Security Operations SOAR: Step 3 - Utilize Chronicle Marketplace

Table of Contents

Below you'll find a table of contents for the Utilize Chronicle Marketplace journey.

soar-marketplace.png

Feeling overwhelmed by siloed security tools and manual threat response processes? You're not alone. The Google Chronicle SOAR Marketplace offers a solution to your overwhelm. Imagine a central hub where you can access a wealth of pre-built integrations, community-developed playbooks, and powerful analytics - all designed to streamline your Security Operations Center (SOC) workflows and supercharge your incident response. Stop reinventing the wheel and tap into the collective expertise of the security community. The Marketplace empowers you to seamlessly connect SecOps SOAR with leading security tools, automate repetitive tasks with pre-built playbooks, and gain invaluable insights from comprehensive dashboards. This collaborative environment fosters innovation, saves valuable time, and allows your SOC team to focus on what matters most - effectively combating cyber threats.

Prerequisites

  • Entitlement for SecOps SOAR on the account and project
  • Administrative permissions to Chronicle SOAR
  • Administrative Access for any 3rd party applications that will be integrated with Chronicle SOAR via the Marketplace

Actions

soar-marketplace-marketplace-integrations.png

Marketplace Integrations

The Marketplace allows you to install company integrations, integrations published by the community, as well as custom integrations you have built in the IDE. The Marketplace also contains a repository for predefined Use Cases, Power Ups that enhance Playbook capabilities, and Analytics that provide valuable insights.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. In the Chronicle UI, click on the Marketplace icon in the top right, then click on Integrations.

  2. Search through the Integrations and click the down arrow icon to install the integration.

  3. Once the integration is installed, navigate to the main section that integration targets.

    1. For instance, you may need to navigate to SOAR Settings > Connectors if the integration is a connector.

  4. Click the Gear icon next to the integration you need to configure.

Relevant Links
soar-marketplace-marketplace-use-cases.png
Marketplace Use-Cases

Chronicle Marketplace is home to many useful things, including Use Cases. Use Cases are a great way to utilize pre-built Chronicle SOAR integrations, playbooks, etc. - all provided by the community, without you needing to understand the backend data modeling and filtering.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. Define the Use-case | Docs

    1. Write a description of the security threat you are solving with the use case.

    2. Define what kind of alert will be handled and what is the detection product that generates it.

  2. Draw an incident response, orchestration, or automation process, to handle this alert. | Docs

  3. Prepare Use Case Alerts | Docs

    1. Create a custom Alert / Event according to a real data case.

    2. Generate sample security alerts / events from a detection tool to simulate the use case.

    3. Go to Cases > click “+” Plus > Simulate Cases.

  4. Extract Entities (Map & Model the data) | Docs

    1. Run the Zero to Hero test case.

    2. In the Cases tab, click to open the Mail case, select Events tab.

    3. Click on the Gear icon on the right of the Alert to open the Event Configuration screen.

    4. On the top left corner, click on the word Mail in the hierarchy.

    5. Assign the Visual Family that most represents the data.

    6. Switch to Mapping and map the Entity Fields.

  5. Build a Playbook. | Docs

  6. Write a Guide. | Docs

  7. Publish the Use Case. | Docs

Relevant Links

soar-marketplace-marketplace-power-ups.png

Marketplace Power-Ups

Power Ups are tools included in the Chronicle Marketplace that enhance your ability to automate processes for more efficient playbooks.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative permissions to Chronicle SOAR
Steps
  1. Power-ups do not need anyu special configuration as they are in-house Chronicle actions.

  2. New power-ups will be pushed to the Chronicle Marketplace all the time.

  3. Click on the Read More in each power up to see what they contain.

Relevant Links
Contributors
Version history
Last update:
3 weeks ago
Updated by: