Skip to main content
Solved

Digital Threat Monitoring (GTI): Expected search recall, query best practices, and Monitors vs. Research Tools result divergence

  • July 1, 2026
  • 1 reply
  • 99 views

maxjunker
Forum|alt.badge.img+4

Hi dear community, 

we're an MSSP evaluating the Digital Threat Monitoring (DTM) module in Google Threat Intelligence as the digital-risk / threat-monitoring capability we offer to our customers. As part of the evaluation, we're benchmarking DTM against Intelligence X (intelx.io), which we currently use for this purpose, and we've run into some results we'd like to sanity-check with the community — and ideally with someone from the GTI/DTM team.

 

Observation

Across the topics, brands, and companies we research, DTM returns substantially fewer results than we expected — and consistently fewer than Intelligence X for comparable queries. The gap is large enough that we want to confirm whether this reflects how DTM is designed, or whether we're operating the tool incorrectly.

 

Our questions

1. Scope / design of the corpus Is DTM intended primarily as a curated, entity- and relevance-driven monitoring capability (optimized to reduce noise) rather than an exhaustive surface/deep/dark-web index like Intelligence X? In other words: is comparatively low recall on broad keyword searches expected by design?

2. Query best practices Are there mechanics that materially affect recall which we may be underusing? For example: Free Text Search vs. Lucene Text Query (Advanced), entity-based conditions, proximity operators, or source scoping. Pointers to documentation or real-world examples would be very welcome.

3. Coverage & entitlement Are there constraints on source coverage, historical depth, or regional/language coverage tied to the license tier (Enterprise vs. Enterprise+)? Our customer base is largely German-speaking SMB / mid-market, so German-language and regional (DACH) source coverage is particularly relevant for us.

 

One specific inconsistency we'd like clarified

Alerts produced by our DTM Monitors do not appear to be retrievable through Research Tools, even when we search for the same terms. This surprised us, because the documentation describes Research Tools and Monitors as drawing on the same collected data, and positions Research Tools as the precursor for building a Monitor.

Is the divergence between the two result sets by design (e.g., visibility/redaction rules for certain result types, such as compromised credentials), or does it indicate a misconfiguration on our side?

Has anyone else compared DTM's recall against dedicated deep/dark-web indexes, or can someone from Google shed light on the intended scope and the Monitors vs. Research Tools behavior? Happy to share more specific findings and example queries if that helps.

Thanks a lot!

Best answer by Rob_P

Hi ​@maxjunker  - 

Thanks for reaching out on this particular topic with your questions. 

I have a reply to a previous post which answers some of your questions and provide additional insight. I think its useful to review that post as well since I include a lot of documentation links and answer some questions about Lucene vs Raw Text searches, and some limitations to Research Tools.
 

  1. I would also like to add some transparency that the My Landscape feature in the Google Threat Intelligence Platform will be eventually replacing DTM sometime in 2027.  This new system, is powered by Gemini and will be a relevance driven system which helps surface threats based on relevant threat scenarios, and not just simple text matches like many other systems operate on, including legacy DTM. 
     
  2. For your 2nd Question about free text vs Lucene, please see some of the links below to help explain each function and how to harness the power of Lucene Queries:
     


https://gtidocs.virustotal.com/docs/lucene-queries-in-dtm

 

  1. There are no restrictions on the content / posts / materials we will find and return based on your license tier in Google Threat Intelligence. 
     
  2. I wanted to also expand on a previous comment about research tools as a whole.  This functionality is a good starting point for understanding if the types of data and entities you are looking for are collected within DTM. While this is the primary method for doing a preliminary search for the content we’ve collected, you may see some of the inconsistencies you’ve mentioned but you would NOT experience that with the monitors once they are configured.  Using free-text search on Research tools may produce inconsistent results, as it's preferable to be using the Monitor Topics listings & Search collection types so we’re searching against specific fields in our index, not just doing a raw text search which may not match on your content by the time the initial query completes.  Additionally, Research Tools is only going to return the first 200 results we find.   Advanced Lucene text Queries do work in Research tools, and can be a good way to search for very specific targeted sets of fields and conditions. 
     
  3. Is the divergence between the two result sets by design (e.g., visibility/redaction rules for certain result types, such as compromised credentials), or does it indicate a misconfiguration on our side?
    Research Tools and Monitors are set to be part of the same dataset, however we do not allow users to search for compromised Credentials in Research Tools due to privacy concerns, those must be setup within a monitor with the domains verified by the users in order to expose the passwords. 


I hope this helps, please reach back if you have any further questions or need clarification.

Thanks, 

  • ​​​​​​​Rob

1 reply

Rob_P
Staff
Forum|alt.badge.img+12
  • Staff
  • Answer
  • July 6, 2026

Hi ​@maxjunker  - 

Thanks for reaching out on this particular topic with your questions. 

I have a reply to a previous post which answers some of your questions and provide additional insight. I think its useful to review that post as well since I include a lot of documentation links and answer some questions about Lucene vs Raw Text searches, and some limitations to Research Tools.
 

  1. I would also like to add some transparency that the My Landscape feature in the Google Threat Intelligence Platform will be eventually replacing DTM sometime in 2027.  This new system, is powered by Gemini and will be a relevance driven system which helps surface threats based on relevant threat scenarios, and not just simple text matches like many other systems operate on, including legacy DTM. 
     
  2. For your 2nd Question about free text vs Lucene, please see some of the links below to help explain each function and how to harness the power of Lucene Queries:
     


https://gtidocs.virustotal.com/docs/lucene-queries-in-dtm

 

  1. There are no restrictions on the content / posts / materials we will find and return based on your license tier in Google Threat Intelligence. 
     
  2. I wanted to also expand on a previous comment about research tools as a whole.  This functionality is a good starting point for understanding if the types of data and entities you are looking for are collected within DTM. While this is the primary method for doing a preliminary search for the content we’ve collected, you may see some of the inconsistencies you’ve mentioned but you would NOT experience that with the monitors once they are configured.  Using free-text search on Research tools may produce inconsistent results, as it's preferable to be using the Monitor Topics listings & Search collection types so we’re searching against specific fields in our index, not just doing a raw text search which may not match on your content by the time the initial query completes.  Additionally, Research Tools is only going to return the first 200 results we find.   Advanced Lucene text Queries do work in Research tools, and can be a good way to search for very specific targeted sets of fields and conditions. 
     
  3. Is the divergence between the two result sets by design (e.g., visibility/redaction rules for certain result types, such as compromised credentials), or does it indicate a misconfiguration on our side?
    Research Tools and Monitors are set to be part of the same dataset, however we do not allow users to search for compromised Credentials in Research Tools due to privacy concerns, those must be setup within a monitor with the domains verified by the users in order to expose the passwords. 


I hope this helps, please reach back if you have any further questions or need clarification.

Thanks, 

  • ​​​​​​​Rob