Services›Google Cloud›Google SecOps Marketplace

Google SecOps Marketplace

100 updates from Google Cloud.

Get Google SecOps Marketplace updates weekly
Google SecOps MarketplacechangeNew

Gitsync: Version 53.0

Gitsync: Version 53.0 • (REGRESSIVE) Updated to support the latest Chronicle API. Important: Existing users must migrate their repository branch and re-export their content after updating. For…

Google SecOps MarketplacechangeNew

Google Chronicle: Version 97.0

Google Chronicle: Version 97.0 • Updated the alert synchronization logic in the following job: Google Chronicle Sync Job

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 33.0

Microsoft 365 Defender: Version 33.0 • Improved the case priority parsing mechanism to support protobuf format on remote agents and updated comment syncing logic to support multi-line…

Google SecOps Marketplacechange

Jira: Version 62.0

Jira: Version 62.0 • Improved context properties processing logic in the following action: Create Issue

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 83.0

CrowdStrike Falcon: Version 83.0 • Updated comment syncing logic to support multi-line closure comments and sync comments from closed CrowdStrike alerts in the following action: Sync Alerts

Google SecOps Marketplacechange

Illusive Networks: Version 11.0

Illusive Networks: Version 11.0 • Fixed the endpoint for retrieving forensic data in the following action: Run Forensic Scan

Google SecOps Marketplacechange

Cyberint: Version 8.0

Cyberint: Version 8.0 • Added the Disable Overflow parameter to the following connector: Cyberint - Alerts Connector

Google SecOps Marketplacechange

Google Chronicle: Version 96.0

Google Chronicle: Version 96.0 • Integration: Removed dummy network socket initialization during multipart response parsing and updated the default API root to point to the Chronicle API.

Google SecOps Marketplacechange

Palo Alto Cortex XDR: Version 33.0

Palo Alto Cortex XDR: Version 33.0 • Added the Unzip File parameter and improved error handling for failed retrievals in the following action: Download File

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 32.0

Microsoft 365 Defender: Version 32.0 • Improved the rate limit handling and timestamp updating mechanism in the following connector: Microsoft 365 Defender - Incidents Connector Added the Sync…

Google SecOps Marketplacechange

Microsoft Graph Mail: Version 47.0

Microsoft Graph Mail: Version 47.0 • Added support for S/MIME digital signing and encryption in the following action: Send Email Added support for HTML URL extraction, attachment exclusions, event…

Google SecOps Marketplacefeature

Siemplify: Version 113.0

Siemplify: Version 113.0 • The following new action has been added: Attach Playbook to Case

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 82.0

CrowdStrike Falcon: Version 82.0 • Updated the polling logic to prevent host containment flapping in the following actions: Contain Endpoint • Lift Contained Endpoint

Google SecOps Marketplacechange

Microsoft Graph Security: Version 29.0

Microsoft Graph Security: Version 29.0 • Integration: Added support for Microsoft Sovereign / GCC High environments by adding Login API Root and API Root parameters.

Google SecOps Marketplacefeature

CyberArk PAM: Version 13.0

CyberArk PAM: Version 13.0 • The following new job has been added: Sync Integration Credentials Job

Google SecOps Marketplacechange

Trend Vision One: Version 12.0

Trend Vision One: Version 12.0 • Made the Description parameter mandatory in the following actions: Isolate Endpoint • Unisolate Endpoint

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 31.0

Microsoft 365 Defender: Version 31.0 • Updated alert tracking logic, extracted alert object metadata, and improved the pagination and timeout handling mechanism in the following…

Google SecOps Marketplacechange

Google Chronicle: Version 95.0

Google Chronicle: Version 95.0 • Integration: Improved OAuth 2.0/JWT authentication logging, validation diagnostics, and error messaging.

Google SecOps Marketplacechange

FireEye ETP: Version 11.0

FireEye ETP: Version 11.0 • Updated ontology mapping rules and fixed missing alert details and event data for v2 API issue in the following connector: FireEye ETP - Email Alerts Connector

Google SecOps Marketplacechange

Google Chronicle: Version 94.0

Google Chronicle: Version 94.0 • Reverted the execution mode to synchronous in the following action: Is Value in Data Table

Google SecOps Marketplacechange

ServiceNow: Version 72.0

ServiceNow: Version 72.0 • Added the ability to authenticate using client credentials without a refresh token to the following connector: Sync Incidents

Google SecOps Marketplacechange

ServiceNow: Version 72.0

ServiceNow: Version 72.0 • Added the ability to authenticate using client credentials without a refresh token to the following connector: Sync Incidents

Google SecOps Marketplacechange

FireEye ETP: Version 11.0

FireEye ETP: Version 11.0 • Updated ontology mapping rules and fixed missing alert details and event data for v2 API issue in the following connector: FireEye ETP - Email Alerts Connector

Google SecOps Marketplacechange

Microsoft Graph Mail: Version 46.0

Microsoft Graph Mail: Version 46.0 • Updated parameters and filtering options in the following actions: Wait For Email From User • Search Emails

Google SecOps Marketplacechange

ServiceNow: Version 71.0

ServiceNow: Version 71.0 • Added support for OAuth authentication in the following job: Sync Incidents Job

Google SecOps Marketplacefeature

FireEye HX: Version 26.0

FireEye HX: Version 26.0 • Added the following new actions: Get File • Check Containment Status • Contain Host • Cancel Host Contain

Google SecOps Marketplacefeature

Wiz: Version 10.0

Wiz: Version 10.0 • Added the Authentication URL parameter to support Gov (FedRAMP) and custom environments. • Added the following new job: Wiz and Google SecOps Bi-directional Sync Job

Google SecOps Marketplacechange

Splunk: Version 67.0

Splunk: Version 67.0 • Updated the lookback timestamp progression logic when all fetched alerts in a cycle have already been processed in the following connector: Splunk ES - Notable Events…

Google SecOps Marketplacechange

Pub/Sub: Version 4.0

Pub/Sub: Version 4.0 • Added support for pubsub_message_id in the Unique ID Field parameter in the following connector: Pub/Sub - Messages Connector

Google SecOps Marketplacechange

Exchange: Version 125.0

Exchange: Version 125.0 • Updated the parsing logic for nested S/MIME email attachments (.eml) sent from macOS and Windows in the following connector: Exchange Mail Connector v2 with Oauth…

Google SecOps Marketplacechange

Zscaler: Version 16.0

Zscaler: Version 16.0 • Fixed an issue where legacy API key and password authentication failed due to URL path normalization issues.

Google SecOps Marketplacechange

Proofpoint Cloud Threat Response: Version 5.0

Proofpoint Cloud Threat Response: Version 5.0 • Fixed an issue where null, missing, or unmapped priority values in API payloads caused log ingestion errors in the following connector: Proofpoint…

Google SecOps Marketplacefeature

Wiz: Version 9.0

Wiz: Version 9.0 • Added the following new job: Wiz and Google SecOps Bi-directional Sync Job

Google SecOps Marketplacechange

Palo Alto Cortex XDR: Version 32.0

Palo Alto Cortex XDR: Version 32.0 • Fixed an issue where the job repeatedly logged errors when a case was merged or deleted in Google SecOps in the following job: Sync Incidents

Google SecOps Marketplacefeature

Microsoft Graph Mail: Version 45.0

Microsoft Graph Mail: Version 45.0 • The following new actions have been added: Block Domain • Block Sender • Delete Inbox Rules • List Rules • Remove Block Domain • Remove Block Sender

Google SecOps Marketplacechange

Cisco Umbrella: Version 21.0

Cisco Umbrella: Version 21.0 • Fixed an issue in the following action where entity attachment failed due to a bytes object serialization error: Get Domain Security Info

Google SecOps Marketplacechange

Active Directory: Version 45.0

Active Directory: Version 45.0 • Fixed an issue in the following action where entity properties were incorrectly reset on update: Enrich Entities

Google SecOps Marketplacechange

Microsoft Graph Mail: Version 45.0

Microsoft Graph Mail: Version 45.0 • Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found: Get Mailbox Account Out Of Facility Settings

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 81.0

CrowdStrike Falcon: Version 81.0 • Added the ability to use device IDs as input parameters in the following actions: Hide Hosts • Contain Endpoint • Download File • Execute Command • Get Host…

Google SecOps Marketplacechange

GitSync

GitSync • Fixed an issue in the following action where the Include Playbook Blocks parameter was ignored when a folder allowlist was used: Push Playbook

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 30.0

Microsoft 365 Defender: Version 30.0 • Added support for GCC High tenants by dynamically constructing API token scopes and adding a configurable API Root parameter in the…

Google SecOps Marketplacechange

Enrichment

Enrichment • Fixed an issue in the following action where unsupported entity types were selected during enrichment: Whois

Google SecOps Marketplacechange

ServiceNow: Version 70.0

ServiceNow: Version 70.0 • Fixed verification logic when updating reference fields in the following action: Update Incident

Google SecOps Marketplacechange

Jira: Version 61.0

Jira: Version 61.0 • Added support for customizable status-to-closure mapping, Case-level job scope, custom field variables in Closed Reason Mapping, context value alignment to JIRA_ISSUE_KEY, and…

Google SecOps Marketplacechange

Google Chronicle: Version 92.0

Google Chronicle: Version 92.0 • Updated the action to use new search API in the following action: Is Value in Data Table

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 29.0

Microsoft 365 Defender: Version 29.0 • Updated Google SecOps event structure, added support for incident tags and assignee filtering, updated ontology mapping, and optimized evidence handling with…

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 80.0

CrowdStrike Falcon: Version 80.0 • Implemented 500-device safety limit per entity search, updated device sorting by last_seen.desc, and added batch request chunking for device details,…

Google SecOps Marketplacechange

Microsoft Graph Mail Delegated: Version 21.0

Microsoft Graph Mail Delegated: Version 21.0 • Updated logic for parsing email headers and S/MIME digitally signed emails in the following connector: Microsoft Graph Mail Delegated Connector

Google SecOps Marketplacechange

Google Chronicle: Version 91.0

Google Chronicle: Version 91.0 • Updated Wiz Defend alert naming format in the following connector: Google Chronicle - Chronicle Alerts Connector

Google SecOps Marketplacechange

Vertex AI: Version 8.0

Vertex AI: Version 8.0 • Added support for multi-region endpoints across the integration configuration.

Google SecOps Marketplacechange

Active Directory: Version 44.0

Active Directory: Version 44.0 • Added optional Connection Timeout and Receive Timeout parameters to configure network connectivity limits in the following action: Enrich Entities

Google SecOps Marketplacechange

Siemplify: Version 112.0

Siemplify: Version 112.0 • Added Update Enabled Connectors Only filtering option in the following job: Response Integration & Connector Upgrade Job

Google SecOps Marketplacechange

Google Threat Intelligence: Version 20.0

Google Threat Intelligence: Version 20.0 • Added support for CHILDHASH and PARENTHASH entity types in the following action: Enrich Entities Added Entity Type Filter parameter to allow configuring…

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 28.0

Microsoft 365 Defender: Version 28.0 • Updated case syncing logic in the following action: Sync Alerts Updated alert processing logic in the following connector: • Microsoft 365 Defender -…

Google SecOps Marketplacefeature

Wiz: Version 14.0

Wiz: Version 14.0 • Added the following action: Get Blue Agent Analysis

Google SecOps Marketplacechange

QRadar: Version 69.0

QRadar: Version 69.0 • Updated timestamp filtering to use last_persisted_time for tracking modifications in the following connector: Qradar Offenses Connector

Google SecOps Marketplacechange

Jira: Version 60.0

Jira: Version 60.0 • Added support for the Created Before date filter and Custom JQL query parameter in the following action: List Issues

Google SecOps Marketplacechange

Azure Monitor: Version 5.0

Azure Monitor: Version 5.0 • Updated integration documentation links in the integration configuration.

Google SecOps Marketplacechange

Google Chronicle: Version 90.0

Google Chronicle: Version 90.0 • Updated handling of Wiz Defend detections and ontology mapping in the following connector: Chronicle Alerts Connector

Google SecOps Marketplacechange

Google Chronicle: Version 88.0

Google Chronicle: Version 88.0 • Added api_root parameter to alert extensions to expand normalization metadata options in the following connector: Chronicle Alerts Connector

Google SecOps Marketplacechange

Google Threat Intelligence: Version 18.0

Google Threat Intelligence: Version 18.0 • Added an optional Active Group parameter to support multi-tenant organization context routing in the integration configuration and the following…

Google SecOps Marketplacechange

Microsoft Defender ATP: Version 33.0

Microsoft Defender ATP: Version 33.0 • Updated execution processing logic to improve backend tracking stability in the following action: Execute Live Response Command

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 78.0

CrowdStrike Falcon: Version 78.0 • Fixed pagination loop logic to prevent infinite timeouts during high-volume sweeps in the following action: Get Host Information

Google SecOps Marketplacechange

AWS GuardDuty: Version 14.0

AWS GuardDuty: Version 14.0 • Added support for Google Cloud Web Identity (OIDC) Federation authentication.

Google SecOps Marketplacechange

ServiceNow: Version 68.0

ServiceNow: Version 68.0 • Updated affected CIs processing logic to handle missing reference keys smoothly in the following job: Sync Incidents Job

Google SecOps Marketplacechange

SCC Enterprise: Version 22.0

SCC Enterprise: Version 22.0 • Refactored integration code to optimize underlying execution performance.

Google SecOps Marketplacechange

Google Threat Intelligence: Version 17.0

Google Threat Intelligence: Version 17.0 • Fixed widget rendering failures by escaping raw HTML script tags within extended_response_body in the following action: Get ASM Entity Details

Google SecOps Marketplacechange

Google Chronicle: Version 87.0

Google Chronicle: Version 87.0 • Improved case and alert synchronization logic by fixing the verification handling of valid external ID values in the following job: Google Chronicle Sync Job

Google SecOps Marketplacechange

FileUtilities: Version 27.0

FileUtilities: Version 27.0 • Added support for extracting files from .7z archives in the following action: Extract Zip Files

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 77.0

CrowdStrike Falcon: Version 77.0 • Updated syncing logic to support multiple CrowdStrike alert IDs mapped to a single SecOps alert and improved error handling for alert ID context values in the…

Google SecOps Marketplacechange

Siemplify: Version 110.0

Siemplify: Version 110.0 • Updated results processing logic to cleanly escape backslashes in the following action: Create Gemini Case Summary

Google SecOps Marketplacechange

VirusTotalV3: Version 41.0

VirusTotalV3: Version 41.0 • Updated Predefined Widgets to fix cached fallback rendering in the following actions: Enrich Hash • Enrich IOC • Enrich IP • Enrich URL • Get Domain Details

Google SecOps Marketplacechange

EmailV2: Version 42.0

EmailV2: Version 42.0 • Updated default values for IMAP server address, port, username, and password for the following connector: Generic IMAP Email Connector

Google SecOps Marketplacechange

Google Cloud Compute: Version 19.0

Google Cloud Compute: Version 19.0 • Refactored action code in the following actions: Add IP To Firewall Rule • Remove external IP addresses • Execute VM Patch Job • Update Firewall Rule

Google SecOps Marketplacechange

Google Threat Intelligence: Version 16.0

Google Threat Intelligence: Version 16.0 • Updated Predefined Widgets to optimize loading performance and aligned layouts to prevent visual shifts in the following actions: Enrich Entities •…

Google SecOps Marketplacechange

FireEye ETP: Version 9.0

FireEye ETP: Version 9.0 • Added Trellix OAuth support, updated public API endpoints to v2, and removed legacy V1 API support.

Google SecOps Marketplacechange

Google Chronicle: Version 86.0

Google Chronicle: Version 86.0 • Fixed an issue where the connector would idle or hang on heartbeats instead of breaking early when nextPageToken or nextPageStartTime is received, and updated…

Google SecOps Marketplacechange

Palo Alto Cortex XDR: Version 29.0

Palo Alto Cortex XDR: Version 29.0 • Updated host name extraction logic in the raw payload in the following connector: Palo Alto Cortex XDR Connector

Google SecOps Marketplacechange

Siemplify: Version 109.0

Siemplify: Version 109.0 • Refactored the code in the following action: Attach Playbook to Alert