Google SecOps - Single-Event Alert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates incidents in Microsoft Sentinel when Google Security Operations raises an active single-event alert (SINGLE_EVENT, riskScore gte 40) at MEDIUM, HIGH, or CRITICAL severity. These alerts represent a single action like malware execution, credential abuse, or defense evasion severe enough to trigger an incident without requiring multi-signal correlation.

Attribute Value
Type Analytic Rule
Solution GoogleSecOps
ID e5a9b143-7e6c-4f0a-c4b1-9d3f5a8e1c7f
Severity High
Status Available
Kind Scheduled
Tactics Execution, CredentialAccess, DefenseEvasion, Impact
Techniques T1059, T1110, T1562, T1485
Required Connectors GSDetectionAlerts
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DetectionAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to GoogleSecOps