[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-02。"],[[["\u003cp\u003eGoogle SecOps Watchlists allow you to manually monitor entities and adjust their risk scores, regardless of automated scores, to prioritize investigations.\u003c/p\u003e\n"],["\u003cp\u003eWatchlists enable security analysts to incorporate human expertise by tracking high-value assets, sensitive data locations, or specific users, ensuring they receive appropriate attention.\u003c/p\u003e\n"],["\u003cp\u003eYou can create up to 200 watchlists, each with customizable names, descriptions, and a multiplying factor (0-100) to modify the risk score of the entities it contains.\u003c/p\u003e\n"],["\u003cp\u003eCommon use cases include monitoring employees who are leaving, tracking senior leaders for unusual activity, and managing internal red team activities by reducing their visibility.\u003c/p\u003e\n"],["\u003cp\u003eEntities can be added to a watchlist based on several different entity types such as IP address, email, employee ID, hostname, and more.\u003c/p\u003e\n"]]],[],null,["# Watchlist Quickstart guide\n==========================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\n\u003cbr /\u003e\n\nLearn how to use the **Watchlist** section. Watchlists in Google SecOps\nlets you manually curate entity lists to monitor, boost, or suppress their risk\nscores in the system. Security analysts can prioritize investigations and focus\non entities that might be particularly important, even if their automated risk\nscores are low.\n| **Note:** Because these risk considerations aren't reflected in the risk score calculation, entities on watchlists usually don't appear in the [Risk Analytics dashboard](/chronicle/docs/detection/risk-analytics-dashboard).\n\nBefore you begin\n----------------\n\nTo access the Watchlist tab, follow these steps:\n\n1. In the left navigation menu, click **Detection**.\n2. From **Detection** , click **Risk analytics**.\n3. Click the **Watchlists** tab.\n\nWatchlists\n----------\n\nWatchlists in Google Security Operations allow users to manually curate lists\nof entities to monitor, boosting or suppressing their risk scores in the system.\nThis enables security analysts to prioritize investigations and focus on entities\nthat may be of particular concern, even if their automated risk scores are low.\n\nEnhance risk scores with human insights\n---------------------------------------\n\nWhile Google SecOps' automated risk scoring provides valuable insights, watchlists\nincorporate human expertise and context into the risk assessment process.\nFor example, a security analyst might have knowledge of high-value assets,\nsensitive data locations, or specific users who warrant closer monitoring.\nBy adding these entities to a watchlist, analysts can ensure they receive\nappropriate attention, regardless of their computed risk scores.\n\nThe **Watchlists** page lets you monitor specific entities from across your\nenterprise according to preferences of your enterprise, regardless of the\nentity's risk score. For example:\n\n- Create a watchlist of employees about to leave the company to monitor any possible data exfiltration\n- Create a watchlist of the C-suite to monitor closely any subtle changes in their security posture.\n\nCreate a watchlist\n------------------\n\nTo create a watchlist to your Google SecOps account, complete the\nfollowing steps. You can configure up to 200 watchlists.\n\n1. Click **Create watchlist**.\n2. Specify a **Watchlist name**.\n3. (Optional) Specify a **Description**.\n4. (Optional) Specify **Multiplying factor** of between 0-100. The default is **1**.\n5. (Optional) Specify entities on the right side of the window following the\n [Add entities into a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#add-entities-into-a-watchlist)\n section. You can add the following entity types here:\n\n - `ASSET_IP_ADDRESS`\n - `EMAIL`\n - `EMPLOYEE_ID`\n - `HOSTNAME`\n - `MAC`\n - `PRODUCT_OBJECT_ID`\n - `PRODUCT_SPECIFIC_ID`\n - `USERNAME`\n - `WINDOWS_SID`\n6. Click **Create watchlist**.\n\nA watchlist lets you globally apply a risk score modifier to a set of entities.\nThis modifier, called **Multiplying factor**, refines the risk scores for all\nentities in the watchlist. Each entity's base risk score is multiplied by the\nsame factor. Enter a multiplying factor with a value from 0 -100. The default\nvalue is 1.\n\nIn addition to creating a watchlist, you can edit a watchlist, pin/unpin,\ndelete and add entities to/ remove entities from it.\nFor more on how to create watchlists, see [Add a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#add_a_watchlist).\n\nUse cases\n---------\n\nHere are a few use cases for the Watchlist section.\n\n### Use case 1:\n\nCreate a watchlist to track activities of employees about to leave your company.\nThese employees may attempt to copy internal specifications, plans, or\npresentations, particularly in highly competitive industries. For most employees,\nthis type of information would be of little value, since that type of behavior\nwould typically be considered to be normal.\n\n### Use case 2: Unusual activity among senior leaders\n\nCreate a watchlist to track unusual activity among senior leaders within your\norganization. Leadership is frequently targeted by spear phishing attacks.\nSudden increases in invoices or requests for funds transfers to outside accounts\ncan be monitored using a watchlist, in particular when known phishing attacks\nhave been identified within your enterprise.\n\n### Use case 3: internal red team\n\nCreate a watchlist for an internal red team that is active in your\nenterprise. The red team could trigger numerous alerts within your security\ninfrastructure (as expected). You can specify the watchlist with a multiplying\nfactor of 0 to reduce their visibility while they are in an active exercise.\nFor more information, see [Add a watchlist](/docs/detection/risk-analytics-dashboard#add_a_watchlist).\n\nWhat's next\n===========\n\n- [Add a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#add_a_watchlist)\n- [Edit a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#edit_a_watchlist)\n- [Pin a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#pin_a_watchlist)\n- [Unpin a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#unpin_a_watchlist)\n- [Delete a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#delete_a_watchlist)\n- [Add entities to a watchlist](/chronicle/docs/detection/risk-analytics-dashboard#add-entities-into-a-watchlist)\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]