ServicesGoogle CloudGoogle SecOps Marketplace

Google SecOps Marketplace

100 updates from Google Cloud.

Get Google SecOps Marketplace updates weekly
Google SecOps MarketplacechangeNew

Splunk: Version 67.0

Splunk: Version 67.0 • Updated the lookback timestamp progression logic when all fetched alerts in a cycle have already been processed in the following connector: Splunk ES - Notable Events…

Google SecOps MarketplacechangeNew

Palo Alto Cortex XDR: Version 32.0

Palo Alto Cortex XDR: Version 32.0 • Fixed an issue where the job repeatedly logged errors when a case was merged or deleted in Google SecOps in the following job: Sync Incidents

Google SecOps MarketplacechangeNew

Exchange: Version 125.0

Exchange: Version 125.0 • Updated the parsing logic for nested S/MIME email attachments (.eml) sent from macOS and Windows in the following connector: Exchange Mail Connector v2 with Oauth…

Google SecOps MarketplacechangeNew

Zscaler: Version 16.0

Zscaler: Version 16.0 • Fixed an issue where legacy API key and password authentication failed due to URL path normalization issues.

Google SecOps MarketplacechangeNew

Proofpoint Cloud Threat Response: Version 5.0

Proofpoint Cloud Threat Response: Version 5.0 • Fixed an issue where null, missing, or unmapped priority values in API payloads caused log ingestion errors in the following connector: Proofpoint…

Google SecOps MarketplacefeatureNew

Wiz: Version 9.0

Wiz: Version 9.0 • Added the following new job: Wiz and Google SecOps Bi-directional Sync Job

Google SecOps MarketplacechangeNew

Pub/Sub: Version 4.0

Pub/Sub: Version 4.0 • Added support for pubsub_message_id in the Unique ID Field parameter in the following connector: Pub/Sub - Messages Connector

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 81.0

CrowdStrike Falcon: Version 81.0 • Added the ability to use device IDs as input parameters in the following actions: Hide Hosts • Contain Endpoint • Download File • Execute Command • Get Host…

Google SecOps Marketplacechange

Cisco Umbrella: Version 21.0

Cisco Umbrella: Version 21.0 • Fixed an issue in the following action where entity attachment failed due to a bytes object serialization error: Get Domain Security Info

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 30.0

Microsoft 365 Defender: Version 30.0 • Added support for GCC High tenants by dynamically constructing API token scopes and adding a configurable API Root parameter in the…

Google SecOps Marketplacechange

Microsoft Graph Mail: Version 45.0

Microsoft Graph Mail: Version 45.0 • Fixed an issue in the following action where an unhandled exception occurred when a user mailbox was not found: Get Mailbox Account Out Of Facility Settings

Google SecOps Marketplacechange

Enrichment

Enrichment • Fixed an issue in the following action where unsupported entity types were selected during enrichment: Whois

Google SecOps Marketplacechange

Active Directory: Version 45.0

Active Directory: Version 45.0 • Fixed an issue in the following action where entity properties were incorrectly reset on update: Enrich Entities

Google SecOps Marketplacefeature

Microsoft Graph Mail: Version 45.0

Microsoft Graph Mail: Version 45.0 • The following new actions have been added: Block Domain • Block Sender • Delete Inbox Rules • List Rules • Remove Block Domain • Remove Block Sender

Google SecOps Marketplacechange

GitSync

GitSync • Fixed an issue in the following action where the Include Playbook Blocks parameter was ignored when a folder allowlist was used: Push Playbook

Google SecOps Marketplacechange

ServiceNow: Version 70.0

ServiceNow: Version 70.0 • Fixed verification logic when updating reference fields in the following action: Update Incident

Google SecOps Marketplacechange

Microsoft Graph Mail Delegated: Version 21.0

Microsoft Graph Mail Delegated: Version 21.0 • Updated logic for parsing email headers and S/MIME digitally signed emails in the following connector: Microsoft Graph Mail Delegated Connector

Google SecOps Marketplacechange

Jira: Version 61.0

Jira: Version 61.0 • Added support for customizable status-to-closure mapping, Case-level job scope, custom field variables in Closed Reason Mapping, context value alignment to JIRA_ISSUE_KEY, and…

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 80.0

CrowdStrike Falcon: Version 80.0 • Implemented 500-device safety limit per entity search, updated device sorting by last_seen.desc, and added batch request chunking for device details,…

Google SecOps Marketplacechange

Google Chronicle: Version 92.0

Google Chronicle: Version 92.0 • Updated the action to use new search API in the following action: Is Value in Data Table

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 29.0

Microsoft 365 Defender: Version 29.0 • Updated Google SecOps event structure, added support for incident tags and assignee filtering, updated ontology mapping, and optimized evidence handling with…

Google SecOps Marketplacechange

Google Chronicle: Version 91.0

Google Chronicle: Version 91.0 • Updated Wiz Defend alert naming format in the following connector: Google Chronicle - Chronicle Alerts Connector

Google SecOps Marketplacechange

Google Threat Intelligence: Version 20.0

Google Threat Intelligence: Version 20.0 • Added support for CHILDHASH and PARENTHASH entity types in the following action: Enrich Entities Added Entity Type Filter parameter to allow configuring…

Google SecOps Marketplacechange

Vertex AI: Version 8.0

Vertex AI: Version 8.0 • Added support for multi-region endpoints across the integration configuration.

Google SecOps Marketplacechange

Active Directory: Version 44.0

Active Directory: Version 44.0 • Added optional Connection Timeout and Receive Timeout parameters to configure network connectivity limits in the following action: Enrich Entities

Google SecOps Marketplacechange

Microsoft 365 Defender: Version 28.0

Microsoft 365 Defender: Version 28.0 • Updated case syncing logic in the following action: Sync Alerts Updated alert processing logic in the following connector: • Microsoft 365 Defender -…

Google SecOps Marketplacechange

Siemplify: Version 112.0

Siemplify: Version 112.0 • Added Update Enabled Connectors Only filtering option in the following job: Response Integration & Connector Upgrade Job

Google SecOps Marketplacechange

Jira: Version 60.0

Jira: Version 60.0 • Added support for the Created Before date filter and Custom JQL query parameter in the following action: List Issues

Google SecOps Marketplacechange

Azure Monitor: Version 5.0

Azure Monitor: Version 5.0 • Updated integration documentation links in the integration configuration.

Google SecOps Marketplacefeature

Wiz: Version 14.0

Wiz: Version 14.0 • Added the following action: Get Blue Agent Analysis

Google SecOps Marketplacechange

QRadar: Version 69.0

QRadar: Version 69.0 • Updated timestamp filtering to use last_persisted_time for tracking modifications in the following connector: Qradar Offenses Connector

Google SecOps Marketplacechange

Google Chronicle: Version 90.0

Google Chronicle: Version 90.0 • Updated handling of Wiz Defend detections and ontology mapping in the following connector: Chronicle Alerts Connector

Google SecOps Marketplacechange

Microsoft Defender ATP: Version 33.0

Microsoft Defender ATP: Version 33.0 • Updated execution processing logic to improve backend tracking stability in the following action: Execute Live Response Command

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 78.0

CrowdStrike Falcon: Version 78.0 • Fixed pagination loop logic to prevent infinite timeouts during high-volume sweeps in the following action: Get Host Information

Google SecOps Marketplacechange

AWS GuardDuty: Version 14.0

AWS GuardDuty: Version 14.0 • Added support for Google Cloud Web Identity (OIDC) Federation authentication.

Google SecOps Marketplacechange

Google Threat Intelligence: Version 18.0

Google Threat Intelligence: Version 18.0 • Added an optional Active Group parameter to support multi-tenant organization context routing in the integration configuration and the following…

Google SecOps Marketplacechange

ServiceNow: Version 68.0

ServiceNow: Version 68.0 • Updated affected CIs processing logic to handle missing reference keys smoothly in the following job: Sync Incidents Job

Google SecOps Marketplacechange

Google Chronicle: Version 88.0

Google Chronicle: Version 88.0 • Added api_root parameter to alert extensions to expand normalization metadata options in the following connector: Chronicle Alerts Connector

Google SecOps Marketplacechange

SCC Enterprise: Version 22.0

SCC Enterprise: Version 22.0 • Refactored integration code to optimize underlying execution performance.

Google SecOps Marketplacechange

Google Threat Intelligence: Version 17.0

Google Threat Intelligence: Version 17.0 • Fixed widget rendering failures by escaping raw HTML script tags within extended_response_body in the following action: Get ASM Entity Details

Google SecOps Marketplacechange

Google Chronicle: Version 87.0

Google Chronicle: Version 87.0 • Improved case and alert synchronization logic by fixing the verification handling of valid external ID values in the following job: Google Chronicle Sync Job

Google SecOps Marketplacechange

FileUtilities: Version 27.0

FileUtilities: Version 27.0 • Added support for extracting files from .7z archives in the following action: Extract Zip Files

Google SecOps Marketplacechange

CrowdStrike Falcon: Version 77.0

CrowdStrike Falcon: Version 77.0 • Updated syncing logic to support multiple CrowdStrike alert IDs mapped to a single SecOps alert and improved error handling for alert ID context values in the…

Google SecOps Marketplacechange

Siemplify: Version 110.0

Siemplify: Version 110.0 • Updated results processing logic to cleanly escape backslashes in the following action: Create Gemini Case Summary

Google SecOps Marketplacechange

EmailV2: Version 42.0

EmailV2: Version 42.0 • Updated default values for IMAP server address, port, username, and password for the following connector: Generic IMAP Email Connector

Google SecOps Marketplacechange

Google Cloud Compute: Version 19.0

Google Cloud Compute: Version 19.0 • Refactored action code in the following actions: Add IP To Firewall Rule • Remove external IP addresses • Execute VM Patch Job • Update Firewall Rule

Google SecOps Marketplacechange

VirusTotalV3: Version 41.0

VirusTotalV3: Version 41.0 • Updated Predefined Widgets to fix cached fallback rendering in the following actions: Enrich Hash • Enrich IOC • Enrich IP • Enrich URL • Get Domain Details

Google SecOps Marketplacechange

Google Threat Intelligence: Version 16.0

Google Threat Intelligence: Version 16.0 • Updated Predefined Widgets to optimize loading performance and aligned layouts to prevent visual shifts in the following actions: Enrich Entities •…

Google SecOps Marketplacechange

FireEye ETP: Version 9.0

FireEye ETP: Version 9.0 • Added Trellix OAuth support, updated public API endpoints to v2, and removed legacy V1 API support.

Google SecOps Marketplacechange

Google Chronicle: Version 86.0

Google Chronicle: Version 86.0 • Fixed an issue where the connector would idle or hang on heartbeats instead of breaking early when nextPageToken or nextPageStartTime is received, and updated…

Google SecOps Marketplacechange

Palo Alto Cortex XDR: Version 29.0

Palo Alto Cortex XDR: Version 29.0 • Updated host name extraction logic in the raw payload in the following connector: Palo Alto Cortex XDR Connector

Google SecOps Marketplacechange

Siemplify: Version 109.0

Siemplify: Version 109.0 • Refactored the code in the following action: Attach Playbook to Alert

Google SecOps Marketplacechange

Qualys VM: Version 28.0

Qualys VM: Version 28.0 • Fixed AttributeError during parsing of multiple host lists and added fallback hostname matching in the following actions: List Endpoint Detections • Enrich Host

Google SecOps Marketplacechange

Microsoft Graph Mail: Version 42.0

Microsoft Graph Mail: Version 42.0 • Updated the logic for robust handling of transient upstream API errors and connection issues in the following connector: Microsoft Graph Mail Connector

Google SecOps Marketplacechange

Google Chronicle: Version 85.0

Google Chronicle: Version 85.0 • Updated partial batch handling and added dynamic batch sizing to prevent timeout loops, refactored logging and added monitoring signals for process health, and…

Google SecOps Marketplacechange

Microsoft Azure Sentinel: Version 64.0

Microsoft Azure Sentinel: Version 64.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…

Google SecOps Marketplacechange

Microsoft Defender ATP: Version 32.0

Microsoft Defender ATP: Version 32.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…

Google SecOps Marketplacechange

Azure Security Center: Version 17.0

Azure Security Center: Version 17.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…

Google SecOps Marketplacechange

Microsoft Graph Security: Version 27.0

Microsoft Graph Security: Version 27.0 • Announced deprecation notice. Connector will be deprecated on 30th March 2027. Only critical bug fixes will be considered. For more information refer to the…

Google SecOps Marketplacechange

Google Cloud IAM: Version 20.0

Google Cloud IAM: Version 20.0 • Updated Predefined Widgets in the following widgets: List Roles • List Service Accounts

Google SecOps Marketplacechange

ConnectWise: Version 23.0

ConnectWise: Version 23.0 • Refactored the code for the following action: Create Alerts Ticket

Google SecOps Marketplacechange

ServiceNow: Version 67.0

ServiceNow: Version 67.0 • Refactored the code for the following action: Create Alert Incident

Google SecOps Marketplacechange

Siemplify: Version 245.0

Siemplify: Version 245.0 • Refactored internal code execution logic for the platform integration.

Google SecOps Marketplacechange

MISP: Version 275.6

MISP: Version 275.6 • Refactored internal code execution logic and optimized core integration components.

Google SecOps Marketplacechange

Jira: Version 58.0

Jira: Version 58.0 • Refactored the code for the following action: Create Alert Issue

Google SecOps Marketplacechange

Tanium: Version 20.0

Tanium: Version 20.0 • Integration: Added a partner header to all API requests.

Google SecOps Marketplacechange

Google Chronicle: Version 83.0

Google Chronicle: Version 83.0 • Added support for filtering alerts by rule type to the following connector: Google Chronicle - Chronicle Alerts Connector

Google SecOps Marketplacechange

ServiceNow: Version 66.0

ServiceNow: Version 66.0 • Updated the code for the following action: Update Incident: Added support for updating reference fields.

Google SecOps Marketplacechange

ConnectWise: Version 22.0

ConnectWise: Version 22.0 • Refactored the code for the following action: Create Alerts Ticket

Google SecOps Marketplacechange

EmailV2: Version 41.0

EmailV2: Version 41.0 • Integration: Updated TIPCommon to 2.3.8 and migrated EnvironmentCommon imports to TIPCommon.envcommon.

Google SecOps Marketplacechange

Jira: Version 57.0

Jira: Version 57.0 • Refactored the code for the following action: Create Alert Issue

Google SecOps Marketplacechange

Google Chronicle: Version 82.0

Google Chronicle: Version 82.0 • Integration: Improved memory efficiency to prevent OOM crashes when querying large timeframes for Lookup Similar Alerts. • Updated the code for the following…

Google SecOps Marketplacechange

ServiceNow: Version 65.0

ServiceNow: Version 65.0 • Refactored the code for the following action: Create Alert Incident

Google SecOps Marketplacechange

Azure Active Directory: Version 27.0

Azure Active Directory: Version 27.0 • Updated enrichment logic to ensure id is fetched when Include Last Sign In Details is enabled in the following action: Enrich User