Welcome to the

Google Cloud Security Community

Here’s where you’ll find a buzzing community of Security professionals from around the world with one common mission: bringing their Security platforms to the next level.

cancel
Showing results for 
Search instead for 
Did you mean: 
Bronze 3
Since ‎02-15-2022
‎11-20-2023

My Stats

  • 15 Posts
  • 0 Solutions
  • 4 Likes given
  • 15 Likes received

amalone341's Bio

Badges amalone341 Earned

View all badges

Recent Activity

Recently I reviewed an article covering an attack path that an actor took in a Google Workspace/GCP environment.https://www.bitdefender.com/blog/businessinsights/the-chain-reaction-new-methods-for-extending-local-breaches-in-google-workspace/When goi...
Is it possible to make a Yara-L rule that is detecting off of a specific field in the additional section?I have data in the UDM field:additional.fields["entity"].entity_payload.attachments.name = "test.exe" I do not know how to access data after the ...
In the documentation it seems that the arrays.contains function can be used like the following, arrays.contains($asset_id_list, "id_1234")Is it possible to use the function with two variables so I can compare the list with a value in a UDM field?The ...
Is there any way in Yara-L to check if a UDM field contains a substring of another UDM field? The following example shows a use case for this and the question I am trying to ask of the data: rule variable_testing {meta: author = "amalone" description...
Does anyone have any advice or example dashboards of good ways to view the graph data within the platform? I am looking for something like the "main" or "IOC Matches" dashboard that provides a high level overview of what data we have access to with t...