Skip to main content
Solved

Mandiant integration with chronicle

  • October 17, 2024
  • 7 replies
  • 47 views

rahul7514
Forum|alt.badge.img+10

Hi

Can some one give me the integration steps for Mandiant with Chronicle SIEM . 

Best answer by ErikaB

@rahul7514 

Mandiant Intelligence can be purchased as a standalone.  There is also Google Security Operations which offers a unified experience across SIEM, SOAR, and threat intelligence.  

7 replies

ErikaB
Community Manager
Forum|alt.badge.img+10
  • Community Manager
  • October 17, 2024

Hi @rahul7514 

Mandiant integration with Chronicle SIEM is done through the SOAR component.

To integrate Mandiant with Chronicle SOAR:

  1. Go to Response > Playbooks in the SOAR interface.
  2. Select the CDIR PLAYBOOK.
  3. Optionally, enable Mandiant enrichment by setting the Mandiant_Enrichment variable to true.
  4. In the Cases page, attach the playbook to a test alert to ensure proper configuration.
  5. You can use a simulation mode to test the playbook run.
  6. Review the playbook results and the overview in the Cases and Alerts tabs.
  7. Update the playbook if necessary until you get the expected flow.

For detailed instructions on configuring integrations in Google Security Operations SOAR, see Configure integrations.

I hope this helps. 


rahul7514
Forum|alt.badge.img+10
  • Author
  • Bronze 2
  • October 17, 2024

@ErikaB so we wont get it in just Siem

I want to use the the threat feeds to filter the traffic logs and trigger alert when suspicious ip is found. 

We have not created playbooks so far. 


jstoner
Staff
Forum|alt.badge.img+22
  • Staff
  • October 17, 2024

I think the question of integration of Mandiant Threat intel and SecOps is somewhat dependent upon the package level that the organization has. Depending on that may drive different things that could potentially be done.


rahul7514
Forum|alt.badge.img+10
  • Author
  • Bronze 2
  • October 17, 2024

I think the question of integration of Mandiant Threat intel and SecOps is somewhat dependent upon the package level that the organization has. Depending on that may drive different things that could potentially be done.


@jstoner @ErikaB 

So if they upgrade their  subscription, will the feed feature automatically start or do we need to integrate anything? 

Can mandiant be recieved as standalone?? 


ErikaB
Community Manager
Forum|alt.badge.img+10
  • Community Manager
  • Answer
  • October 18, 2024

@rahul7514 

Mandiant Intelligence can be purchased as a standalone.  There is also Google Security Operations which offers a unified experience across SIEM, SOAR, and threat intelligence.  


rahul7514
Forum|alt.badge.img+10
  • Author
  • Bronze 2
  • October 24, 2024

@rahul7514 

Mandiant Intelligence can be purchased as a standalone.  There is also Google Security Operations which offers a unified experience across SIEM, SOAR, and threat intelligence.  


@ErikaB thanks for the information. When using mandiant threat intel in soar so when we want to enrich ip it makes an api call to mandiant feed right so is there count of how many calls can be made? 

Also is this push or pull mechanism? 


dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • October 24, 2024

@ErikaB thanks for the information. When using mandiant threat intel in soar so when we want to enrich ip it makes an api call to mandiant feed right so is there count of how many calls can be made? 

Also is this push or pull mechanism? 


This would be pull.  I’d need to research the call amount.