QuestionQ82
Detection engineeringYou have identified a new threat actor group with several IOCs in Google Threat Intelligence. You want to use some of these IOCs in multiple detection rules in Google Security Operations (SecOps) to help identify suspicious activity. You want to use the most effective approach. What should you do?
- A Identify the detection rules that apply to the new IOCs, and update the YARA-L logic to reference the threat actor group.
- B Add the IOCs to a new or existing reference list, and update the YARA-L logic of detection rules to include the reference list.
- C Save the IOCs in a new collection in Google Threat Intelligence. Share this list with other members of the security team to facilitate their searches and rule creation.
- D Configure a new data feed in Google SecOps that includes the IOCs. Update the YARA-L logic to reference the new IOCs against applicable UDM fields.
Community Discussion