The following tables list the supported security technologies, required Google Security Operations parsers, and supported alert types from each vendor that are processed as part of providing security event monitoring and threat hunting services.
Indicators of Compromise (IOCs) and signatures created by customers are not within the scope of Managed Defense service delivery. Managed Defense does not generally escalate rules where activity has been blocked. For instance, an email may be quarantined before you receive it or traffic may be dropped by an inline network security device. This escalation is only possible if the activity is related to other malicious activity.
Corelight
| Product | Description | Required SecOps Parsers | Managed Defense Supported Alert Types |
|---|---|---|---|
| Open NDR | Suricata alerts and Zeek logs are supported by Managed Defense. | Alerts and Telemetry: CORELIGHT |
|
CrowdStrike
| Product | License requirement | Description | Required SecOps Parsers | Managed Defense Supported Alert Types |
|---|---|---|---|---|
| CrowdStrike Endpoint Security | CrowdStrike Falcon Enterprise or higher | CrowdStrike Falcon Enterprise, Elite, and Complete are supported for Endpoint Protection Platform (EPP) alerts. | CS_ALERTS | Endpoint Protection (EPP) alerts |
| CrowdStrike Falcon Next-Gen Identity Security | CrowdStrike Falcon Next-Gen Identity Security | Managed Defense supports ingestion and monitoring of alerts from the CrowdStrike Falcon Identity Protection (IDP) module. | CS_ALERTS | Identity Protection (IDP) alerts |
| Falcon Endpoint Telemetry | Falcon Data Replicator license | CrowdStrike Falcon Enterprise, Elite, and Complete are supported by Managed Defense. Falcon Data Replicator is required for service. | CS_EDR |
N/A
|
Microsoft
| Product | License requirement | Description | Required SecOps Parsers | Managed Defense Supported Alert Types |
|---|---|---|---|---|
| Defender for Endpoint | One of the following:
|
Microsoft Defender for Endpoint Plan 2 or Defender for Business is required for service delivery. Managed Defense uses the Endpoint Detection and Response features of the platform. | Alerts: MICROSOFT_GRAPH_ALERT
Telemetry: MICROSOFT_DEFENDER_ENDPOINT |
|
| Defender for Identity | One of the following:
|
Microsoft Defender for Identity alerts is supported for customers who have provided Managed Defense access to Microsoft Security Graph. | Alerts: MICROSOFT_GRAPH_ALERT | The following signatures are monitored in real-time by the Managed Defense SOC. All other signatures are leveraged for hunting and do not adhere to Managed Defense Service Level Objectives.
|
Operational Technology applications
| Product | Description | Required SecOps Parser | Managed Defense Supported Alert Types |
|---|---|---|---|
| Claroty CTD | Alerts from Claroty CTD are supported by Managed Defense. | CLAROTY_CTD |
|
| Claroty xDome | Alerts from the Threat category are supported by Managed Defense. | CLAROTY_XDOME |
|
| Forescout eyeInspect | Alerts from Forescout eyeInspect are supported by Managed Defense | FORESCOUT_EYEINSPECT | N/A |
| Nozomi Guardian | INCIDENT and SIGN alerts are supported by Managed Defense. | NOZOMI_GUARDIAN |
|
Palo Alto Networks
| Product | License requirement | Description | Required SecOps Parsers | Managed Defense Supported Alert Types |
|---|---|---|---|---|
| Next Generation Firewall | N/A | Palo Alto Next Generation Firewalls (PAN NGFW) threats that are not blocked are supported by Managed Defense. Managed Defense can integrate with a WildFire Free or Advanced license for additional detection of malware. Data Filtering logs can optionally provide additional context for investigations. | Alerts: |
|
SentinelOne
| Product | License requirement | Description | Required SecOps Parsers | Managed Defense Supported Alert Types |
|---|---|---|---|---|
| Singularity | Cloud Funnel license | SentinelOne Singularity Complete is supported by Managed Defense. A Cloud Funnel license is required for Managed Defense service delivery. | Alerts:
SENTINELONE_ALERT
|
|
Trellix
| Product | Minimum Version | Maximum Version | Description | Required SecOps Parsers | Managed Defense Supported Alert Types |
|---|---|---|---|---|---|
|
Email Security (EX)* |
9.1 | 10.0 | Trellix Email Security Server Edition on-premises. | N/A |
|
| Email Security Cloud | N/A | N/A | Trellix Email Security Cloud Edition is software as a service application. | N/A |
|
|
Endpoint Security (HX)* |
5.3 | 10.0 | Trellix Endpoint Security can be deployed in on-premises, cloud, or virtual appliance configuration for Managed Defense service delivery. | N/A |
|
| Helix Security Platform | N/A | N/A | Trellix Helix Enterprise can be connected to Managed Defense service delivery by granting Managed Defense access to the instance through Trellix IAM. | N/A |
|
|
Network Security (NX)* |
9.1 | 10.0 | Trellix Network Security can be deployed in on-premises, cloud, or virtual appliance configuration in either inline or passive modes for Managed Defense service delivery. | N/A |
|
* Managed Defense follows the End of Life Policy for Trellix Supported Technology. In general, this End of Life Policy typically means that the most recent two software revisions for each product are supported.
** Alerts are leveraged for hunting and/or for additional context and do not adhere to Managed Defense Service Level Objectives noted in the Managed Defense Service Description.