Applied Threat Intelligence membantu Anda mengidentifikasi dan merespons ancaman. Fitur ini terus-menerus menganalisis dan mengevaluasi telemetri keamanan Anda terhadap indikator kompromi (IOC) yang dikurasi oleh kecerdasan ancaman Mandiant.
Jika Applied Threat Intelligence diaktifkan, Google Security Operations akan memproses IOC yang dikurasi oleh Mandiant Threat Intelligence dengan Skor IC lebih dari 80. Jika kecocokan ditemukan, pemberitahuan akan dibuat, dan Anda dapat menyelidiki kecocokan tersebut menggunakan halaman kecocokan IOC.
Halaman IOC Matches menampilkan kemungkinan kecocokan IOC untuk domain, alamat IP, hash file, dan URL. Halaman ini mencakup informasi tentang kecocokan, termasuk yang berikut ini:
Prioritas GCTI
Skor Keyakinan Indikator (IC-Score)
Asosiasi
Kampanye
Anda dapat melihat informasi mendetail tentang peristiwa yang memicu kecocokan, informasi dari sumber intelijen ancaman, dan alasan di balik Skor IC.
Deteksi pilihan Google SecOps mengevaluasi data peristiwa Anda terhadap data intelijen ancaman Mandiant, dan menghasilkan pemberitahuan saat satu atau beberapa aturan mengidentifikasi kecocokan dengan IOC yang berlabel Pelanggaran Aktif atau Tinggi.
Untuk menggunakan Applied Threat Intelligence, lakukan hal berikut:
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[[["\u003cp\u003eApplied Threat Intelligence helps identify and respond to threats by analyzing security telemetry against Mandiant threat intelligence IOCs.\u003c/p\u003e\n"],["\u003cp\u003eWhen enabled, it ingests IOCs with an IC-Score over 80, generating alerts upon finding a match.\u003c/p\u003e\n"],["\u003cp\u003eThe IOC Matches page displays matches for domains, IP addresses, and file hashes, providing details like GCTI Priority and IC-Score.\u003c/p\u003e\n"],["\u003cp\u003eGoogle Security Operations SIEM curated detections trigger alerts when event data matches an IOC with an Active Breach or High label.\u003c/p\u003e\n"],["\u003cp\u003eUsing Applied Threat Intelligence requires enabling curated detections and using the IOC matches page to investigate alerts.\u003c/p\u003e\n"]]],[],null,["# Applied Threat Intelligence overview\n====================================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nApplied Threat Intelligence (ATI) helps you identify and respond to threats. It continually\nanalyzes and evaluates your security telemetry against Indicators of Compromise\n(IoCs) curated by Mandiant threat intelligence.\n\nWhen ATI is enabled, Google Security Operations ingests IoCs curated\nby Mandiant threat intelligence that have an [Indicator Confidence Score](https://cloud.google.com/chronicle/docs/detection/understand-ic-score) (IC-Score) greater than 80. When a match is found, an alert is generated. You can then investigate the IoC on the **IoC matches** page, which displays possible IoC matches for domains, IP addresses,\nfile hashes, and URLs. Information about the IoC is displayed, including:\n\n- GCTI priority\n- IC-Score\n- Associations\n- Campaigns\n\nYou can also view detailed information about the events that triggered the IoC match, information from the threat intelligence source,\nand the rationale for the IC-Score. For more information, see [View IoCs using Applied Threat Intelligence](/chronicle/docs/detection/ati-view-ioc-page).\n| **Important:** Applied Threat Intelligence in Google SecOps is available with a Google SecOps Enterprise Plus license.\n\nGoogle SecOps curated detections evaluate your event data against\nMandiant threat intelligence data, and generates an alert when one or more rules\nidentify a match to an IoC with an *Active Breach* or *High* priority.\n\nTo use Applied Threat Intelligence, do the following:\n\n1. Enable the [Applied Threat Intelligence curated detections](/chronicle/docs/detection/ati-curated-detections).\n2. Investigate alerts using the [**IOC matches** page](/chronicle/docs/detection/ati-view-ioc-page).\n\nYou can also learn more about how the IC-Score is assigned in the [IC-Score overview](/chronicle/docs/detection/understand-ic-score).\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]