Google Insights In-the-Wild Prevalence
Understand global in-the-wild sightings, enterprise reach, and vertical targeting telemetry powered by Google's planetary sensor network.
Special privileges requiredGoogle Insights In-the-Wild Prevalence is only available to users with the Google Threat Intelligence (Google TI) Enterprise or Enterprise Plus licenses.
1. Executive Overview: What is Google Insights?
Google Insights: In-the-Wild Prevalence delivers planetary-scale visibility into how indicators of compromise (IoCs)—including file hashes, domain hostnames, IP addresses, and URLs—are observed across global enterprise environments.
While traditional threat intelligence platforms rely heavily on passive DNS records, public multi-scanner submissions, or synthetic sandbox runs, Google Insights taps directly into Google’s planetary telemetry mesh:
- 365-Day Rolling Lookback: Aggregates approximately 40 billion real-world observation events across multi-layer enterprise environments over a rolling 1-year window.
- Massive Net-New Visibility: Expands baseline threat visibility by over 25.3 billion net-new indicators (65.24% Net-New) compared to static file repositories alone.
- Dual-Layer Telemetry Mesh:
- Google Observation Network: Synthesizes over 31 billion operational network indicators, establishing the global baseline required to validate normal enterprise behaviors and filter out false alarms.
- Privileged Endpoint Telemetry Feeds: High-conviction execution telemetry capturing blocked endpoint events, delivering over 90% net-new SHA256 malware hashes that have never been submitted to public multiscanners.
- Unmatched Scale: Covers active observations across 6.89 billion unique file hashes and 158 million active domain hostnames.
2. Core Principles: How to Think About Prevalence
To effectively interpret in-the-wild telemetry and avoid common analytical pitfalls, security teams should adhere to five foundational principles:
Principle 1: Absence of Signal ≠ Benign
- Prevalence is an amplifier of priority, not an allowlisting mechanism. A zero-sighting record does not mean an indicator is safe or clean.
- Advanced persistent threats (APTs), targeted espionage operations, and bespoke red-team implants deliberately maintain a low operational footprint to evade discovery.
- Use prevalence to escalate high-impact threats and prioritize active campaigns, but never automatically allowlist unobserved assets solely based on a low or zero observation count.
Principle 2: How Google Uses Prevalence in GTI Threat Scoring
- Contextual Behavioral Weighting: Within the GTI Threat Scoring methodology, in-the-wild telemetry acts as a critical behavioral weighting factor alongside multi-engine classifications, Mandiant analyst overrides, and threat actor infrastructure associations.
- Distinguishing Research Lookups from Live Enterprise Executions: Unlike community lookups or security scanner queries, Google Insights isolates telemetry from live enterprise network traffic and endpoint executions. This enables analysts to separate benign research curiosity from genuine in-the-wild attacks.
- Distinguishing Ubiquity from Targeted Malice: High global prevalence across diverse sectors helps validate operational infrastructure and baseline enterprise noise, while low-prevalence indicators showing high-conviction execution patterns are elevated as targeted threats.
Principle 3: "Sightings" vs. "Unique Organizations" (Volume vs. Reach)
- Raw Sighting Volume (
observation_count): Represents the total aggregate event count across telemetry pipelines. A high raw sighting count on a single indicator can simply reflect an automated internal scanner, a misconfigured test host, or an aggressive beaconing loop. - Global Unique Organization Count (
customer_count): Represents the deduplicated, anonymized count of distinct organizations where the indicator was observed globally. - Analytical Decision Rule: Always weigh Unique Organization Count over raw sightings when assessing whether a threat is widespread commodity noise or a narrow, targeted attack:
- 4,000 sightings within 1 organization: Likely localized noise, beaconing loop, or internal misconfiguration.
- 4 sightings across 4 distinct organizations in the same industry vertical: High probability of a targeted adversary campaign requiring immediate escalation.
Principle 4: Interpreting Absolute Numbers
- Google does not publish total monitored organization counts, baseline market share percentages, or total customer denominators.
- Sighting and organization numbers are absolute observational values. Treat them as relative weights in your triage and risk-scoring models rather than calculating statistical percentages against an assumed global denominator.
Principle 5: The Shared Infrastructure & Cloud/CDN Caveat
- IP Addresses: High organization prevalence on an IP address often indicates shared infrastructure—such as Content Delivery Networks (Cloudflare, Fastly, Akamai), public cloud egress proxies (AWS, GCP, Azure), or multi-tenant hosting.
- Analytical Rule: Never place an IP address on an allowlist solely because it exhibits high global prevalence. Adversaries frequently host C2 workers and malicious payloads behind shared CDNs. Always evaluate IP prevalence in conjunction with domain (SNI) and URL context.
- Hashes & Hostnames: High global prevalence on a specific file hash or fully qualified domain name (FQDN) is a much stronger indicator of ubiquitous corporate software or legitimate services than IP prevalence.
3. Key Telemetry Components & Metrics
In the Google Threat Intelligence UI, navigate to the Telemetry tab and select the Google Insights sub-tab on any supported indicator (file hash, domain, IP address, URL) to view:
- First Seen & Last Seen Timelines: Ground-truth timestamps marking when Google first and most recently observed the indicator in live enterprise environments. Historical observation charts allow teams to detect emerging threats (first seen within 48h), actively surging campaigns, or resurging dormant infrastructure.
- Targeted Industry Histograms: Interactive breakdowns distributing sightings across 15+ vertical industry sectors (e.g., Financial Services, Healthcare, Government, Manufacturing, Technology). Empowers analysts to immediately determine if an intrusion is part of a targeted vertical campaign or untargeted global background noise.
- Geographic Distribution: Maps observation density across global regions (AMER, EMEA, APAC) and individual countries.
- Single-Source Fallback Scoring: Automatically factors emerging polymorphic hashes detected by high-conviction endpoint telemetry into GTI scoring, even before multi-engine scanner consensus is established.
4. Practical Customer Workflows & Use Cases
To learn more about how Google Threat Intelligence supports core investigation, incident response, and vulnerability management operations, see Use cases and other resources.
Workflow 1: SOC Alert Triage & Contextual Prioritization
Objective: Rapidly validate whether an incoming SIEM/EDR alert represents an urgent targeted threat or routine operational noise.
- Open the Indicator in GTI: Navigate to the Telemetry > Google Insights tab.
- Evaluate the Blast Radius:
- Pattern A (Targeted Threat): Sighted in only 1–3 organizations globally, concentrated exclusively within your industry vertical -> High Priority: Escalate immediately to Incident Response.
- Pattern B (Commodity Scan): Sighted across hundreds of organizations evenly distributed across all sectors -> Standard Priority: Apply automated perimeter containment.
- Pattern C (Shared Infrastructure): High sighting count on an IP address across thousands of organizations -> Inspect associated domain/URL before making a triage decision.
Workflow 2: Threat Hunting & Vertical Targeting Profiling
Objective: Assess whether an emerging threat actor or ransomware operation is actively targeting peer organizations in your industry.
- Input Campaign Indicators: Query the campaign's C2 domains, hashes, or staging IPs in GTI.
- Apply Industry & Region Filters: Select your specific industry vertical (e.g., Financial Services) and operating region (e.g., EMEA).
- Analyze Velocity: Review the Observation Timeline to see if sightings in your vertical are trending upwards over the last 7 to 30 days.
- Outcome: Escalate for proactive internal threat hunting across endpoints and SIEM logs.
Workflow 3: Investigating Zero-Day Polymorphic Malware
Objective: Determine the threat level of an endpoint binary that returns "0/70 Detections" or "Not Found" on public file multiscanners.
- Search the Hash: Enter the binary SHA256/MD5 in GTI.
- Review In-the-Wild Sighting Signals: Inspect the Telemetry > Google Insights tab to verify if Google observation sources intercepted the file executing in enterprise environments within the past few hours.
- Check Execution Recency: Verify First Seen timestamps and organizational footprint to evaluate campaign velocity.
- Outcome: Isolate the endpoint and initiate memory triage without waiting for static signature updates.
Workflow 4: Enterprise SOAR / SIEM Enrichment via API
Objective: Ingest Google Insights telemetry programmatically to dynamically enrich and score security alerts in Chronicle SOAR, Cortex XSOAR, Splunk SOAR, or custom pipelines.
Security operations teams can query the GET /api/v3/global_prevalence/summarize endpoint passing an indicator value and entity type (SHA256, MD5, IP, HOSTNAME, etc.) to retrieve real-time organization reach (customer_count), sighting volume (observation_count), first/last seen dates, and vertical targeting telemetry.
For complete cURL commands, response JSON models, and an executable Python SOAR playbook implementation demonstrating risk score adjustment and triage rules, see the Get global prevalence summary endpoint documentation.
5. Threat Actor Profiles & Targeting Telemetry
A common question from threat intelligence teams is how in-the-wild targeting data connects with GTI's finished Threat Actor and Campaign profiles:
How Threat Profiles Use Targeting Information Today
- Analyst-Curated Intelligence: Mandiant intelligence analysts and frontline incident responders curate the vertical and geographic targeting profiles in GTI Threat Actor Dossiers (e.g., APT29, UNC3886, FIN11) based on confirmed intrusions, victimology assessments, and verified incident response engagements.
- Indicator Association: When indicators linked to a known actor are viewed in GTI, analysts can compare the indicator's Google Insights telemetry histograms against the threat actor's known target sectors to corroborate active operations.
What Plans are in Motion (Roadmap)
- Dynamic Actor Histogram Aggregation: Automatically aggregating telemetry across all indicators attributed to a threat actor or campaign, surfacing a real-time Observed Campaign Targeting view directly on Threat Actor pages.
- Automated Victimology Drift Detection: Alerting analysts when an actor historically known for targeting Financial Services begins showing an anomalous surge of in-the-wild execution telemetry within Healthcare or Critical Infrastructure.
- Direct TTP & Actor Attribution: Tying live prevalence directly to MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), enabling automated correlation between endpoint execution behaviors and active threat groups.
6. Future Horizon
- Autonomous Threat Flywheel: Real-time submission of newly sighted in-the-wild infrastructure into active VirusTotal deep scanning and sandboxing queues.
- AI-Generated Detection Rules: Dynamic compilation of observed campaign behaviors into vendor-neutral Sigma and YARA-L2 (Y2) detection rules for immediate SIEM export.
Updated about 18 hours ago