Google SecOps SIEM
自動配備
Filigranの提供による
Detection & Response Enablement
概要
Streams OpenCTI threat intelligence indicators to Google SecOps SIEM in real time, enabling detection rule management and indicator-based threat hunting.
Google SecOps SIEM offers a cloud-based security information and event management solution that helps organizations collect, analyze, and respond to security incidents across their networks.
The integration of Google SecOps SIEM with OpenCTI enables the automatic dissemination of STIX indicators into Google SecOps SIEM. The connector consumes indicators from an OpenCTI stream, convert them as UDM entities and push them into Google SecOps SIEM using the"entities.import" API.