flâneur

Overview of context-aware analytics | Google Security Operations | Google Cloud

cloud.google.com · 1,204 words · saved by 1 readers

Google Security Operations enables you to view telemetry, entity context, relationships, and vulnerabilities as a single detection within your Google Security Operations account. It provides entity contextualization to enable you to understand both the behavioral patterns in telemetry and the context of those impacted entities from those patterns. Examples: Customers can use this contextualization for detection filtering, heuristic alert prioritization, triage, and investigation. Security analysts and detection engineers typically work to craft a detection on a basic pattern of event telemetry (an outbound network connection), creating numerous detections for their analysts to triage. The analysts attempt to stitch together an understanding of what happened to trigger the alert and how significant the threat is. Context-aware analytics incorporates advanced enrichment capabilities earlier in the detection authoring and execution workflow, enabling you to provide the following additiona

Unterstützt in: Mit Google SecOps können Sie Telemetrie, Entitätskontext, Beziehungen und Sicherheitslücken als einzelne Erkennung in Ihrem Google SecOps-Konto ansehen. Sie bietet eine Kontextualisierung von Entitäten, damit Sie sowohl die Verhaltensmuster in der Telemetrie als auch den Kontext der betroffenen Entitäten aus diesen Mustern heraus verstehen können. Beispiele: Die Berechtigungen für ein Konto werden angezeigt, für das ein Brute-Force-Login versucht wird. Bedeutung von Daten, die von einem Asset gehostet werden, das auch die Quelle ausgehender Netzwerkaktivitäten ist.…

related reading