Google Security Operations Detection Rules Logo

Google Security Operations Detection Rules

0
Free
Visit Website

This repository contains sample detection rules and dashboards for use within Google Security Operations. Rules within the community directory were created by the Google Security Operations Security team and members of the Google Security Operations user community. These rules take advantage of the latest YARA-L syntax, provide a starter set of rules that can be used with Google Security Operations' entity graph as well as for other use cases or as inspiration for new use cases. Rules within the soc_prime_rules directory were created by SOC Prime and made available to Google Security Operations Customers. Before deploying any rules, using Google Security Operations' test rule functionality is considered a best practice and provides the opportunity for users to tune rules to their environment before creating alerts for them. Dashboard YAML files can be imported into Google Security Operations dashboards using the Add - Import Dashboard capability found next to the Personal Dashboards or Shared Dashboards section of the UI. The intent of this is to provide sample dashboards that can serve as templates, inspiration or starting points for your

FEATURES

ALTERNATIVES

A cybersecurity concept categorizing indicators of compromise based on their level of difficulty for threat actors to change.

Signature-based YARA rules for detecting and preventing threats within Linux, Windows, and macOS systems.

Analyze suspicious files, domains, IPs, and URLs to detect malware and other breaches, and share results with the security community.

A PowerShell module for threat hunting via Windows Event Logs

msticpy is a library for InfoSec investigation and hunting in Jupyter Notebooks with extensive functionality for log data analysis, threat intelligence enrichment, and visualization.

Cortex is a tool for analyzing observables at scale and automating threat intelligence, digital forensics, and incident response.

Python APIs for serializing and de-serializing STIX2 JSON content with higher-level APIs for common tasks.

Machinae is a tool for collecting intelligence from public sites/feeds about various security-related pieces of data.

PINNED