Google SecOps SIEM
Automatic deploy
Supported by Filigran
Detection & Response Enablement
Overview
Streams OpenCTI threat intelligence indicators to Google SecOps SIEM in real time, enabling detection rule management and indicator-based threat hunting.
Google SecOps SIEM offers a cloud-based security information and event management solution that helps organizations collect, analyze, and respond to security incidents across their networks.
The integration of Google SecOps SIEM with OpenCTI enables the automatic dissemination of STIX indicators into Google SecOps SIEM. The connector consumes indicators from an OpenCTI stream, convert them as UDM entities and push them into Google SecOps SIEM using the"entities.import" API.