Chronicle, the security startup that spun off and then later re-merged with Google Cloud, today rolled out a new threat detection tool called Detect.
Google Cloud started talking about Detect’s pieces at RSA Conference earlier this year. This included a detection rules engine based on YARA-L, a language built specifically for modern threats and behaviors, including types described in Mitre ATT&CK.
Also at RSA, Google added a Chronicle capability it calls intelligent data fusion, which combines a new data model and the ability to automatically link multiple events into a single timeline. Palo Alto Networks Cortex XSOAR is Google’s first partner to integrate with this.
“And Detect is basically the rest of the puzzle,” said Google’s Rick Caccia, head of marketing for cloud security. “We’ve built out the rules engine so it can handle very complex event analytics on that stitched data. We’ve flushed out the language intuitive to these Mitre ATT&CK scenarios. And then we’ve added a very interesting set of threat signals and rules feed from our internal research team.”
How Chronicle Detect WorksHere’s how it works. Security teams first send their telemetry to Chronicle so that Detect can use this security data to detect threats. Detect maps that data into a common model across machines, users, and threat indicators so that security teams can apply detection rules to a unified set of data.
Customers can use rules out-of-the-box, build their own, or migrate rules from legacy threat detection tools. In a blog post about Detect, Caccia and Cloud Security VP of Engineering Sunil Potti say many organizations are integrating Sigma-based rules or converting their legacy rules to Sigma for portability. “Chronicle Detect includes a Sigma-YARA converter so that customers can port their rules to and from our platform,” they wrote.
Additionally, Chronicle customers have access to detection rules and threat indicators from Uppercase, which is Chronicle’s threat research team. Uppercase analyses indicators of compromise against security telemetry and alerts customers immediately when they have high-risk indicators in their environments.
Detect works across on-premises data centers, Google Cloud, and other cloud environments.
While Chronicle Detect isn’t the first threat-detection product on the market, it is betting its core strengths — namely Google-scale data analytics — to win market share.
“The big problem most any customers have is: they can’t run detection rules against all the data,” Caccia said. “They don’t run quickly enough, so they catch a problem a day after it happens or later, and it’s not real time. It just takes forever. So the first thing is this rules engine works at the speed and scale of Google infrastructure. We built it at Google scale, you can run it against petabytes of data, and it works in basically real time. That is a very useful thing for companies that are drowning in data.”
Comments