Google Chronicle

Chronicle, a security analytics platform, joined Google Cloud in June 2019. The platform itself was launched at RSA 2019 “to help change the way any business could quickly, efficiently, and affordably investigate alerts and threats in their organization.”

Google announced another two additions to the platform: Threat detection using the new YARA-L rules language, and enhanced data modeling.

YARA is a language built for detecting and recognizing malware (YARA-L is a version that logs information) which Google said is “built specifically for modern threats and behaviours.” Its addition will allow Chronicle to better detect new forms of malware and novel forms of attack.

Google Describes YARA-L’s capabilities as being able to bring “massively scalable, real-time and retroactive rule execution” to Chronicle’s existing threat detection capabilities.

The second addition to Chronicle is what Google called “intelligent data fusion.” This new tool includes a new type of data model and the ability to link multiple security events into a single timeline for improved incident modeling.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s