QuestionQ4

Threat hunting

You received an IOC from your threat-intelligence feed that is identified as a suspicious domain used for command and control (C2). You want to use Google Security Operations (SecOps) to investigate whether this domain has appeared in your environment. You want to search for this IOC using the most efficient approach. What should you do?

Explanation

A UDM search limited to the DNS portion of the network event data directly examines normalized DNS telemetry for the domain, avoiding the unnecessary breadth of a raw-log string search. Google SecOps supports searches over normalized UDM events and provides domain-focused investigation capabilities for determining whether a domain is present in enterprise data.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!