3Threat hunting
- 3.1Threat hunting across environments
Understand developing queries across environment logs to find anomalous activity, analyzing user behavior for anomalies, investigating network/endpoints/services for IOCs with Google Cloud tools (Logs Explorer, Log Analytics, BigQuery, Google SecOps), collaborating with incident response, and developing hypotheses from behavior/threat intel/posture/incident data.
- 3.2Leveraging threat intelligence and retrohunt
Understand searching IOCs in historical logs, identifying new attack patterns/techniques in real time using threat intelligence and risk assessments (GTI, detection rules, SCC toxic combinations), analyzing entity risk score for anomalies, retrohunting historical events with newly enriched logs (Google SecOps rules engine, BigQuery, Cloud Logging), and proactively searching for underlying threats with threat intelligence.

