Google SecOps v6.0.0
Retrieve Google SecOps detections, impacted assets, IOC matches, and 3P alerts to enrich your XSOAR workflows.
- Author:
- Support:
- partner
- Default data source:
- Google Chronicle Backstory Streaming API
Incident fields (60)
- Chronicle Alert Count
- Chronicle Alert Name
- Chronicle Auto Block Entities
- Chronicle Curated Events
- Chronicle DBot Score
- Chronicle Detection Created Time
- Chronicle Detection ID
- Chronicle Detection State
- Chronicle Detection Time
- Chronicle Detection Type
- Chronicle Detection Window End Time
- Chronicle Detection Window Start Time
- Chronicle Domain Name
- Chronicle Events
- Chronicle First Seen
- Chronicle IOC Ingest Time
- Chronicle Last Seen
- Chronicle Rule ID
- Chronicle Rule Name
- Chronicle Rule Type
- Chronicle Rule Version
- Chronicle Skip Entity Isolation
- Chronicle Source Product
- Chronicle User
- ChronicleAsset Support Contact
- Google SecOps Alert Count
- Google SecOps Alert Details
- Google SecOps Alerts SLA Critical Expiration Time
- Google SecOps Alerts SLA Expiration Time
- Google SecOps Alerts SLA Remaining Time Since Last Pause
- Google SecOps Alerts SLA Status
- Google SecOps Assignee
- Google SecOps Case ID
- Google SecOps Closure Action
- Google SecOps Closure Comment
- Google SecOps Closure Reason
- Google SecOps Closure Root Cause
- Google SecOps Description
- Google SecOps Entity Details
- Google SecOps Environment
- Google SecOps Important
- Google SecOps Incident
- Google SecOps Involved Suspicious Entity
- Google SecOps Last Modified User
- Google SecOps Last Modified User ID
- Google SecOps Overflow Case
- Google SecOps Playbook Status
- Google SecOps Priority
- Google SecOps Products
- Google SecOps SLA Critical Expiration Time
- Google SecOps SLA Expiration Time
- Google SecOps SLA Remaining Time Since Last Pause
- Google SecOps SLA Status
- Google SecOps Score
- Google SecOps Source
- Google SecOps Stage
- Google SecOps Status
- Google SecOps Tasks
- Google SecOps Type
- Google SecOps Update Time
Indicator fields (8)
Indicator types (1)
Integrations (4)
Layouts (5)
Playbooks (8)
- Case Investigation - Google SecOps
- ChronicleAsset Investigation - Chronicle
- ChronicleAssets Investigation And Remediation - Chronicle
- Hostname And IP Address Investigation And Remediation - Chronicle
- IOC Enrichment and Blocking - Google SecOps
- Investigate On Bad Domain Matches - Chronicle
- List Device Events - Chronicle
- Threat Hunting - Chronicle
Scripts (15)
- ChronicleAssetEventsForHostnameWidgetScript
- ChronicleAssetEventsForIPWidgetScript
- ChronicleAssetEventsForMACWidgetScript
- ChronicleAssetEventsForProductIDWidgetScript
- ChronicleAssetIdentifierScript
- ChronicleDBotScoreWidgetScript
- ChronicleDomainIntelligenceSourcesWidgetScript
- ChronicleIsolatedHostnameWidgetScript
- ChronicleIsolatedIPWidgetScript
- ChronicleListDeviceEventsByEventTypeWidgetScript
- ChroniclePotentiallyBlockedIPWidgetScript
- ConvertDomainToURLs
- ExtractDomainFromIOCDomainMatchRes
- GoogleSecOpsSyncCaseInformation
- ListDeviceEvents
README
Quickly respond to security incidents by integrating Google SecOps with Palo Alto Networks Cortex XSOAR.
Google SecOps is a cloud service, built as a specialized layer on top of core Google infrastructure, designed for enterprises to privately retain, analyze, and search the massive amounts of security and network telemetry they generate. Google SecOps normalizes, indexes, correlates, and analyzes the data to provide instant analysis and context on risky activity.
Google SecOps instances, APIs and search parameters are all accessible directly within Cortex XSOAR for full automation of playbooks.
For more information, please visit https://chronicle.security/products/platform/