QuestionQ28

Detection engineering

You are creating a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You can access Google Threat Intelligence (GTI) data through your Google SecOps subscription.

You need to ensure that the threat-score output in the detection logic affects the alert's risk score and remains available for future detections. What should you do?

Explanation

In Google SecOps YARA-L, the outcome section derives values for a triggered detection. Setting the $risk_score outcome variable assigns risk to the resulting alert or detection; the value is stored in the security_result.risk_score UDM field and contributes to entity risk that can be used by subsequent rules. The outcome section is also intended for holding enrichment values for downstream use.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!