Hoppa till huvudinnehåll
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/virustotalsl1681486227461.azure-sentinel-solution-googlesecops-23e3ed0c-dbf8-4c94-aab0-2de570d3f994/image0_Secops.png

Google SecOps

av VIRUSTOTAL SL.

Detect and correlate Google Security Operations alerts and threat findings within Microsoft Sentinel

This Microsoft Sentinel solution integrates Google Security Operations (formerly Chronicle) to bring detection alerts, threat intelligence findings, and correlated event data directly into your security investigations. It achieves this by deploying data connectors and parsers that ingest Google SecOps detection alerts via the legacyStreamDetectionAlerts API, along with Analytics Rules that map ingested events to actionable Sentinel incidents.

Here's a breakdown of what this solution offers and how it benefits your security operations:

Key Features:
  • Detection Alert Ingestion: Deploys a data connector (Azure Function based) that pulls detection alerts from Google SecOps and ingests them into Sentinel via the Log Ingestion API.
  • Threat Hunting & Detection: Includes pre-built Analytics Rules — GoogleSecOps-DetectionAlerts, GoogleSecOps-GCTIThreatIntelligenceFinding, GoogleSecOps-MultiEventCorrelatedAlert, and GoogleSecOps-SingleEventAlert — that automatically convert Google SecOps alerts and findings into Sentinel incidents.
  • Custom Parser: Ships a normalized KQL parser (GoogleSecOpsDetectionAlerts) to structure raw ingested data for consistent querying and correlation.
  • Google Threat Intelligence: Surfaces Google's threat intelligence findings (GCTI) alongside correlated multi-event and single-event alerts for richer investigation context.
  • Solution Package: Provides a complete, versioned solution package (mainTemplate.json, createUiDefinition.json) for streamlined deployment and management within Microsoft Sentinel.

Benefits:
  • Unified Visibility: Bring Google SecOps detections into the same workspace as your other security signals for centralized monitoring.
  • Faster Investigations: Correlated and single-event alerts give analysts immediate context without needing to pivot to a separate console.
  • Improved Accuracy: Rely on Google's detection and threat-finding engine rather than manual cross-referencing.
  • Enhanced Efficiency: Automated ingestion and mapping reduce the manual effort of triaging Google SecOps alerts.

Target Users:
This solution is ideal for security professionals who rely on Microsoft Sentinel for SIEM and need visibility into Google SecOps detections, including:
  • Security Analysts: Investigate and respond to Google SecOps-driven alerts and incidents.
  • SOC Teams: Monitor and correlate Google SecOps events alongside other telemetry.
  • Incident Responders: Handle and mitigate threats identified by Google's detection engine.

Addressing Customer Needs:
  • Need for Context: Correlated multi-event alerts and threat intelligence findings give analysts deeper insight into the nature of a threat.
  • Efficiency and Speed: Automated ingestion and rule-based incident creation accelerate response times.
  • Reliable Threat Data: Leverages Google's detection engine and threat intelligence for accurate, up-to-date alerting.

By deploying this solution, you empower your security team with unified visibility into Google Security Operations detections, enabling faster and more informed incident response within Microsoft Sentinel
Svenska (Sverige)
Ikon för inaktivering av sekretessval Dina sekretessval
Sekretess för konsumenthälsa Platskarta Kontakta oss Sekretess och cookies Användningsvillkor Varumärken Om våra annonser Hantera cookies