QuestionQ24
Detection engineeringYour Google Security Operations (SecOps) instance is creating alerts for unusual login times across multiple user accounts. SOC analysts report that many of these alerts are false positives associated with service accounts used by scheduled automation tasks. You want to refine the detection logic by using entity-level context available in Google SecOps. What is the most effective action to take?
Community Discussion