Skip to main content

IOC Matches and Mandiant Threat intelligence

  • June 12, 2025
  • 4 replies
  • 38 views

yasinmnk
Forum|alt.badge.img+7

"In our Google SecOps environment, we're currently unable to view any IOC (Indicator of Compromise) matches . Could there be a reason for this, and what solutions might be available? And how to check Mandiant threat intelligence if it does works properly? 

4 replies

kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • June 12, 2025

You need SecOps Enterprise Plus and you can learn more on this guide: Applied Threat Intelligence overview.

Let me know if that helps.


yasinmnk
Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • June 13, 2025

Hi @kentphelps  Thank you for your answer, we have Secops Enterprise Plus and still can't see IOC matches that is important for us, do we need to open a suppert tciket for that?


kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • June 13, 2025

Hi @kentphelps  Thank you for your answer, we have Secops Enterprise Plus and still can't see IOC matches that is important for us, do we need to open a suppert tciket for that?


Support would be able to troubleshoot issues with where you are ingesting IOC log sources from or perhaps any timestamp issues.


yasinmnk
Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • June 16, 2025

thank you already created a support ticket.