4Detection engineering
- 4.1Developing and implementing detection mechanisms
Understand reconciling threat intelligence with user/asset activity, analyzing logs/events for anomalies, detection rules and searches across timelines, detection rules using risk values (Google SecOps reference lists), assigning risk values (Google SecOps Risk Analytics, curated detection rules), detecting posture/risk-profile changes (SCC Security Health Analytics, posture management), identifying low-prevalence processes/domains/IPs (YARA-L rules), using entity/context data (SecOps entity graph), and SCC Event Threat Detection custom detectors.
- 4.2Leveraging threat intelligence for detection and reducing false positives
Understand scoring alerts based on the risk level of IOCs, searching ingested security telemetry with the latest IOCs, and measuring the frequency of repetitive alerts to identify and reduce false positives.

