You are creating a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You can access Google Threat Intelligence (GTI) data through your Google SecOps subscription.
You need to ensure that the threat-score output in the detection logic affects the alert's risk score and remains available for future detections. What should you do?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion