Getting Started with Detection-as-Code and Chronicle Security Operations from David French:
- In Part 1 David shares the principles and benefits of managing detection rules as code, an example detection engineering workflow used by security teams, and how to configure a CI/CD pipeline job in GitLab to pull existing detection rules via Chronicle’s API and commit them to a GitLab project: https://www.googlecloudcommunity.com/gc/Community-Blog/Getting-Started-with-Detection-as-Code-and-Chronicle-Security/ba-p/702154
- In Part 2, he demonstrates how to create and modify detection rules via Chronicle’s API: https://www.googlecloudcommunity.com/gc/Community-Blog/Getting-Started-with-Detection-as-Code-and-Chronicle-Security/ba-p/702956
#DetectionAsCode #detectionengineering #chroniclesecurityoperations