Skip to main content

Rules and how they works

  • January 27, 2023
  • 1 reply
  • 2 views

Forum|alt.badge.img

Does anyone know if Google have a list of Rules which are available in Chronicle Security and are base on which logs source.

1 reply

mccrilb
Forum|alt.badge.img+12
  • Silver 2
  • January 30, 2023

Not that I know of


We use SOC Prime as one source for our rule content. We had qradar previously so we recreated the rules that were getting hits. Other sources we use are purple teaming, our intel group and SOC findings. SOC Prime is a great way to stay ahead of things though.