Now that Google bought Mandiant, Google Chronicle may become an insanely good platform if there is some merging of techniques and tooling there!
Definitely something to keep an eye on for SOC teams if re-tooling or looking to bolster your tooling.
https://chronicle.security
@cybergingey Seems like it's definitely going to happen (merging of things, that is). Mandiant was front-and-center during a few Cloud Next presos last month, including some discussion about it with Chronicle.