Hi
Can some one give me the integration steps for Mandiant with Chronicle SIEM .
Solved! Go to Solution.
Mandiant Intelligence can be purchased as a standalone. There is also Google Security Operations which offers a unified experience across SIEM, SOAR, and threat intelligence.
This would be pull. Iโd need to research the call amount.
Hi @rahul7514
Mandiant integration with Chronicle SIEM is done through the SOAR component.
To integrate Mandiant with Chronicle SOAR:
For detailed instructions on configuring integrations in Google Security Operations SOAR, see Configure integrations.
I hope this helps.
@ErikaB so we wont get it in just Siem
I want to use the the threat feeds to filter the traffic logs and trigger alert when suspicious ip is found.
We have not created playbooks so far.
I think the question of integration of Mandiant Threat intel and SecOps is somewhat dependent upon the package level that the organization has. Depending on that may drive different things that could potentially be done.
Mandiant Intelligence can be purchased as a standalone. There is also Google Security Operations which offers a unified experience across SIEM, SOAR, and threat intelligence.
@ErikaB thanks for the information. When using mandiant threat intel in soar so when we want to enrich ip it makes an api call to mandiant feed right so is there count of how many calls can be made?
Also is this push or pull mechanism?
This would be pull. Iโd need to research the call amount.