QuestionQ21
Threat huntingYou are a SOC analyst investigating a case in Google Security Operations (SecOps). The case includes a file hash that playbooks have automatically enriched with VirusTotal context and classified as likely malicious. You need to rapidly identify the devices and users in your organization that have interacted with this file. What should you do?
- A Build a playbook to perform a UDM search matching on the file hash in Google SecOps SIEM.
- B Build a playbook to query your threat intelligence platform (TIP) for the presence of the file hash.
- C Use a manual action in Google SecOps SOAR to perform a UDM search matching on the file hash in Google SecOps SIEM.
- D Use a manual action in Google SecOps SOAR to query your threat intelligence platform (TIP) for the presence of the file hash.
Community Discussion