Hi All,
We want to integrate Mandiant with Google SIEM.
Can someone please advise how can this be done.
Hi @Khushboo14,
could you elaborate more on what you want to achieve exactly? (Use Case)
Mandiant is integrated as a threat intel source inside the entity context graph depending on your license.
There are several option you can "integrate" TI, for example within rules. Imagine a rule correlating target IP with the global context.
$event.target.ip = $maliciousIp
Hope this helps. If not, please elaborate on your use case.
We need to integrate Mandiant DTM as a Feed with Google SIEM.
DTM is a supported log type but currently it doesn't have a default parser, so a custom one would need to be built. I advise to go through support as this request my be prioritized for a default parser:
Thanks for that and by which integration method we can integrate Mandiant DTM with SIEM.