Gemini dapat menjawab pertanyaan terkait kecerdasan ancaman tentang topik seperti pelaku ancaman, asosiasi, dan pola perilakunya, termasuk pertanyaan tentang TTP MITRE.
Pertanyaan terkait informasi ancaman terbatas pada informasi yang tersedia untuk
edisi produk Google SecOps Anda. Jawaban atas pertanyaan mungkin berbeda-beda, bergantung pada edisi produk. Secara khusus, data intelijen ancaman lebih terbatas di edisi produk selain Enterprise Plus karena tidak menyertakan akses penuh ke Mandiant dan VirusTotal.
Mengajukan pertanyaan kepada Gemini
Buka panel Gemini.
Masukkan pertanyaan terkait kecerdasan ancaman. Contoh: What is UNC3782?
Tinjau hasilnya.
Lakukan penyelidikan lebih lanjut dengan meminta Gemini membuat kueri untuk mencari
indikator kompromi (IOC) tertentu yang dirujuk dalam laporan intelijen ancaman. Informasi intelijen ancaman tunduk pada hak yang tersedia dari lisensi Google SecOps Anda.
Link disediakan untuk setiap set aturan yang mungkin tersedia untuk memantau jenis masalah keamanan yang Anda masukkan ke Gemini.
Di bagian bawah panel Gemini, klik Sumber dan konten terkait. Gemini memberikan link ke beberapa artikel yang menjadi sumber konten yang digunakan dalam ringkasan.
Contoh: Pertanyaan tentang kecerdasan ancaman dan keamanan
Help me hunt for APT 44
Are there any known attacker tools that use RDP to brute force logins?
Is 103.224.80.44 suspicious?
What types of attacks may be associated with CVE-2020-14145?
Can you provide details around buffer overflow and how it can affect the
target machine?
Gemini dan MITRE
Matriks MITRE ATT&CK® adalah pusat informasi yang mendokumentasikan TTP yang digunakan oleh penyerang cyber dunia nyata. Matriks MITRE
memberikan pemahaman tentang cara organisasi Anda dapat menjadi target dan
memberikan sintaksis standar untuk membahas serangan.
Anda dapat mengajukan pertanyaan kepada Gemini tentang taktik, teknik, dan prosedur (TTP) MITRE, serta menerima jawaban yang relevan secara kontekstual yang mencakup detail MITRE berikut:
Taktik
Teknik
Sub-teknik
Saran deteksi
Prosedur
Mitigasi
Gemini akan menampilkan link ke deteksi pilihan yang disediakan Google SecOps untuk setiap TTP. Anda juga dapat mengajukan pertanyaan lanjutan kepada Gemini untuk mendapatkan insight tambahan tentang TTP MITRE dan dampaknya terhadap perusahaan Anda.
Menghapus sesi chat
Anda dapat menghapus sesi percakapan chat atau menghapus semua sesi chat.
Gemini menjaga kerahasiaan semua histori percakapan pengguna dan mematuhi praktik AI yang bertanggung jawab dari Google Cloud. Histori pengguna tidak pernah digunakan untuk melatih model.
Di panel Gemini, pilih Hapus percakapan dari menu di kanan atas.
Klik Hapus percakapan di kanan bawah untuk menghapus sesi percakapan saat ini.
Opsional: Untuk menghapus semua sesi chat, pilih Hapus semua sesi chat
lalu klik Hapus semua percakapan.
Berikan masukan
Anda dapat memberikan masukan untuk respons yang dihasilkan oleh bantuan penyelidikan AI Gemini. Masukan Anda membantu Google meningkatkan kualitas fitur dan output yang dihasilkan oleh Gemini.
Di panel Gemini, klik thumb_upSuka atau thumb_downTidak Suka.
Opsional: Klik thumb_downTidak Suka dan berikan masukan.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[[["\u003cp\u003eGemini can assist with threat intelligence inquiries, offering details on threat actors, their connections, and attack methodologies, including MITRE TTPs.\u003c/p\u003e\n"],["\u003cp\u003eThe depth of threat intelligence available through Gemini is contingent on the user's Google SecOps product edition, with Enterprise Plus providing the most comprehensive data through Mandiant and VirusTotal access.\u003c/p\u003e\n"],["\u003cp\u003eUsers can interact with Gemini by asking specific questions, such as identifying threat actors or suspicious IP addresses, and subsequently review results or request queries for IOCs.\u003c/p\u003e\n"],["\u003cp\u003eGemini provides links to relevant rule sets, resources, and articles that contribute to the content, while also allowing for feedback on the quality of its responses.\u003c/p\u003e\n"],["\u003cp\u003eConversations within Gemini can be managed through deletion, and Google assures that user history is kept private and is not used to train the models.\u003c/p\u003e\n"]]],[],null,["# Answer Threat Intelligence questions with Gemini\n================================================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nGemini can answer questions related to threat intelligence about\ntopics such as threat actors, their associations, and their behavior patterns,\nincluding questions about [MITRE TTPs](#mitre).\n\nThreat intelligence questions are limited to information available to your\n[Google SecOps product edition](/security/products/security-operations#pricing). Answers to\nquestions might vary depending on the product edition. Specifically, threat\nintelligence data is more limited in product editions other than Enterprise Plus\nbecause they don't include full access to Mandiant and VirusTotal.\n\nAsk Gemini questions\n--------------------\n\n1. Open the Gemini pane.\n\n2. Enter a threat intelligence question. For example: `What is UNC3782?`\n\n3. Review the results.\n\n4. Investigate further by asking Gemini to create queries to look for\n specific indicators of compromise (IOCs) referenced in the threat intelligence reports. Threat\n intelligence information is subject to available entitlements from your\n Google SecOps license.\n\n5. Links are provided to any rule sets that might be available for monitoring the type of security issue you entered into Gemini.\n\n6. At the bottom of the Gemini pane, click **Sources and related content**. Gemini provides links to some of the articles that were the sources for the content used in the summary.\n\n| **Note:** If Gemini responds to a prompt with text written by someone else, the original source is cited in the *Referenced Sources* section of the Gemini pane. For more information, see [How and when Gemini\n| cites sources](/gemini/docs/discover/works#how-when-gemini-cites-sources).\n\n### Example: Threat intelligence and security questions\n\n- `Help me hunt for APT 44`\n- `Are there any known attacker tools that use RDP to brute force logins?`\n- `Is 103.224.80.44 suspicious?`\n- `What types of attacks may be associated with CVE-2020-14145?`\n- `Can you provide details around buffer overflow and how it can affect the\n target machine?`\n\n### Gemini and MITRE\n\nThe [MITRE ATT\\&CK® Matrix](https://attack.mitre.org/) is a knowledge base that\ndocuments the TTPs used by real-world cyber adversaries. The MITRE Matrix\nprovides an understanding of how your organization might be targeted and\nprovides a standardized syntax for discussing attacks.\n\nYou can ask Gemini questions about MITRE tactics, techniques, and\nprocedures (TTPs), and receive contextually relevant answers that include the\nfollowing MITRE details:\n\n- Tactic\n- Technique\n- Sub-technique\n- Detection suggestions\n- Procedures\n- Mitigations\n\nGemini returns a link to the curated detections\nGoogle SecOps makes available for each TTP. You can also ask\nGemini follow up questions to gain additional insight on a MITRE TTP\nand how it might impact your enterprise.\n\n### Delete a chat session\n\nYou can delete your chat conversation session or delete all chat sessions.\nGemini maintains all user conversation histories privately and adheres\nto Google Cloud's [responsible AI\npractices](/duet-ai/docs/discover/responsible-ai). User history is never used to train models.\n\n1. In the Gemini pane, select **Delete chat** from the menu at the top right.\n2. Click **Delete chat** at the bottom right to delete the current chat session.\n3. Optional: To delete all chat sessions, select **Delete all chat sessions** and then click **Delete all chats**.\n\n### Provide feedback\n\nYou can provide feedback to responses generated by the Gemini AI\ninvestigation assistance. Your feedback helps Google improve the feature and the\noutput generated by Gemini.\n\n1. In the Gemini pane, click thumb_up **Thumb Up** or thumb_down **Thumb Down**.\n2. Optional: Click thumb_down **Thumb Down** and provide feedback.\n3. Click **Send feedback**.\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]