You can view Composite Detections from Google Security Operations directly within the Mandiant Managed Defense Portal. These alerts are available in the Activity > Alerts table, where they appear with a "[Composite]" prefix in the Signature Name field.
There is a known issue where the "Source" appears as "Unidentified Source." Mandiant analysts will identify sources of activity in Investigation reports that include composite detections.