flâneur — a map of the web's best reading

How Google Security Operations enriches event and entity data | Google Cloud

cloud.google.com · saved by 1 readers

This document describes how Google Security Operations enriches data and the Unified Data Model (UDM) fields where data is stored. To enable a security investigation, Google Security Operations ingests contextual data from different sources, performs analysis on the data, and provides additional context about artifacts in a customer environment. Analysts can use contextually enriched data in Detection Engine rules, investigative searches, or reports. Google Security Operations performs the following types of enrichment: Enriched data from WHOIS, Safe Browsing, GCTI Threat Intelligence, VirusTotal metadata, and VirusTotal relationship are identified by event_type, product_name, and vendor_name. When creating a rule that uses this enriched data, we recommend that you include a filter in the rule that identifies the specific enrichment type to include. This filter helps improve performance of the rule. For example, include the following filter fields in the events section of the rule that

This document describes how Google Security Operations enriches data and the Unified Data Model (UDM) fields where data is stored. To enable a security investigation, Google Security Operations ingests contextual data from different sources, performs analysis on the data, and provides additional context about artifacts in a customer environment. Analysts can use contextually enriched data in Detection Engine rules, investigative searches, or reports. Google Security Operations performs the following types of enrichment: Enriched data from WHOIS, Safe Browsing, GCTI Threat Intelligence, VirusTo

Explore this link on the map →