You use Google Security Operations (SecOps) curated detections and YARA-L rules to identify suspicious activity on Windows endpoints. Your source telemetry consists of EDR and Windows Event logs, and your rules match the principal.user.userid UDM field. You need to ingest an additional log source so this field can match all possible log entries from your EDR and Windows Event logs. What should you do?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion