Investigations contain links to Google Threat Intelligence context for entities (IP addresses, Domains, URLs, and SHA256 file hashes). This information is located in the evidence section of an Investigation and applies to all Investigations. In the Managed Defense portal, click the Google Threat Intelligence icon next to an entity to display a summary of the threat actor, malware family, and verdicts from engine vendors and sandboxes.
For more information, see Working with Investigations.