashboards, and YARA-L rules.
5. Getting Started
Both releases require access to Google Security Operations and an ELLIO API key.
Event Management Content Pack: Configure the ELLIO feed in the ELLIO Platform and import the content pack to enable entity enrichment, detection rules, and dashboards.Response Integration: Install the integration from the Google Security Operations Content Hub to enable case actions and automated enrichment playbooks.
6. Support
- Documentation: docs.ellio.tech/threat-intel/integrations/google-secops
- ELLIO Threat Intelligence Content Pack for Google Security Operations SIEM: github.com/ELLIO-Technology/ellio-secops-content-pack
- ELLIO Threat Intelligence Response Integration for Google Security Operations SOAR: Google SecOps -> Content Hub -> Search for ELLIO
- ELLIO Platform: https://auth.platform.ellio.tech/en/signup
- Contact: [email protected]
Written by
A team of product specialists and innovative engineers building solutions that turn ELLIO’s research and intelligence on mass exploitation and network reconnaissance into real-world tools.