Can we execute a retro hunt using the playbook based on the provided timeline?

is it possible to run retrohunt from playbook ?

Solved Solved
0 2 190
1 ACCEPTED SOLUTION

Hello @vanitharaj1208 

Yes its possible to execute Retro hunt from the playbook using Action "Execute Retrohunt" from GoogleChronicle. Rule ID, Start time and End time is required.

Reference: Google SecOps  |  Google Security Operations  |  Google Cloud

Thanks

View solution in original post

2 REPLIES 2

Hello @vanitharaj1208 

Yes its possible to execute Retro hunt from the playbook using Action "Execute Retrohunt" from GoogleChronicle. Rule ID, Start time and End time is required.

Reference: Google SecOps  |  Google Security Operations  |  Google Cloud

Thanks

I have a rule that previously generated detections, but now when I attempt to run a retro hunt, it is not generating any alerts.