Welcome to the Google Cloud Security Forums! Your ultimate security conversation spot. Collaborate with peers and experts to solve challenges, together.
SecOps starts here! Q&A, ask, share, connect.
Google Threat Intelligence chat space. Inquire, contribute, pass it on.
SCC questions? Join in, discuss, solve together.
Security Validation forum: Engage, be curious, stay up to date
Fraud Defense (reCAPTCHA) troubleshooting. Find out the answers together.
Join the discussion. Post, diagnose, get the latest.
We successfully established HTTPS log forwarding profiles within Palo Alto Strata Logging Service last year usingĀ https://malachiteingestion-pa.googleapis.com/v2/unstructuredlogentries:batchCreate.Ā Although these profiles continue to forward logs to
Here is how we combine Chronicle YARA-L correlation with Gemini SecOps to solve a tricky detection challenge:What the rule captures in Chronicle:Ā We watch for a single user account accessing Workday fromĀ at least two completely different external ne
I'm seeing a specific Android device consistently receive floor scores from reCAPTCHA Enterprise, and I can't find any signal that explains why. Looking for anyone who has seen this pattern or knows what an assessment with score: 0 and no reason code
Hi everyone,I am attempting to set up ServiceNow CMS as our ITSM for ticket management, and I am wanting to implement a sort of polling in Google SecOps to check if any updates have been made to the ServiceNow case.I am not too concerned with comment
Hi Team,I have below ingestion filter in GCP which is applied to logs sent out to secops someone changed the filter but i am not able to search for log for the same to identify who updated / changed the filter is there a way to get that details from
Hi Team,We have a sample log where the internetmessageID field is being mapped to network.email.mail_id in UDM. We need to create an array for this field using a parser extension.As I am new to parser development, could someone please guide me on how
I need to map specifically internet message ids from the Office 365 logs. Issue is in the mailitemsaccess logs that are bind events, multiple internet message ids can be captured within a single json path. I need to be able to iterate through and gra
We noticed that the GCP Cloud NGFW Enterprise endpoints issue impersonation certificates without AKID extension. This violates https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.1While Cloud NGFW is claimed to be powered by Palo Alto network
Hi All,In our environment, we are using the Bindplane OP Console. As part of our logging and monitoring requirements, we need to forward the Bindplane OP Console Audit logs to the SecOps console for centralized visibility and analysis. Could someone
I have built a custom connector and now i have alerts flowing in and now i want to customize alert name with some enriched valuesĀ Ā how can i achieve this ?Ā kindly help me with thisand please dont provide answers from AI
Summary:In the checkbox image challenge popup, the instruction line renders correctly in Japanese (e.g. ć横ęę©éć®ćæć¤ć«ććć¹ć¦éøęćć¦ćć ććć), but the red hint/error text and the verify/skip button labels render as random-looking strings (e.g.F&JfWOUD, 9-CW`).
Hi everyone,How to change the "From Email address" in SecOps Scheduled Reports. As I can see it is being sent from Google SMTP server, But I don't want to send data to Google SMTP instead I want to use our internal SOAR Email Integration to send this
Google Cloudās agentic architecture provides strong controls for identity, isolation, prompt protection, observability, and tool access.However, once an AI agent is allowed to trigger a consequential operation ā such as approving a financial conditio
My personal Google account unexpectedly has access to a Google Cloud project that I do not recognize.Project ID: enhanced-epoch-kf6jrProject number: 379531433770Organization ID: 71994629047The project is inside an organization and folder hierarchy th
Hi,Iām trying to build a Native Dashboard that would show the log_count and log_volume for GCP Projects but owned by different business units in the org.Also, all ingestion into SecOps is via Direct IngestUsing the below query, the namespace returns
The leaderboard is currently empty. Contribute to the community to earn your spot!
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.