Stay Informed
Recently active
In a time when cyberattacks are rapidly growing in both frequency and sophistication, organizations are focused on addressing potential threats in a smarter, faster, and more cost-effective manner. Chronicle SIEM is Google’s cloud-based security platform capable of ingesting massive amounts of data with built-in intelligence to quickly analyze and identify threat signals. In this video, Program Manager Nick Troutini, provides Chronicle SIEM users the information and resources you need to quickly gain cloud security confidence with Chronicle SIEM, stay up-to-date with the latest product updates, and find support when you need it. You can use the timestamp links to quickly navigate to topics in the video that you’re interested in learning more about: 01:52 Where to find self-service support resources: documentation, events, and community 03:24 How to get help with your technical questions or issues: reaching the support team, using the support portal 04:46 What's
Hi SecOps Community :)I’m excited to share that our SecOps Community (where we are now) will have a new and improved home beginning September 25, 2023, as part of the Google Cloud Community (GCC). My name is Shaked, your current Community Manager and together with @Willie_Turney , @Lauren_vdv & @Ray_a from the Google Cloud Community team , I’m thrilled to have the opportunity to help support you as we make this transition. We believe that a strong community is essential for both your success and ours and we want to ensure we provide you with the support, content, and space to allow you to connect and learn from each other.Moving to the GCC ensures long-term durability and sustainability of this community and its programs. This iteration will also allow us to manage and moderate the community more efficiently, which will enable us to offer more updates from the product team and more community events to learn and share best practices from Cloud Security experts.What’s ch
Hi Community Chronicle Security Operations’ momentum is holding strong with additional functionality to save you time and resources. We are continuing to bolster threat detection, investigation and response capabilities for cloud environments while also focusing on everyday functionality. To find a comprehensive list of our Q2 additions to Chronicle Security Operations, visit this blog . To find a comprehensive list of recent Chronicle Release Notes/Changes, go here .
Hello SecOps Community, Stay up to date with everything going on in Chronicle SIEM and SOAR by reading the SecOps Customer Newsletter! Updated every other month, you can find a summary of major Product Updates, Learning and Training, Community Announcements, Best Practices, and Upcoming Events. Chronicle Security Operations Updates Introducing turnkey TDIR (Threat Detection, Investigation and Response) for Google Cloud This latest release enables teams to: Detect with confidence. Out-of-the-box detection rule sets developed by Google threat researchers surface cloud attack vectors and provide high fidelity, contextualized alerts that quickly give insight into potential threats in your Google Cloud environment. Investigate with full context. Visualize threat storylines, complete with cloud-specific context that is correlated with additional data and context from across your environment for fast and efficient investigations. Respond with speed and precision. Streamline work
Hello SecOps Community, Stay up to date with everything going on in Chronicle SIEM and SOAR by reading the SecOps Customer Newsletter! Updated every other month, you can find a summary of major Product Updates, Learning and Training, Community Announcements, Best Practices, and Upcoming Events. SecOps Community Spotlight For a quick start guide on Getting Started With Chronicle SIEM, check out this video with Program Manager, Nick Troutini. Included in the content: Where to find self help resources, how to get help with your technical questions or issues, what’s included and how to access Chronicle documentation, and the features and benefits of the SecOps Community. Chronicle Security Updates We’ve been busy on the Chronicle Security Operations front, and have been hustling to continue to add more innovative and practical features. To find a comprehensive list of our Q1 additions to Chronicle Security Operations, visit this blog. To find a comprehensive list of recent C
Hello SecOps Community,Stay up to date with everything going on in Chronicle SIEM and SOAR by reading the SecOps Customer Newsletter! Updated every other month, you can find a summary of major Product Updates, Learning and Training, Community Announcements, Best Practices, and Upcoming Events.SecOps Community SpotlightFor a quick start guide on Getting Started With Chronicle SIEM, check out this video with Program Manager, Nick Troutini. Included in the content: Where to find self help resources, how to get help with your technical questions or issues, what’s included and how to access Chronicle documentation, and the features and benefits of the SecOps Community.Chronicle Security Operations UpdatesGoogle named a 2023 Strong Performer in the Gartner Peer Insights™ Voice of the Customer for Security Information and Event ManagementWe are thrilled to be named a "Strong Performer" in the Gartner Peer Insights Voice of the Customer for SIEM with a 4.8/5 star rating and 89% of customers s
Hello again SecOps Community! I am thrilled to share that Google Cloud and Mandiant will be united at RSAC 2023! We have a robust lineup at the event, including a keynote, 12 track sessions, booth in the North Expo ( N6058 ), and several hospitality events. Sign up for these “must-attend” events: Visit our website for a full list of our activities at the event! PS. If you haven’t registered for RSAC yet, be sure to use our discount code. To get a free Expo pass, enter the Google Cloud and Mandiant code 54SMANDIAXP when you register . Or use code 52FCDMANDIA to get $150 off the Full Conference pass. Hope to see you there!
Hello SecOps Community,Stay up to date with everything going on in Chronicle SIEM and SOAR by reading the SecOps Customer Newsletter! Updated every other month, you can find a summary of major Product Updates, Learning and Training, Community Announcements, Best Practices, and Upcoming Events.SecOps Community SpotlightSecOps Office Hours We had 2 very exciting Office Hours in the Community this month where we covered these topics:How to use Approval links in Chronicle SOAR - featuring the newly added "Approval links" that allow people outside your SOC to respond using a link sent to them by the SOAR platform.What are reference lists in Chronicle SIEM and how to use them - the session helped SIEM users learn what are Reference Lists, what you can do with them, and when you should (and when shouldn't you) use them.We will be scheduling additional office hours so stay tuned and access the Secops Community for more information.SecPops Community PlaylistIn the event of celebrating 6K
Hi SecOps Community! I wanted to invite you all to our upcoming Google Cloud Security Talks 2023 virtual event on March 22. Our first Security Talks of 2023 is designed to help you better understand threat actors and potential attack vectors, secure your cloud transformation, and detect, investigate and respond to threats faster. Hear from experts and explore the latest threat intel from across Google Cloud’s Threat Analysis Group (TAG), Mandiant and VirusTotal, see what your peers had to say as we review the results of a recent cloud security survey report, and check out all the latest Google Cloud Security product innovations! Check out our agenda, register, and more here --> https://goo.gle/3n1YmlS View files in slack
Hello SecOps Community, Stay up to date with everything going on in Chronicle SIEM and SOAR by reading the SecOps Customer Newsletter! Updated every other month, you can find a summary of major Product Updates, Learning and Training, Community Announcements, Best Practices, and Upcoming Events. SecOps Community Spotlight SecOps Office Hours In the last two office hours, we covered these topics: How to use Approval links in Chronicle SOAR - featuring the newly added "Approval links" that allow people outside your SOC to respond using a link sent to them by the SOAR platform. What are reference lists in Chronicle SIEM and how to use them - the session helped SIEM users learn what are Reference Lists, what you can do with them, and when you should (and when shouldn't you) use them. We will be scheduling additional office hours so stay tuned and access the SecOps Community for more information! SecPops Community Playlist In the event of celebrating 6K SOAR & SIEM Users
As we continue to provide you with all the knowledge you need to navigate the Chronicle platform, we are now turning our attention to a very popular feature that you have asked a lot about. Our next Office Hour addresses Chronicle SOAR Approval Links. Here's the link to register!
This post was originally sent by Tom Fridman The future's so bright - gotta wear shades! How do we know the future? Well we don’t, but we do know that Chris Martin will be the first SIEM person to present the next SecOps Community office hour- and when Chris explains something, well let’s just say that the sun puts on Chris-glasses. This time we will tackle Chronicle SIEM reference lists especially for you- SIEM users! Ready to be dazzled? Join us https://forms.gle/UKiFReY858brRDQKA
Join us for our next SecOps Community Office Hours on February 22nd at 10AM ET. @cmmartin_google, a Chronicle Security Specialist, will lead the session on what Chronicle SIEM Reference Lists are, what you can do with them, and when you should (and shouldn't) use them. Sign up and ask your questions in advance here. Hope to see you there!
This post was originally sent by Tom Fridman hi Oops you did it again! You've sent us your most beloved pop songs that together created the most amazing SecPops playlist of all time. A playlist like this will bring all the boys to the yard. It'll wake you up like you were hit by a wrecking ball. It's a toxic playlist that will make you fall crazy in love. So SecOps people - let's get loud with our brand new and wonderful playlist. https://open.spotify.com/playlist/11RTj8KuDt1JZ2iqj5pfPM?si=5c3e76c14d32487a
This post was originally sent by Tom Fridman Tom the boy (this is how we call him in the office) is king of the Grandma test. Do you know this test? It's when you are sitting down for a family dinner and grandma asks you "explain to me again what it is that you do?" If grandma can repeat that and explain it to her friends, you passed the test. Using Tom's simple approach, any granny can use even the most complex platforms and features. Tom will be joining us this week for office hours and will talk about the newly added approval links feature. Register here View files in slack
This post was originally sent by Tom Fridman As we continue to provide you with all the knowledge you need to navigate the Chronicle platform, we are now turning our attention to a very popular feature that you have asked about a lot- our next Office Hour addresses "Chronicle SOAR Approval Links". Here's the link to register ! Don't miss it!
This post was originally sent by Tom Fridman Is this highly informative session about connectors something you missed? Please find attached the video. https://www.youtube.com/watch?v=TtRst5wvKsc&list=PLBgogxgQVM9txkUU42ugsTyf75YGJmfL6&index=3
Hello Cloud Security Champions,Stay up-to-date on all the latest with SIEM and SOAR by reading our Google SecOps Customer Newsletter! Posted every other month, this is where you can see a summary of major product updates, resources, learning, training, community spotlights, best practices, and events.SecOps Community SpotlightThis past month we launched some exciting new things, including the Chronicle users Tips and Tricks Book! You sent us your best Chronicle SOAR tips and tricks, we created a book out of it, and the result is pretty amazing!Thanks to all of the amazing community members who shared their brilliant ideas with us!SecOps Community Office HoursAs your familiarity with Chronicle continues to grow, we are seeing your desire to learn more. To give you an edge and help you learn, we have decided to offer SecOps community office hours!So, how does it work?1. A date and topic will be posted here.2. You can register for the session and submit questions regarding the topics w
Hello Cloud Security Champions, Stay up-to-date on all the latest with SIEM and SOAR by reading our Google SecOps Customer Newsletter! Posted every other month, this is where you can see a summary of major product updates, resources, learning, training, community spotlights, best practices, and events. SecOps Community Spotlight This past month we launched some exciting new things, including the Chronicle users Tips and Tricks Book! You sent us your best Chronicle SOAR tips and tricks, we created a book out of it, and the result is pretty amazing! Thanks to all of the amazing community members who shared their brilliant ideas with us! SecOps Community Office Hours As your familiarity with Chronicle continues to grow, we are seeing your desire to learn more. To give you an edge and help you learn, we have decided to offer SecOps community office hours! So, how does it work? A date and topic will be posted here. You can register for the session and s
This post was originally sent by Tom Fridman Hi It's been almost a year since we created the Community SOC playlist and we have been listening to it non-stop. Every time we sit down to work, we put it on and enjoy our community's chosen tunes (it's straight fire btw). But it's been a while, and we think it's about time to change things up. The last playlist was dedicated to hardcore music, so to mix things up we decided that we wanted this one to be all about happy, fun music - Pop! So..... with no further introduction (nearly) we invite you to help us create the SecOps community's pop playlist: SecPops. Send us your must-have pop song here, in private or wherever you feel comfortable and we will add it to our awesome community playlist! View files in slack
This post was originally sent by Tom Fridman Hi We know how badly you wanted to join the Mapping and Modeling session - but you just couldn’t because of the holiday madness. Don't worry, it's cool - here is the video .
This post was originally sent by Tom Fridman Connectors work as a main mechanism for fetching and ingesting alerts from any 3rd systems into Chronicle SOAR. Therefore, they are crucial for the creation of cases and alerts which can then be automated using playbooks. Join us for a session dedicated to connectors! "Connectors Part 1" (Part 2 will be more advanced). January 26th 10am ET Link to register View files in slack
What is the mapping and modeling process? Why do we need it? What are the ways that mapping and modeling help me gain visibility, group and investigate my cases? What are the available entity types and what does source-destination mean? Learn the answers to these questions and more by joining us for SecOps Community Office Hours on January 11th at 10AM ET. Register today!
This post was originally sent by Tom Fridman Missed the session? Here is the video for you ! Thank you @Jay_Sverdlov for a wonderful office hour.
This post was originally sent by Tom Fridman Hi Community ( ) The supply chain has become a major attack vector, and security operations teams must take note. This week, we share with you a research report on supply chain security, which explores events like SolarWinds and Log4j and shares actionable insights for organizations, among other findings. https://goo.gle/3hk7mjs View files in slack
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.