QuestionQ8

Detection engineering

You need to enhance your organization’s existing Security Command Center (SCC) implementation with additional detectors. You have a list of known IOCs and want to incorporate external signals for this capability to provide broad detection coverage. What should you do?

  • A Create an Event Threat Detection custom module using the "Configurable Bad IP" template.
  • B Create a Security Health Analytics (SHA) custom module using the compute address resource.
  • C Create a custom posture for your organization that combines the prebuilt Event Threat Detection and Security Health Analytics (SHA) detectors.
  • D Create a custom log sink with internal and external IP addresses from threat intelligence. Use the SCC API to generate a finding for each event.
Explanation

An Event Threat Detection custom module based on the Configurable Bad IP template lets an organization supply and maintain suspicious external IP addresses or CIDR blocks. Event Threat Detection evaluates the relevant logs for connections to those indicators and creates findings, while retaining its built-in detection logic and threat intelligence.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!