Google SecOps - Multi-Event Correlated Alert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates incidents in Microsoft Sentinel when Google Security Operations raises an active multi-event correlated alert (MULTI_EVENT, riskScore gte 40) at HIGH or CRITICAL severity. These alerts indicate complex attack patterns like lateral movement, staged persistence, or command-and-control identified by correlating multiple signals across a time window.

Attribute Value
Type Analytic Rule
Solution GoogleSecOps
ID d4f8a032-6d5b-4e9f-b3a0-8c2e4f7d0b6e
Severity High
Status Available
Kind Scheduled
Tactics LateralMovement, Persistence, PrivilegeEscalation, CommandAndControl
Techniques T1210, T1021, T1053, T1055
Required Connectors GSDetectionAlerts
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DetectionAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to GoogleSecOps