{"id":6255,"date":"2025-09-20T11:20:13","date_gmt":"2025-09-20T11:20:13","guid":{"rendered":"https:\/\/pokecon.jp\/job\/?p=6255"},"modified":"2025-09-20T11:20:13","modified_gmt":"2025-09-20T11:20:13","slug":"professional-security-operations-engineer-%e8%a9%a6%e9%a8%93-%e5%ae%8c%e5%85%a8%e6%94%bb%e7%95%a5%e3%82%ac%e3%82%a4%e3%83%89-2025","status":"publish","type":"post","link":"https:\/\/pokecon.jp\/job\/6255\/","title":{"rendered":"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025"},"content":{"rendered":"\n<\/p>\n<div>\n<p data-line=\"0\" class=\"code-line\">\u3053\u3093\u306b\u3061\u306f\u3001\u30af\u30e9\u30a6\u30c9\u30a8\u30fc\u30b9\u306e<a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/taisei-oda\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">\u5c0f\u7530<\/a>\u3067\u3059\u3002<\/p>\n<p data-line=\"2\" class=\"code-line\">2025 \u5e74 9 \u6708 16 \u65e5\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f Google Cloud \u306e\u6700\u65b0\u8a8d\u5b9a\u8cc7\u683c\u3067\u3042\u308b <strong>Professional Security Operations Engineer (PSOE)<\/strong> \u306e\u30d9\u30fc\u30bf\u7248\u8a66\u9a13\u3092\u5148\u6708\u53d7\u9a13\u3057\u3001\u7121\u4e8b\u53d6\u5f97\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u305f\u305f\u3081\u3001<strong>\u300cProfessional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c92025\u300d<\/strong> \u3068\u984c\u3057\u3066\u3001\u5408\u683c\u4f53\u9a13\u8a18\uff0b\u653b\u7565\u8a18\u4e8b\u3092\u6b8b\u3057\u307e\u3059\u3002<br \/>\u3053\u306e\u8cc7\u683c\u53d6\u5f97\u3092\u76ee\u6307\u3059\u65b9\u306b\u6709\u76ca\u306a\u60c5\u5831\u3068\u306a\u308c\u3070\u5e78\u3044\u3067\u3059\u3002<\/p>\n<p data-line=\"5\" class=\"code-line\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/zenn\/image\/fetch\/s--zsGLwxxp--\/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_1200\/https:\/\/images.credly.com\/images\/59ad6615-4b4c-4508-88f5-0c397597f437\/blob\" alt=\"certified-badge\" width=\"400\" class=\"md-img\" loading=\"lazy\"\/><\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__c05502ec2d385\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__c05502ec2d385\" data-content=\"https%3A%2F%2Fcloud.google.com%2Flearn%2Fcertification%2Fsecurity-operations-engineer%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h2 id=\"%E6%B3%A8%E6%84%8F%E4%BA%8B%E9%A0%85\" data-line=\"9\" class=\"code-line\">\n \u6ce8\u610f\u4e8b\u9805<\/h2>\n<aside class=\"msg alert\"><span class=\"msg-symbol\">!<\/span><\/p>\n<div class=\"msg-content\">\n<p data-line=\"11\" class=\"code-line\">\u3053\u306e\u8a18\u4e8b\u306f\u53c2\u8003\u60c5\u5831\u3067\u3042\u308a\u3001Google Cloud \u306e\u8a66\u9a13\u5185\u5bb9\u3092\u30ea\u30fc\u30af\u3059\u308b\u76ee\u7684\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u3002<br \/>\u307e\u305f\u3001\u3053\u306e\u8a18\u4e8b\u3067\u5b66\u7fd2\u3057\u305f\u304b\u3089\u3068\u3044\u3063\u3066\u78ba\u5b9f\u306a\u5408\u683c\u3092\u7d04\u675f\u3059\u308b\u3082\u306e\u3067\u3082\u3042\u308a\u307e\u305b\u3093\u3002<br \/>\u5f53\u7136\u3067\u3059\u304c\u3001\u8a66\u9a13\u5185\u5bb9\u304c\u65b0\u3057\u304f\u306a\u3063\u305f\u5834\u5408\u306b\u901a\u7528\u3057\u306a\u3044\u30b1\u30fc\u30b9\u3082\u3042\u308a\u307e\u3059\u3002<br \/>\u73fe\u5728\u82f1\u8a9e\u3067\u306e\u307f\u8a66\u9a13\u304c\u63d0\u4f9b\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u3001\u5358\u8a9e\u306f\u82f1\u8a9e\u306e\u307e\u307e\u8a18\u8f09\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\u4e88\u3081\u3054\u4e86\u627f\u304f\u3060\u3055\u3044\u3002<\/p>\n<\/div>\n<\/aside>\n<h2 id=\"%E8%A9%A6%E9%A8%93%E3%82%92%E7%9F%A5%E3%82%8B\" data-line=\"18\" class=\"code-line\">\n \u8a66\u9a13\u3092\u77e5\u308b<\/h2>\n<h3 id=\"%E5%87%BA%E9%A1%8C%E8%83%8C%E6%99%AF%E3%81%A8%E7%AF%84%E5%9B%B2\" data-line=\"19\" class=\"code-line\">\n \u51fa\u984c\u80cc\u666f\u3068\u7bc4\u56f2<\/h3>\n<p data-line=\"20\" class=\"code-line\">\u307e\u305a\u3001<a target=\"_blank\" href=\"https:\/\/services.google.com\/fh\/files\/misc\/professional_security_operations_engineer_exam_guide_english.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">\u8a8d\u5b9a\u8a66\u9a13\u30ac\u30a4\u30c9<\/a>\u3092\u78ba\u8a8d\u3059\u308b\u3068\u3001\u5927\u304d\u304f 6 \u3064\u306e\u30bb\u30af\u30b7\u30e7\u30f3\u306b\u5206\u985e\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3059\u3002<\/p>\n<ol data-line=\"22\" class=\"code-line\">\n<li data-line=\"22\" class=\"code-line\">\n<p data-line=\"22\" class=\"code-line\"><strong>Platform operations<\/strong> (~14%)<\/p>\n<ul data-line=\"23\" class=\"code-line\">\n<li data-line=\"23\" class=\"code-line\">\u691c\u51fa\u3068\u5bfe\u5fdc\u306e\u5f37\u5316<\/li>\n<li data-line=\"24\" class=\"code-line\">\u30a2\u30af\u30bb\u30b9\u306e\u69cb\u6210<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"26\" class=\"code-line\">\n<p data-line=\"26\" class=\"code-line\"><strong>Data management<\/strong> (~14%)<\/p>\n<ul data-line=\"27\" class=\"code-line\">\n<li data-line=\"27\" class=\"code-line\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30c4\u30fc\u30eb\u3078\u306e\u30ed\u30b0\u53d6\u308a\u8fbc\u307f<\/li>\n<li data-line=\"28\" class=\"code-line\">\u30e6\u30fc\u30b6\u30fc\u3001\u30a2\u30bb\u30c3\u30c8\u3001\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306e\u30d9\u30fc\u30b9\u30e9\u30a4\u30f3\u8b58\u5225<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"30\" class=\"code-line\">\n<p data-line=\"30\" class=\"code-line\"><strong>Threat hunting<\/strong> (~19%)<\/p>\n<ul data-line=\"31\" class=\"code-line\">\n<li data-line=\"31\" class=\"code-line\">\u74b0\u5883\u5168\u4f53\u3067\u306e\u8105\u5a01\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0\u306e\u5b9f\u884c<\/li>\n<li data-line=\"32\" class=\"code-line\">\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u306e\u6d3b\u7528<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"34\" class=\"code-line\">\n<p data-line=\"34\" class=\"code-line\"><strong>Detection engineering<\/strong> (~22%)<\/p>\n<ul data-line=\"35\" class=\"code-line\">\n<li data-line=\"35\" class=\"code-line\">\u30ea\u30b9\u30af\u691c\u51fa\u3068\u8105\u5a01\u7279\u5b9a\u306e\u30e1\u30ab\u30cb\u30ba\u30e0\u958b\u767a\u30fb\u5b9f\u88c5<\/li>\n<li data-line=\"36\" class=\"code-line\">\u691c\u77e5\u3078\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u306e\u6d3b\u7528<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"38\" class=\"code-line\">\n<p data-line=\"38\" class=\"code-line\"><strong>Incident response<\/strong> (~21%)<\/p>\n<ul data-line=\"39\" class=\"code-line\">\n<li data-line=\"39\" class=\"code-line\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306e\u5c01\u3058\u8fbc\u3081\u3068\u8abf\u67fb<\/li>\n<li data-line=\"40\" class=\"code-line\">\u30ec\u30b9\u30dd\u30f3\u30b9 Playbook \u306e\u69cb\u7bc9\u30fb\u5b9f\u88c5\u30fb\u4f7f\u7528<\/li>\n<li data-line=\"41\" class=\"code-line\">\u30b1\u30fc\u30b9\u7ba1\u7406\u30e9\u30a4\u30d5\u30b5\u30a4\u30af\u30eb\u306e\u5b9f\u88c5<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"43\" class=\"code-line\">\n<p data-line=\"43\" class=\"code-line\"><strong>Observability<\/strong> (~10%)<\/p>\n<ul data-line=\"44\" class=\"code-line\">\n<li data-line=\"44\" class=\"code-line\">\u6d1e\u5bdf\u3092\u63d0\u4f9b\u3059\u308b\u305f\u3081\u306e\u30c0\u30c3\u30b7\u30e5\u30dc\u30fc\u30c9\u3068\u30ec\u30dd\u30fc\u30c8\u306e\u958b\u767a\u30fb\u7dad\u6301<\/li>\n<li data-line=\"45\" class=\"code-line\">\u30d8\u30eb\u30b9 \u30e2\u30cb\u30bf\u30ea\u30f3\u30b0\u3068\u30a2\u30e9\u30fc\u30c8\u306e\u8a2d\u5b9a<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p data-line=\"47\" class=\"code-line\">\u8a66\u9a13\u30ac\u30a4\u30c9\u304b\u3089\u3001\u3053\u306e\u8a66\u9a13\u306f\u5358\u7d14\u306a\u77e5\u8b58\u554f\u984c\u3067\u306f\u306a\u304f\u3001\u5b9f\u969b\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u904b\u7528\u30b7\u30ca\u30ea\u30aa\u306b\u57fa\u3065\u3044\u305f\u5b9f\u8df5\u7684\u306a\u554f\u984c\u304c\u591a\u304f\u51fa\u984c\u3055\u308c\u308b\u3053\u3068\u304c\u63a8\u6e2c\u3055\u308c\u307e\u3059\u3002<br \/>\u305d\u306e\u305f\u3081\u3001Security Operations Center (\u4ee5\u964d\u3001SOC) \u3084 Network Operation Center (\u4ee5\u964d\u3001NOC) \u306e\u7d4c\u9a13\u3001Google Security Operations (\u4ee5\u964d\u3001SecOps) \u3068 Security Command Center (\u4ee5\u964d\u3001SCC) \u306e\u64cd\u4f5c\u7d4c\u9a13\u304c\u3042\u308b\u3053\u3068\u304c\u524d\u63d0\u306b\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__f665a1484c94a\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__f665a1484c94a\" data-content=\"https%3A%2F%2Fservices.google.com%2Ffh%2Ffiles%2Fmisc%2Fprofessional_security_operations_engineer_exam_guide_english.pdf\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h2 id=\"%E8%A9%A6%E9%A8%93%E3%81%AE%E5%AF%BE%E7%AD%96\" data-line=\"52\" class=\"code-line\">\n \u8a66\u9a13\u306e\u5bfe\u7b56<\/h2>\n<h3 id=\"%E5%85%88%E3%81%AB%E5%8F%96%E5%BE%97%E3%81%97%E3%81%A6%E3%81%8A%E3%81%8F%E3%81%93%E3%81%A8%E3%82%92%E3%81%8A%E3%81%99%E3%81%99%E3%82%81%E3%81%99%E3%82%8B%E8%B3%87%E6%A0%BC\" data-line=\"53\" class=\"code-line\">\n \u5148\u306b\u53d6\u5f97\u3057\u3066\u304a\u304f\u3053\u3068\u3092\u304a\u3059\u3059\u3081\u3059\u308b\u8cc7\u683c<\/h3>\n<ul data-line=\"54\" class=\"code-line\">\n<li data-line=\"54\" class=\"code-line\">\n<strong>Professional Cloud Security Engineer(PCSE)<\/strong>: Google Cloud \u306e\u4e00\u822c\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30d7\u30ed\u30c0\u30af\u30c8\u306b\u3064\u3044\u3066\u306e\u7406\u89e3<\/li>\n<li data-line=\"55\" class=\"code-line\">\n<strong>Associate Cloud Engineer(ACE)<\/strong>: Google Cloud \u306e\u57fa\u672c\u306e\u7406\u89e3<\/li>\n<\/ul>\n<h3 id=\"%E6%8E%A8%E5%A5%A8%E3%81%95%E3%82%8C%E3%82%8B%E6%BA%96%E5%82%99%E6%96%B9%E6%B3%95\" data-line=\"57\" class=\"code-line\">\n \u63a8\u5968\u3055\u308c\u308b\u6e96\u5099\u65b9\u6cd5<\/h3>\n<p data-line=\"58\" class=\"code-line\"><strong>\ud83d\udcda \u5fc5\u9808\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8<\/strong><br \/>\u4ee5\u4e0b\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u306f\u76ee\u3092\u901a\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n<p data-line=\"67\" class=\"code-line\"><strong>\ud83d\udee0\ufe0f \u30cf\u30f3\u30ba\u30aa\u30f3\u30fb\u30aa\u30f3\u30c7\u30de\u30f3\u30c9\u5b66\u7fd2<\/strong><\/p>\n<ul data-line=\"68\" class=\"code-line\">\n<li data-line=\"68\" class=\"code-line\">\n<strong>Google Cloud Skills Boost<\/strong>: \u52d5\u753b\u3084\u30cf\u30f3\u30ba\u30aa\u30f3\u30e9\u30dc\u3092\u901a\u3058\u3066\u5b66\u7fd2\u3067\u304d\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__6aadbab93a047\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__6aadbab93a047\" data-content=\"https%3A%2F%2Fwww.cloudskillsboost.google%2Fpaths%2F2150\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"71\" class=\"code-line\"><strong>\ud83d\udcdd \u7406\u89e3\u5ea6\u30c1\u30a7\u30c3\u30af<\/strong><\/p>\n<ul data-line=\"72\" class=\"code-line\">\n<li data-line=\"72\" class=\"code-line\">\n<strong>\u516c\u5f0f\u306e\u6a21\u64ec\u8a66\u9a13<\/strong>: \u516c\u5f0f\u306e\u6a21\u64ec\u8a66\u9a13\u3092\u53d7\u9a13\u3057\u307e\u3057\u3087\u3046\u3002<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__39b5894afbb98\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__39b5894afbb98\" data-content=\"https%3A%2F%2Fdocs.google.com%2Fforms%2Fd%2Fe%2F1FAIpQLScryxTOcaqWaPwxsQ-yjq29xRpYGpsAdy9L0XtIXtZy0s3miQ%2Fviewform\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"75\" class=\"code-line\"><strong>\ud83d\udcbc \u5b9f\u52d9\u7d4c\u9a13<\/strong><\/p>\n<ul data-line=\"76\" class=\"code-line\">\n<li data-line=\"76\" class=\"code-line\">SOC\/NOC \u3067\u306e\u904b\u7528\u7d4c\u9a13<\/li>\n<li data-line=\"77\" class=\"code-line\">SIEM \u88fd\u54c1\u306e\u64cd\u4f5c\u7d4c\u9a13<\/li>\n<li data-line=\"78\" class=\"code-line\">\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u7d4c\u9a13<\/li>\n<\/ul>\n<h3 id=\"%E5%89%8D%E6%8F%90%E7%9F%A5%E8%AD%98\" data-line=\"80\" class=\"code-line\">\n \u524d\u63d0\u77e5\u8b58<\/h3>\n<h4 id=\"%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E5%B0%82%E9%96%80%E7%94%A8%E8%AA%9E\" data-line=\"81\" class=\"code-line\">\n \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c02\u9580\u7528\u8a9e<\/h4>\n<p data-line=\"82\" class=\"code-line\">PSOE \u8a66\u9a13\u3067\u306f\u591a\u304f\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c02\u9580\u7528\u8a9e\u304c\u51fa\u984c\u3055\u308c\u307e\u3059\u3002\u5fc5\u9808\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306b\u66f8\u3044\u3066\u3042\u308b\u8cc7\u6599\u306a\u3069\u3092\u5229\u7528\u3057\u3001\u4ee5\u4e0b\u306e\u7528\u8a9e\u3092\u4e8b\u524d\u306b\u7406\u89e3\u3057\u3066\u304a\u304f\u3053\u3068\u304c\u91cd\u8981\u3067\u3059\u3002<br \/>IoC \u7b49\u3001\u3044\u304f\u3064\u304b\u306e\u5358\u8a9e\u306f\u3001\u3053\u306e\u8a18\u4e8b\u4e2d\u3067\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\u307e\u305f\u3001\u7528\u8a9e\u9593\u306e\u95a2\u4fc2\u6027\u3084\u5b9f\u969b\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u904b\u7528\u3067\u3069\u306e\u3088\u3046\u306b\u9023\u643a\u3059\u308b\u304b\u3082\u4f75\u305b\u3066\u7406\u89e3\u3057\u3066\u304a\u304f\u3068\u3001\u3088\u308a\u5b9f\u8df5\u7684\u306a\u554f\u984c\u306b\u5bfe\u5fdc\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p data-line=\"86\" class=\"code-line\"><strong>\u653b\u6483\u624b\u6cd5\u30fb\u8105\u5a01\u95a2\u9023<\/strong><\/p>\n<ul data-line=\"87\" class=\"code-line\">\n<li data-line=\"87\" class=\"code-line\">\n<strong>C2(Command and Control)<\/strong>: \u653b\u6483\u8005\u304c\u4fb5\u5bb3\u3055\u308c\u305f\u30c7\u30d0\u30a4\u30b9\u3068\u901a\u4fe1\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3059\u308b\u30b5\u30fc\u30d0\u30fc<\/li>\n<li data-line=\"88\" class=\"code-line\">\n<strong>APT(Advanced Persistent Threat)<\/strong>: \u9ad8\u5ea6\u306a\u6a19\u7684\u578b\u653b\u6483<\/li>\n<li data-line=\"89\" class=\"code-line\">\n<strong>Lateral Movement<\/strong>: \u30b7\u30b9\u30c6\u30e0\u4fb5\u5165\u5f8c\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u3092\u6a2a\u79fb\u52d5\u3057\u4fb5\u5bb3\u7bc4\u56f2\u3092\u62e1\u5927\u3057\u3066\u3044\u304f\u653b\u6483<\/li>\n<li data-line=\"90\" class=\"code-line\">\n<strong>Privilege Escalation<\/strong>: \u6a29\u9650\u6607\u683c\u653b\u6483<\/li>\n<li data-line=\"91\" class=\"code-line\">\n<strong>Credential Dumping<\/strong>: \u8cc7\u683c\u60c5\u5831\u306e\u7a83\u53d6<\/li>\n<li data-line=\"92\" class=\"code-line\">\n<strong>Backdoor<\/strong>: \u30b7\u30b9\u30c6\u30e0\u3078\u306e\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u53ef\u80fd\u306b\u3059\u308b\u4fb5\u5165\u53e3<\/li>\n<li data-line=\"93\" class=\"code-line\">\n<strong>Ransomware<\/strong>: \u30c7\u30fc\u30bf\u3092\u6697\u53f7\u5316\u3057\u3066\u8eab\u4ee3\u91d1\u3092\u8981\u6c42\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2<\/li>\n<li data-line=\"94\" class=\"code-line\">\n<strong>XSS(Cross-Site Scripting)<\/strong>: Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u633f\u5165\u3057\u3001\u4e0d\u6b63\u64cd\u4f5c\u3092\u5b9f\u884c\u3059\u308b\u653b\u6483<\/li>\n<\/ul>\n<p data-line=\"96\" class=\"code-line\"><strong>\u691c\u51fa\u30fb\u5bfe\u5fdc\u95a2\u9023<\/strong><\/p>\n<ul data-line=\"97\" class=\"code-line\">\n<li data-line=\"97\" class=\"code-line\">\n<strong>IoC(Indicators of Compromise)<\/strong>: \u4fb5\u5bb3\u306e\u75d5\u8de1\u30fb\u6307\u6a19(\u5f8c\u8ff0)<\/li>\n<li data-line=\"98\" class=\"code-line\">\n<strong>TTPs(Tactics, Techniques, and Procedures)<\/strong>: \u653b\u6483\u8005\u306e\u6226\u8853\u30fb\u6280\u8853\u30fb\u624b\u9806<\/li>\n<li data-line=\"99\" class=\"code-line\">\n<strong>False Positive<\/strong>: \u507d\u967d\u6027(\u6b63\u5e38\u306a\u6d3b\u52d5\u3092\u8105\u5a01\u3068\u3057\u3066\u8aa4\u8a8d)<\/li>\n<li data-line=\"100\" class=\"code-line\">\n<strong>Threat Hunting<\/strong>: \u80fd\u52d5\u7684\u306a\u8105\u5a01\u306e\u63a2\u7d22\u30fb\u8abf\u67fb<\/li>\n<li data-line=\"101\" class=\"code-line\">\n<strong>Forensic<\/strong>: \u30c7\u30b8\u30bf\u30eb\u8a3c\u62e0\u306e\u53ce\u96c6\u3001\u4fdd\u5b58\u3001\u5206\u6790\u3092\u542b\u3080\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5f8c\u306e\u5206\u6790<\/li>\n<li data-line=\"102\" class=\"code-line\">\n<strong>Dwell Time<\/strong>: \u653b\u6483\u8005\u306e\u4fb5\u5165\u304b\u3089\u691c\u51fa\u307e\u3067\u306e\u6642\u9593<\/li>\n<li data-line=\"103\" class=\"code-line\">\n<strong>Containment<\/strong>: \u8105\u5a01\u306e\u5c01\u3058\u8fbc\u3081\u3092\u6307\u3059\u7528\u8a9e<\/li>\n<li data-line=\"104\" class=\"code-line\">\n<strong>Enrichment<\/strong>: \u8ffd\u52a0\u60c5\u5831\u306b\u3088\u308b\u6587\u8108\u4ed8\u52a0<\/li>\n<li data-line=\"105\" class=\"code-line\">\n<strong>CSPM(Cloud Security Posture Management)<\/strong>: \u30af\u30e9\u30a6\u30c9\u74b0\u5883\u306e\u8a2d\u5b9a\u72b6\u6cc1\u3092\u7d99\u7d9a\u7684\u306b\u76e3\u8996\u3057\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u8a2d\u5b9a\u30df\u30b9\u3084\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u9055\u53cd\u3092\u691c\u51fa\u3059\u308b\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3<\/li>\n<li data-line=\"106\" class=\"code-line\">\n<strong>CWPP(Cloud Workload Protection Platform)<\/strong>: \u30af\u30e9\u30a6\u30c9\u4e0a\u3067\u5b9f\u884c\u3055\u308c\u308b\u30ef\u30fc\u30af\u30ed\u30fc\u30c9\uff08\u4eee\u60f3\u30de\u30b7\u30f3\u3001\u30b3\u30f3\u30c6\u30ca\u3001\u30b5\u30fc\u30d0\u30fc\u30ec\u30b9\u95a2\u6570\u306a\u3069\uff09\u3092\u4fdd\u8b77\u3057\u3001\u8105\u5a01\u3092\u691c\u51fa\u30fb\u9632\u5fa1\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0<\/li>\n<li data-line=\"107\" class=\"code-line\">\n<strong>CNAPP(Cloud Native Application Protection Platform)<\/strong>: \u30af\u30e9\u30a6\u30c9\u30cd\u30a4\u30c6\u30a3\u30d6 \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u305d\u306e\u57fa\u76e4\u3068\u306a\u308b\u30a4\u30f3\u30d5\u30e9\u30b9\u30c8\u30e9\u30af\u30c1\u30e3\u3092\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30e9\u30a4\u30d5\u30b5\u30a4\u30af\u30eb\u5168\u4f53\u306b\u308f\u305f\u3063\u3066\u7d71\u5408\u7684\u306b\u4fdd\u8b77\u3059\u308b\u7d71\u5408\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3002CSPM\u3001CWPP \u306f CNAPP \u306e\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8\u306e\u4e00\u90e8\u3068\u3057\u3066\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<\/ul>\n<p data-line=\"109\" class=\"code-line\"><strong>\u7d44\u7e54\u30fb\u904b\u7528\u95a2\u9023<\/strong><\/p>\n<ul data-line=\"110\" class=\"code-line\">\n<li data-line=\"110\" class=\"code-line\">\n<strong>SOC(Security Operations Center)<\/strong>: \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3 \u30bb\u30f3\u30bf\u30fc\u3002\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8105\u5a01\u3092\u8fc5\u901f\u306b\u691c\u51fa\u30fb\u7279\u5b9a\u3057\u3001\u88ab\u5bb3\u3092\u9632\u3050\u305f\u3081\u306b\u3001\u76e3\u8996\u30fb\u8abf\u67fb\u30fb\u5206\u6790\u306a\u3069\u3092\u884c\u3046\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u306b\u5bfe\u5fdc\u3059\u308b\u305f\u3081\u306e\u7d44\u7e54\u3002<\/li>\n<li data-line=\"111\" class=\"code-line\">\n<strong>NOC(Network Operation Center)<\/strong>: \u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30f3 \u30bb\u30f3\u30bf\u30fc\u3002\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u7d99\u7d9a\u7684\u306a\u76e3\u8996\u3092\u62c5\u3044\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u306e\u5065\u5168\u6027\u3001\u53ef\u7528\u6027\u306e\u7dad\u6301\u3092\u884c\u3046\u305f\u3081\u306e\u7d44\u7e54\u3002<\/li>\n<li data-line=\"112\" class=\"code-line\">\n<strong>SIEM(Security Information and Event Management)<\/strong>: \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u60c5\u5831\u30fb\u30a4\u30d9\u30f3\u30c8\u7ba1\u7406<\/li>\n<li data-line=\"113\" class=\"code-line\">\n<strong>SOAR(Security Orchestration, Automation and Response)<\/strong>: \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u696d\u52d9\u306e\u81ea\u52d5\u5316<\/li>\n<li data-line=\"114\" class=\"code-line\">\n<strong>EDR(Endpoint Detection and Response)<\/strong>: \u30e9\u30c3\u30d7\u30c8\u30c3\u30d7\u3001\u30b5\u30fc\u30d0\u30fc\u306a\u3069\u306e\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8 \u30c7\u30d0\u30a4\u30b9\u304b\u3089\u30ed\u30b0\u3092\u53ce\u96c6\u3057\u3001\u30c7\u30fc\u30bf\u5206\u6790\u624b\u6cd5\u3092\u4f7f\u7528\u3057\u3066\u7591\u308f\u3057\u3044\u30b7\u30b9\u30c6\u30e0\u52d5\u4f5c\u3092\u691c\u51fa\u3057\u3001\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u60c5\u5831\u3092\u63d0\u4f9b\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30c6\u30a3\u30d3\u30c6\u30a3\u3092\u30d6\u30ed\u30c3\u30af\u3057\u3001\u5f71\u97ff\u3092\u53d7\u3051\u308b\u30b7\u30b9\u30c6\u30e0\u3092\u5fa9\u5143\u3059\u308b\u305f\u3081\u306e\u5c01\u3058\u8fbc\u3081\u306a\u3069\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u63d0\u4f9b\u3059\u308b\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3<\/li>\n<li data-line=\"115\" class=\"code-line\">\n<strong>NDR(Network Detection and Response)<\/strong>: \u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u7d99\u7d9a\u7684\u76e3\u8996\u3068\u9ad8\u5ea6\u306a\u5206\u6790\u306b\u3088\u308a\u7570\u5e38\u6319\u52d5\u3092\u691c\u77e5\u3057\u3001\u5c01\u3058\u8fbc\u3081\u306a\u3069\u306e\u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u63d0\u4f9b\u3059\u308b\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3<\/li>\n<li data-line=\"116\" class=\"code-line\">\n<strong>UEBA(User and Entity Behavioral Analytics)<\/strong>: \u30e6\u30fc\u30b6\u30fc \u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u884c\u52d5\u5206\u6790<\/li>\n<li data-line=\"117\" class=\"code-line\">\n<strong>TIP(Threat Intelligence Platform)<\/strong>: \u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9 \u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0<\/li>\n<li data-line=\"118\" class=\"code-line\">\n<strong>MSSP(Managed Security Service Provider)<\/strong>: \u30de\u30cd\u30fc\u30b8\u30c9 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30b5\u30fc\u30d3\u30b9 \u30d7\u30ed\u30d0\u30a4\u30c0\u30fc<\/li>\n<\/ul>\n<p data-line=\"120\" class=\"code-line\"><strong>\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u30fb\u6a19\u6e96\u306a\u3069<\/strong><\/p>\n<ul data-line=\"121\" class=\"code-line\">\n<li data-line=\"121\" class=\"code-line\">\n<strong>MITRE ATT&amp;CK<\/strong>: MITRE Corporation \u3068\u3044\u3046\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5206\u91ce\u306a\u3069\u3067\u7c73\u56fd\u653f\u5e9c\u6a5f\u95a2\u7b49\u3092\u30b5\u30dd\u30fc\u30c8\u3059\u308b\u975e\u55b6\u5229\u7d44\u7e54\u304c\u958b\u767a\u3057\u305f\u653b\u6483\u624b\u6cd5\u306e\u5206\u985e\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3002\u5b9f\u969b\u306e\u653b\u6483\u3067\u89b3\u6e2c\u3055\u308c\u305f\u6226\u8853 (Tactics) \u3068\u6280\u8853 (Techniques) \u3092\u4f53\u7cfb\u7684\u306b\u6574\u7406\u3057\u3001\u8105\u5a01\u306e\u5206\u6790\u3084\u691c\u51fa\u30eb\u30fc\u30eb\u306e\u958b\u767a\u306b\u5e83\u304f\u6d3b\u7528\u3055\u308c\u308b<\/li>\n<li data-line=\"122\" class=\"code-line\">\n<strong>CVE(Common Vulnerabilities and Exposures)<\/strong>: \u8106\u5f31\u6027\u8b58\u5225\u5b50<\/li>\n<li data-line=\"123\" class=\"code-line\">\n<strong>PCI DSS(Payment Card Industry Data Security Standard)<\/strong>: \u30af\u30ec\u30b8\u30c3\u30c8 \u30ab\u30fc\u30c9\u696d\u754c\u306e\u56fd\u969b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u57fa\u6e96<\/li>\n<li data-line=\"124\" class=\"code-line\">\n<strong>SLA(Service Level Agreement)<\/strong>: \u30b5\u30fc\u30d3\u30b9\u6c34\u6e96\u5408\u610f<\/li>\n<\/ul>\n<h4 id=\"%E6%8A%80%E8%A1%93%E5%9F%BA%E7%9B%A4%E7%9F%A5%E8%AD%98\" data-line=\"126\" class=\"code-line\">\n \u6280\u8853\u57fa\u76e4\u77e5\u8b58<\/h4>\n<p data-line=\"127\" class=\"code-line\">\u305d\u306e\u4ed6\u3001\u4ee5\u4e0b\u306e\u77e5\u8b58\u30fb\u7d4c\u9a13\u304c\u3042\u308b\u3068\u5b66\u7fd2\u304c\u30b9\u30e0\u30fc\u30ba\u306b\u9032\u307f\u307e\u3059\u3002<\/p>\n<ul data-line=\"128\" class=\"code-line\">\n<li data-line=\"128\" class=\"code-line\">\n<strong>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u904b\u7528\u306e\u57fa\u790e\u77e5\u8b58<\/strong> (SOC\u3001SIEM\u3001\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc)<\/li>\n<li data-line=\"129\" class=\"code-line\">\n<strong>MITRE ATT&amp;CK framework<\/strong> \u306e\u7406\u89e3<\/li>\n<li data-line=\"130\" class=\"code-line\">\n<strong>YARA-L \u8a00\u8a9e<\/strong>\u306e\u57fa\u672c\u69cb\u6587<\/li>\n<li data-line=\"131\" class=\"code-line\">\n<strong>\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9<\/strong>\u306e\u57fa\u790e\u6982\u5ff5<\/li>\n<li data-line=\"132\" class=\"code-line\">\n<strong>MISP(Malware Information Sharing Platform)<\/strong>: \u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u304a\u3088\u3073\u5171\u6709\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0<\/li>\n<li data-line=\"133\" class=\"code-line\">\n<strong>Google Cloud<\/strong> \u306e\u57fa\u672c\u7684\u306a\u30b5\u30fc\u30d3\u30b9\u7406\u89e3<\/li>\n<\/ul>\n<h2 id=\"%E3%83%97%E3%83%AD%E3%83%80%E3%82%AF%E3%83%88%E6%A6%82%E8%A6%81\" data-line=\"135\" class=\"code-line\">\n \u30d7\u30ed\u30c0\u30af\u30c8\u6982\u8981<\/h2>\n<p data-line=\"136\" class=\"code-line\">\u8a66\u9a13\u8981\u9805\u3068\u3057\u3066\u516c\u8868\u3055\u308c\u3066\u3044\u308b\u30d7\u30ed\u30c0\u30af\u30c8\u306b\u3064\u3044\u3066\u3001\u8981\u70b9\u306e\u307f\u89e3\u8aac\u3057\u307e\u3059\u3002<br \/>\u3059\u3079\u3066\u554f\u308f\u308c\u308b\u3068\u3044\u3046\u308f\u3051\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u304c\u3001\u516c\u8868\u3055\u308c\u3066\u3044\u308b\u30d7\u30ed\u30c0\u30af\u30c8\u3067\u3059\u306e\u3067\u6982\u8981\u306f\u628a\u63e1\u3057\u3066\u304a\u304f\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<br \/>\u53ef\u80fd\u306a\u9650\u308a\u3001\u300cSecOps\u300d\u3068\u300cSCC\u300d\u306e\u7406\u89e3\u3092\u6df1\u3081\u3001Google Cloud \u3067\u3069\u306e\u3088\u3046\u306b\u8981\u4ef6\u306b\u5bfe\u5fdc\u3057\u3066\u3044\u304f\u304b\u3092\u7406\u89e3\u3057\u3066\u304a\u304f\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<\/p>\n<hr data-line=\"140\" class=\"code-line\"\/>\n<h3 id=\"google-security-operations(secops)\" data-line=\"142\" class=\"code-line\">\n Google Security Operations(SecOps)<\/h3>\n<p data-line=\"143\" class=\"code-line\">Google SecOps \u306f\u3001SIEM\u3001SOAR\u3001\u304a\u3088\u3073\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u5305\u62ec\u7684\u306b\u7d71\u5408\u3057\u305f\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002<\/p>\n<h4 id=\"%E4%B8%BB%E8%A6%81%E3%82%B3%E3%83%B3%E3%83%9D%E3%83%BC%E3%83%8D%E3%83%B3%E3%83%88\" data-line=\"145\" class=\"code-line\">\n \u4e3b\u8981\u30b3\u30f3\u30dd\u30fc\u30cd\u30f3\u30c8<\/h4>\n<ul data-line=\"146\" class=\"code-line\">\n<li data-line=\"146\" class=\"code-line\"><strong>SIEM(Security Information and Event Management)<\/strong><\/li>\n<li data-line=\"147\" class=\"code-line\"><strong>SOAR(Security Orchestration, Automation and Response)<\/strong><\/li>\n<\/ul>\n<p data-line=\"149\" class=\"code-line\">\u30ed\u30b0\u306e\u53ce\u96c6\u304b\u3089\u30a2\u30e9\u30fc\u30c8\u3068\u3057\u3066\u306e\u691c\u77e5\u307e\u3067\u304c SIEM \u306e\u7bc4\u56f2\u3067\u3001SOAR \u306f\u691c\u77e5\u5f8c\u306e\u30a2\u30e9\u30fc\u30c8\u3084\u8105\u5a01\u306e\u7ba1\u7406\u3001\u5206\u6790\u3001\u5bfe\u5fdc\u307e\u3067\u884c\u3044\u307e\u3059\u3002<br \/><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/zenn\/image\/fetch\/s--kHaCACQ0--\/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_1200\/https:\/\/storage.googleapis.com\/zenn-user-upload\/deployed-images\/548c3fa6c7ebfd12d1caff5f.png%3Fsha%3D716019536fd33355ee1029f8f0eca74ccd2d62ba\" alt=\"secops\" class=\"md-img\" loading=\"lazy\"\/><br \/><em>\u30a4\u30e1\u30fc\u30b8\u56f3: \u72ec\u81ea\u306b\u4f5c\u6210\u3057\u305f\u3082\u306e\u3067\u3001\u516c\u5f0f\u306e\u3082\u306e\u3067\u306f\u3042\u308a\u307e\u305b\u3093<\/em><\/p>\n<hr data-line=\"153\" class=\"code-line\"\/>\n<h4 id=\"%E3%83%86%E3%82%A3%E3%82%A2%E6%A7%8B%E6%88%90\" data-line=\"155\" class=\"code-line\">\n \u30c6\u30a3\u30a2\u69cb\u6210<\/h4>\n<p data-line=\"156\" class=\"code-line\">Google SecOps \u306b\u306f\u5229\u7528\u898f\u6a21\u3084\u30cb\u30fc\u30ba\u306b\u5fdc\u3058\u3066 3 \u3064\u306e\u30c6\u30a3\u30a2\u304c\u7528\u610f\u3055\u308c\u3066\u304a\u308a\u3001\u305d\u308c\u305e\u308c\u6a5f\u80fd\u3084\u30b5\u30dd\u30fc\u30c8\u7bc4\u56f2\u304c\u7570\u306a\u308a\u307e\u3059\u3002<\/p>\n<div class=\"s_table\"><table data-line=\"157\" class=\"code-line\">\n<thead data-line=\"157\" class=\"code-line\">\n<tr data-line=\"157\" class=\"code-line\">\n<th>\u6a5f\u80fd<\/th>\n<th>Standard<\/th>\n<th>Enterprise<\/th>\n<th>Enterprise Plus<\/th>\n<\/tr>\n<\/thead>\n<tbody data-line=\"159\" class=\"code-line\">\n<tr data-line=\"159\" class=\"code-line\">\n<td>SecOps SIEM<\/td>\n<td>\u2705<\/td>\n<td>\u2705<\/td>\n<td>\u2705<\/td>\n<\/tr>\n<tr data-line=\"160\" class=\"code-line\">\n<td>SecOps SOAR<\/td>\n<td>&#8211;<\/td>\n<td>\u2705 + multi-environment(MSSP)<\/td>\n<td>\u2705 + multi-environment(MSSP)<\/td>\n<\/tr>\n<tr data-line=\"161\" class=\"code-line\">\n<td>UEBA DIY<\/td>\n<td>\u2705<\/td>\n<td>\u2705<\/td>\n<td>\u2705<\/td>\n<\/tr>\n<tr data-line=\"162\" class=\"code-line\">\n<td>Rules(YARA-L)<\/td>\n<td>\u6700\u5927 1,000 \u306e\u5358\u4e00\u30a4\u30d9\u30f3\u30c8\u30eb\u30fc\u30eb\u3068 75 \u306e\u30de\u30eb\u30c1\u30a4\u30d9\u30f3\u30c8 \u30eb\u30fc\u30eb<\/td>\n<td>\u6700\u5927 2,000 \u306e\u5358\u4e00\u30a4\u30d9\u30f3\u30c8\u30eb\u30fc\u30eb\u304a\u3088\u3073\u6700\u5927 125 \u306e\u30de\u30eb\u30c1\u30a4\u30d9\u30f3\u30c8 \u30eb\u30fc\u30eb<\/td>\n<td>\u6700\u5927 3,500 \u306e\u5358\u4e00\u30a4\u30d9\u30f3\u30c8\u30eb\u30fc\u30eb\u304a\u3088\u3073\u6700\u5927 200 \u306e\u30de\u30eb\u30c1\u30a4\u30d9\u30f3\u30c8 \u30eb\u30fc\u30eb<\/td>\n<\/tr>\n<tr data-line=\"163\" class=\"code-line\">\n<td>Applied Threat Intelligence<\/td>\n<td>\u304a\u5ba2\u69d8\u72ec\u81ea\u306e IoC<\/td>\n<td>Google OSINT \u306e\u307f<\/td>\n<td>Mandiant \u306b\u3088\u308b\u6df1\u3044\u77e5\u898b\u3001Google Threat Intelligence \u306e\u5b8c\u5168\u30a2\u30af\u30bb\u30b9\u6a29<\/td>\n<\/tr>\n<tr data-line=\"164\" class=\"code-line\">\n<td>GCTI Curated Detections<\/td>\n<td>&#8211;<\/td>\n<td>\u2705<\/td>\n<td>\u2705 + Active IR \u306a\u3069<\/td>\n<\/tr>\n<tr data-line=\"165\" class=\"code-line\">\n<td>Gemini<\/td>\n<td>&#8211;<\/td>\n<td>\u2705<\/td>\n<td>\u2705<\/td>\n<\/tr>\n<tr data-line=\"166\" class=\"code-line\">\n<td>BQ UDM Storage<\/td>\n<td>&#8211;<\/td>\n<td>&#8211;<\/td>\n<td>\u2705<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__b592a9cd15677\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__b592a9cd15677\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fsecurity%2Fproducts%2Fsecurity-operations%3Fhl%3Dja%23pricing\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"170\" class=\"code-line\"\/>\n<h4 id=\"siem%2Fsoar-%E5%8F%96%E3%82%8A%E8%BE%BC%E3%81%BF%E6%96%B9%E6%B3%95%E3%81%AE%E9%81%95%E3%81%84\" data-line=\"172\" class=\"code-line\">\n SIEM\/SOAR \u53d6\u308a\u8fbc\u307f\u65b9\u6cd5\u306e\u9055\u3044<\/h4>\n<p data-line=\"173\" class=\"code-line\">SIEM \u3068 SOAR \u306b\u304a\u3051\u308b\u30c7\u30fc\u30bf\u53d6\u308a\u8fbc\u307f\u65b9\u6cd5\u306e\u9055\u3044\u3092\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<div class=\"s_table\"><table data-line=\"174\" class=\"code-line\">\n<thead data-line=\"174\" class=\"code-line\">\n<tr data-line=\"174\" class=\"code-line\">\n<th>\u9805\u76ee<\/th>\n<th>SIEM \u306e\u30ed\u30b0\u53d6\u308a\u8fbc\u307f<\/th>\n<th>SOAR \u306e\u30a2\u30e9\u30fc\u30c8\u53d6\u308a\u8fbc\u307f<\/th>\n<\/tr>\n<\/thead>\n<tbody data-line=\"176\" class=\"code-line\">\n<tr data-line=\"176\" class=\"code-line\">\n<td>\u5bfe\u8c61\u30c7\u30fc\u30bf<\/td>\n<td>\u69d8\u3005\u306a\u30bd\u30fc\u30b9\u304b\u3089\u306e\u300c\u751f\u30ed\u30b0\u30c7\u30fc\u30bf\u300d<\/td>\n<td>\u5916\u90e8 SIEM \u3084 CSPM \u306a\u3069\u304c\u751f\u6210\u3057\u305f\u300c\u30a2\u30e9\u30fc\u30c8(\u76f8\u95a2\u6027\u306e\u3042\u308b\u30a4\u30d9\u30f3\u30c8)\u300d<\/td>\n<\/tr>\n<tr data-line=\"177\" class=\"code-line\">\n<td>\u76ee\u7684<\/td>\n<td>\u30ed\u30b0\u306e\u53ce\u96c6\u30fb\u6b63\u898f\u5316\u3001\u30a2\u30e9\u30fc\u30c8(\u76f8\u95a2\u6027\u306e\u3042\u308b\u30a4\u30d9\u30f3\u30c8)\u3001\u8105\u5a01\u306e<strong>\u691c\u77e5\u3001\u5206\u6790\u3001\u30cf\u30f3\u30c6\u30a3\u30f3\u30b0<\/strong>\n<\/td>\n<td>\u30a2\u30e9\u30fc\u30c8\u306e\u96c6\u7d04\u30fb\u7ba1\u7406\u3001<strong>\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u306e\u81ea\u52d5\u5316<\/strong>\u3001MTTR (\u5e73\u5747\u5fa9\u65e7\u6642\u9593)\u524a\u6e1b<\/td>\n<\/tr>\n<tr data-line=\"178\" class=\"code-line\">\n<td>\u53d6\u308a\u8fbc\u307f\u5f8c\u306e\u51e6\u7406<\/td>\n<td>UDM \u3078\u306e\u6b63\u898f\u5316\u3001\u691c\u7d22\u3001\u691c\u51fa\u30eb\u30fc\u30eb\u306e\u5165\u529b<\/td>\n<td>\u30b1\u30fc\u30b9\u3078\u306e\u96c6\u7d04\u3001\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30de\u30c3\u30d4\u30f3\u30b0\u3001Playbook \u306b\u3088\u308b\u81ea\u52d5\u5bfe\u5fdc<\/td>\n<\/tr>\n<tr data-line=\"179\" class=\"code-line\">\n<td>\u4e3b\u306a\u65b9\u6cd5<\/td>\n<td>\u76f4\u63a5\u53d6\u308a\u8fbc\u307f\u3001Bindplane\u3001Feed Management\u3001Ingestion API<\/td>\n<td>\u30b3\u30cd\u30af\u30bf (\u30d7\u30eb\u578b)\u3001Webhook (\u30d7\u30c3\u30b7\u30e5\u578b)<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<hr data-line=\"181\" class=\"code-line\"\/>\n<h4 id=\"ioc-matches\" data-line=\"183\" class=\"code-line\">\n IoC matches<\/h4>\n<p data-line=\"184\" class=\"code-line\">Google SecOps \u3067\u306f\u3001IoC matches \u3068\u3044\u3046\u6a5f\u80fd\u306b\u3088\u308a\u53d6\u308a\u8fbc\u3093\u3060\u30ed\u30b0\u30a4\u30d9\u30f3\u30c8\u3092 Google \u304c\u4fdd\u6709\u3057\u3066\u3044\u308b IoC \u306e\u30bd\u30fc\u30b9\u3068\u81ea\u52d5\u3067\u95a2\u9023\u4ed8\u3051\u3092\u884c\u3044\u307e\u3059\u3002<\/p>\n<p data-line=\"186\" class=\"code-line\"><strong>IoC(Indicators of Compromise)<\/strong> \u3068\u306f\u3001\u4fb5\u5bb3\u306e\u75d5\u8de1\u3092\u793a\u3059\u30d1\u30bf\u30fc\u30f3\u306e\u3053\u3068\u3067\u3059\u3002\u4f8b\u3048\u3070\u3001\u65e2\u77e5\u306e\u60aa\u610f\u306e\u3042\u308b\u30c9\u30e1\u30a4\u30f3\u3001IP \u30a2\u30c9\u30ec\u30b9\u3001\u30d5\u30a1\u30a4\u30eb \u30cf\u30c3\u30b7\u30e5\u3001URL \u304c IoC \u306b\u3042\u305f\u308a\u307e\u3059\u3002<br \/>\u7591\u308f\u3057\u3044\u30a4\u30d9\u30f3\u30c8\u304c\u3042\u3063\u305f\u5834\u5408\u3001\u305d\u308c\u3089\u304c IoC matches \u306e\u753b\u9762\u3067\u4e00\u89a7\u3067\u8868\u793a\u3055\u308c\u308b\u305f\u3081\u3001\u7c21\u5358\u306b\u305d\u306e\u30a4\u30d9\u30f3\u30c8\u306e\u8a73\u7d30\u3092\u8ffd\u8de1\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__d793b2b769a81\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__d793b2b769a81\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Finvestigation%2Falerts-iocs%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h4 id=\"curated-detections\" data-line=\"191\" class=\"code-line\">\n Curated Detections<\/h4>\n<p data-line=\"192\" class=\"code-line\">Google Cloud Threat Intelligence (GCTI) \u30c1\u30fc\u30e0\u306b\u3088\u308a\u4e8b\u524d\u5b9a\u7fa9\u3055\u308c\u305f\u8105\u5a01\u691c\u51fa\u30eb\u30fc\u30eb\u3092\u63d0\u4f9b\u3059\u308b\u6a5f\u80fd\u3067\u3059\u3002<br \/>\u5404\u30eb\u30fc\u30eb\u306e\u8a2d\u5b9a\u3092\u6709\u52b9\u306b\u3059\u308b\u3068\u3001\u305d\u306e\u30eb\u30fc\u30eb\u3067\u5b9a\u7fa9\u3055\u308c\u305f\u4e0d\u5be9\u306a\u632f\u308b\u821e\u3044\u306e\u30d1\u30bf\u30fc\u30f3\u304c\u78ba\u8a8d\u3055\u308c\u305f\u969b\u306b\u3001\u691c\u77e5\u3057\u8868\u793a\u3055\u308c\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__5623a86845044\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__5623a86845044\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fdetection%2Fcurated-detections%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"197\" class=\"code-line\">\u95a2\u9023\u8a18\u4e8b\u306f\u3053\u3061\u3089\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__4bd53d94cacf\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__4bd53d94cacf\" data-content=\"https%3A%2F%2Fzenn.dev%2Fcloud_ace%2Farticles%2Fgoogle-secops-siem-detections\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"200\" class=\"code-line\"\/>\n<h4 id=\"udm-(unified-data-model)%E3%80%90%E9%87%8D%E8%A6%81%EF%BC%81%E3%80%91\" data-line=\"202\" class=\"code-line\">\n UDM (Unified Data Model)\u3010\u91cd\u8981\uff01\u3011<\/h4>\n<p data-line=\"203\" class=\"code-line\">SecOps \u304c\u4f7f\u7528\u3059\u308b\u7d71\u4e00\u30c7\u30fc\u30bf\u30e2\u30c7\u30eb\u3067\u3042\u308a\u3001\u7570\u306a\u308b\u30ed\u30b0\u30bd\u30fc\u30b9\u3092\u5171\u901a\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u306b\u6b63\u898f\u5316\u3059\u308b\u5f79\u5272\u3092\u62c5\u3044\u307e\u3059\u3002<br \/>YARA-L \u691c\u51fa\u30eb\u30fc\u30eb\u3084 UDM Search \u3067\u5229\u7528\u3055\u308c\u308b\u91cd\u8981\u306a\u6982\u5ff5\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__38459c4b660eb\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__38459c4b660eb\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fevent-processing%2Fudm-overview%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__e9e20d34e52a5\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__e9e20d34e52a5\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Freference%2Fudm-field-list\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"209\" class=\"code-line\">YARA-L \u691c\u51fa\u30eb\u30fc\u30eb\u3084 UDM Search \u3067\u4f7f\u7528\u3059\u308b\u30af\u30a8\u30ea\u306f\u3059\u3079\u3066\u624b\u52d5\u3067\u8a18\u8ff0\u3059\u308b\u3053\u3068\u3082\u53ef\u80fd\u3067\u3059\u304c\u3001Gemini \u3092\u4f7f\u7528\u3057\u3066\u81ea\u7136\u8a00\u8a9e\u304b\u3089\u30eb\u30fc\u30eb\u3092\u751f\u6210\u3059\u308b\u3053\u3068\u3082\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__30a54fc2056ca\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__30a54fc2056ca\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fdetection%2Fgenerate-yara-l-with-gemini%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"213\" class=\"code-line\">\u4e00\u90e8\u629c\u7c8b\u3057\u3066\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<br \/><strong>\u57fa\u672c\u69cb\u9020<\/strong>:<\/p>\n<ul data-line=\"215\" class=\"code-line\">\n<li data-line=\"215\" class=\"code-line\">\n<code>principal<\/code>: \u52d5\u4f5c\u4e3b\u4f53(\u30e6\u30fc\u30b6\u3001\u30d7\u30ed\u30bb\u30b9\u7b49)<\/li>\n<li data-line=\"216\" class=\"code-line\">\n<code>target<\/code>: \u5bfe\u8c61(\u30d5\u30a1\u30a4\u30eb\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u7b49)<\/li>\n<li data-line=\"217\" class=\"code-line\">\n<code>network<\/code>: \u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u95a2\u9023\u60c5\u5831<\/li>\n<li data-line=\"218\" class=\"code-line\">\n<code>metadata<\/code>: \u30a4\u30d9\u30f3\u30c8 \u30e1\u30bf\u30c7\u30fc\u30bf<\/li>\n<\/ul>\n<p data-line=\"220\" class=\"code-line\"><strong>\u91cd\u8981\u30d5\u30a3\u30fc\u30eb\u30c9\u8a73\u7d30<\/strong>:<\/p>\n<hr data-line=\"245\" class=\"code-line\"\/>\n<h4 id=\"%E3%82%A8%E3%83%B3%E3%83%86%E3%82%A3%E3%83%86%E3%82%A3-%E3%82%B3%E3%83%B3%E3%83%86%E3%82%AD%E3%82%B9%E3%83%88\" data-line=\"247\" class=\"code-line\">\n \u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30b3\u30f3\u30c6\u30ad\u30b9\u30c8<\/h4>\n<p data-line=\"248\" class=\"code-line\">Google SecOps \u5185\u3067\u95a2\u9023\u30c7\u30fc\u30bf\u306e\u7d50\u5408\u3084\u30a8\u30f3\u30ea\u30c3\u30c1\u306b\u4f7f\u7528\u3055\u308c\u308b\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8 \u30c7\u30fc\u30bf\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__9e84328f8639a\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__9e84328f8639a\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fevent-processing%2Fdata-enrichment%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"253\" class=\"code-line\"><strong>\u30bd\u30fc\u30b9\u30bf\u30a4\u30d7<\/strong><\/p>\n<ul data-line=\"254\" class=\"code-line\">\n<li data-line=\"254\" class=\"code-line\">\n<strong>Entity Context<\/strong>: \u30e6\u30fc\u30b6\u30fc\u304c SIEM \u306b\u767b\u9332\u3057\u305f\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3002\u4f8b: Entra ID Audit \u3084 Okta\u3001Google Workspace \u306a\u3069\u304b\u3089\u53d6\u5f97\u3055\u308c\u308b\u30a2\u30bb\u30c3\u30c8\u3084\u30e6\u30fc\u30b6\u30fc \u30b0\u30eb\u30fc\u30d7\u3002<\/li>\n<li data-line=\"255\" class=\"code-line\">\n<strong>Derived Context<\/strong>: \u30e6\u30fc\u30b6\u30fc\u306e\u30c7\u30fc\u30bf\u304b\u3089\u81ea\u52d5\u8a08\u7b97\u3055\u308c\u305f\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3002\u4f8b: \u521d\u89b3\u6e2c\u65e5\u6642\u3001\u6700\u7d42\u89b3\u6e2c\u65e5\u6642\u3001\u51fa\u73fe\u983b\u5ea6\u306a\u3069\u3002<\/li>\n<li data-line=\"256\" class=\"code-line\">\n<strong>Global Context<\/strong>: Google Threat Intelligence\u3001Google \u30bb\u30fc\u30d5 \u30d6\u30e9\u30a6\u30b8\u30f3\u30b0\u306a\u3069\u304b\u3089\u63d0\u4f9b\u3055\u308c\u305f\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3002\u4f8b: Whois\u3001\u30bb\u30fc\u30d5 \u30d6\u30e9\u30a6\u30b8\u30f3\u30b0\u3001Tor \u306e\u51fa\u53e3\u30ce\u30fc\u30c9\u60c5\u5831\u30c7\u30fc\u30bf\u3002<\/li>\n<li data-line=\"257\" class=\"code-line\">\n<strong>Unspecified Context<\/strong>: \u4e00\u822c\u7684\u3067\u306f\u306a\u3044\u3001\u307e\u305f\u306f\u4e88\u60f3\u3055\u308c\u306a\u3044\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8 \u30c7\u30fc\u30bf\u3002<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__ac03580444e4f\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__ac03580444e4f\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Freference%2Fudm-field-list%23entitymetadatasourcetype\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h4 id=\"%E3%82%A8%E3%83%B3%E3%83%86%E3%82%A3%E3%83%86%E3%82%A3-%E3%82%BF%E3%82%A4%E3%83%97\" data-line=\"261\" class=\"code-line\">\n \u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30bf\u30a4\u30d7<\/h4>\n<p data-line=\"262\" class=\"code-line\"><strong>\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30bf\u30a4\u30d7<\/strong>\u3068\u306f\u3001Google SecOps \u304c\u6271\u3046\u69d8\u3005\u306a\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u3092\u6b63\u898f\u5316\u3057\u3001\u5171\u901a\u306e\u5f62\u5f0f\u3067\u5206\u985e\u3059\u308b\u305f\u3081\u306e\u3082\u306e\u3067\u3059\u3002<br \/>\u69d8\u3005\u306a\u30bd\u30fc\u30b9\u304b\u3089\u53ce\u96c6\u3055\u308c\u305f\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30c7\u30fc\u30bf\u306f\u3001\u3053\u306e\u5171\u901a\u306e\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30bf\u30a4\u30d7\u306b\u30de\u30c3\u30d4\u30f3\u30b0\u3055\u308c\u3001\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u9593\u306e\u95a2\u4fc2\u6027\u306b\u57fa\u3065\u3044\u305f\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30b0\u30e9\u30d5\u3068\u3044\u3046\u96a3\u63a5\u30ea\u30b9\u30c8\u306b\u4fdd\u6301\u3055\u308c\u307e\u3059\u3002<\/p>\n<p data-line=\"265\" class=\"code-line\"><strong>\u4e3b\u8981\u306a\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3 \u30bf\u30a4\u30d7<\/strong><\/p>\n<ul data-line=\"266\" class=\"code-line\">\n<li data-line=\"266\" class=\"code-line\">\n<strong>ASSET<\/strong>: \u7d44\u7e54\u304c\u6240\u6709\u3059\u308b\u30ea\u30bd\u30fc\u30b9(\u4f8b\uff1a\u7aef\u672b\u3001\u30b5\u30fc\u30d0\u30fc)\u3002\u4e3b\u306b ServiceNow CMDB \u306a\u3069\u306e Entity Context \u304b\u3089\u53d6\u5f97\u3055\u308c\u307e\u3059\u3002<\/li>\n<li data-line=\"267\" class=\"code-line\">\n<strong>DOMAIN_NAME<\/strong>: \u89b3\u6e2c\u3055\u308c\u305f\u30c9\u30e1\u30a4\u30f3\u540d\u3002Derived Context \u3068\u3057\u3066\u8a18\u9332\u3055\u308c\u3001IoC matches \u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<li data-line=\"268\" class=\"code-line\">\n<strong>FILE (HASH)<\/strong>: \u89b3\u6e2c\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb \u30cf\u30c3\u30b7\u30e5\u3002Derived Context \u3068\u3057\u3066\u8a18\u9332\u3055\u308c\u308b\u304b\u3001IoC matches \u306e\u7528\u9014\u3067\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002\u305f\u3060\u3057\u3001IoC matches \u4ee5\u5916\u306e\u76ee\u7684\u3067\u30d5\u30a1\u30a4\u30eb \u30a8\u30f3\u30ea\u30c3\u30c1 \u30c7\u30fc\u30bf\u3068\u3057\u3066 Entity Context \u306f\u4f7f\u7528\u3067\u304d\u307e\u305b\u3093\u3002<\/li>\n<li data-line=\"269\" class=\"code-line\">\n<strong>GROUP<\/strong>: \u30e6\u30fc\u30b6\u30fc \u30b0\u30eb\u30fc\u30d7\u60c5\u5831\u3002Entity Context \u3067\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<li data-line=\"270\" class=\"code-line\">\n<strong>IP_ADDRESS<\/strong>: IP \u30a2\u30c9\u30ec\u30b9\u60c5\u5831\u3002\u901a\u5e38\u306f <code>graph.entity.hostname<\/code>, <code>graph.entity.ip<\/code> \u306a\u3069\u306e\u30a2\u30bb\u30c3\u30c8\u306e\u4e00\u90e8\u3068\u3057\u3066\u542b\u307e\u308c\u307e\u3059\u304c\u3001\u4e3b\u306b IoC matches \u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<li data-line=\"271\" class=\"code-line\">\n<strong>MUTEX<\/strong>: IoC matches \u306b\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002<\/li>\n<li data-line=\"272\" class=\"code-line\">\n<strong>RESOURCE<\/strong>: \u30af\u30e9\u30a6\u30c9\u30d9\u30fc\u30b9\u306e\u30ea\u30bd\u30fc\u30b9(\u30aa\u30d6\u30b8\u30a7\u30af\u30c8 \u30b9\u30c8\u30ec\u30fc\u30b8\u3001IAM\u3001\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u306a\u3069)\u3002Entity Context \u306e\u4e00\u90e8\u3068\u3057\u3066\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<li data-line=\"273\" class=\"code-line\">\n<strong>URL<\/strong>: IoC matches \u7528\u9014\u3067 Entity Context \u307e\u305f\u306f Global Context \u304b\u3089\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002<\/li>\n<li data-line=\"274\" class=\"code-line\">\n<strong>USER<\/strong>: \u30e6\u30fc\u30b6\u30fc\u60c5\u5831(\u4f8b\uff1aActive Directory)\u306e\u30a8\u30a4\u30ea\u30a2\u30b9\u3084\u30a8\u30f3\u30ea\u30c3\u30c1\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002IoC matches (\u4f8b\uff1a\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9)\u306b\u3082\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__78144e95267ae\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__78144e95267ae\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Freference%2Fudm-field-list%23entity_enumerated_types\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"278\" class=\"code-line\"\/>\n<h4 id=\"yara-l-%E6%A4%9C%E5%87%BA%E3%83%AB%E3%83%BC%E3%83%AB%E3%80%90%E9%87%8D%E8%A6%81%EF%BC%81%E3%80%91\" data-line=\"280\" class=\"code-line\">\n YARA-L \u691c\u51fa\u30eb\u30fc\u30eb\u3010\u91cd\u8981\uff01\u3011<\/h4>\n<p data-line=\"281\" class=\"code-line\">VirusTotal \u306e YARA \u306b\u7531\u6765\u3059\u308b Google SecOps SIEM \u306e\u691c\u51fa\u30eb\u30fc\u30eb\u69cb\u6587\u3067\u3042\u308a\u3001UDM \u306b\u6e96\u62e0\u3057\u305f\u5171\u901a\u30d5\u30a3\u30fc\u30eb\u30c9\u3067\u30eb\u30fc\u30eb\u4f5c\u6210\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__60471b68a0cfd\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__60471b68a0cfd\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fdetection%2Fyara-l-2-0-syntax%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<div class=\"code-block-container\">\n<pre class=\"language-yaral\"><code class=\"language-yaral code-line\" data-line=\"285\">rule <rule name=\"\"> {\n  meta:\n    \/\/ \u5fc5\u9808\n    \/\/ \u30eb\u30fc\u30eb\u306e\u8a73\u7d30\u60c5\u5831(\u4f5c\u6210\u8005\u3001\u691c\u51fa\u5bfe\u8c61\u3001\u8aac\u660e\u3001\u91cd\u8981\u5ea6\u3001Mitre ATT&amp;CK \u306e TTPs\u3001\u30d0\u30fc\u30b8\u30e7\u30f3\u7ba1\u7406\u306a\u3069)\n\n  events:\n    \/\/ \u5fc5\u9808\n    \/\/ UDM \u30a4\u30d9\u30f3\u30c8\u306e\u6761\u4ef6\u3092\u6307\u5b9a\n\n  match:\n    \/\/ \u7701\u7565\u53ef\u80fd(\u30de\u30eb\u30c1 \u30a4\u30d9\u30f3\u30c8 \u30eb\u30fc\u30eb\u3067\u306f\u5fc5\u9808)\n    \/\/ `events` \u30bb\u30af\u30b7\u30e7\u30f3\u5185\u3067\u5b9a\u7fa9\u3055\u308c\u305f\u30d7\u30ec\u30fc\u30b9 \u30db\u30eb\u30c0\u30fc\u5909\u6570\u306b\u57fa\u3065\u3044\u3066\u3001\u7d50\u679c\u3092\u30b0\u30eb\u30fc\u30d7\u5316\n\n  outcome:\n    \/\/ \u7701\u7565\u53ef\u80fd\n    \/\/ \u8abf\u67fb\u306b\u95a2\u3059\u308b\u8ffd\u52a0\u306e\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3092\u63d0\u4f9b\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\n\n  condition:\n    \/\/ \u5fc5\u9808\n    \/\/ \u691c\u51fa\u3092\u767a\u751f\u3055\u305b\u308b\u305f\u3081\u306b\u4e00\u81f4\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u30a4\u30d9\u30f3\u30c8\u306a\u3069\u3092\u8a18\u8f09\n\n  options:\n    \/\/ \u7701\u7565\u53ef\u80fd\n    \/\/ \u3053\u306e\u30eb\u30fc\u30eb\u306e\u52d5\u4f5c\u65b9\u6cd5\u3092\u5909\u66f4\u3059\u308b\u305f\u3081\u306e\u30aa\u30d7\u30b7\u30e7\u30f3\n    \/\/ allow_zero_values = <true or=\"\" false=\"\">\n}\n<\/true><\/rule><\/code><\/pre>\n<\/div>\n<p data-line=\"314\" class=\"code-line\"><strong>\u57fa\u672c\u69cb\u6587<\/strong><\/p>\n<ol data-line=\"315\" class=\"code-line\">\n<li data-line=\"315\" class=\"code-line\">\n<strong>\u30b7\u30f3\u30b0\u30eb \u30a4\u30d9\u30f3\u30c8\u691c\u51fa<\/strong>:<br \/>1 \u3064\u306e\u30a4\u30d9\u30f3\u30c8\u304c\u5b58\u5728\u3059\u308b\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3059\u308b\u30eb\u30fc\u30eb\u306e\u4f8b\u3067\u3059\u3002<\/li>\n<\/ol>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__82a45335ee15f\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__82a45335ee15f\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fdetection%2Fyara-l-2-0-overview%3Fhl%3Dja%23single-event-rule\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<div class=\"code-block-container\">\n<pre class=\"language-yaral\"><code class=\"language-yaral code-line\" data-line=\"320\">rule single_event_rule {\n  meta:\n    author = \"example@example.com\"\n\n  events:\n    $e.metadata.event_type = \"USER_LOGIN\"\n\n  condition:\n    $e\n}\n<\/code><\/pre>\n<\/div>\n<ol start=\"2\" data-line=\"333\" class=\"code-line\">\n<li data-line=\"333\" class=\"code-line\">\n<strong>\u30de\u30eb\u30c1\u30a4\u30d9\u30f3\u30c8\u691c\u51fa<\/strong>:<br \/>\u7279\u5b9a\u306e\u671f\u9593\u306e\u8907\u6570\u306e\u30a4\u30d9\u30f3\u30c8\u3092\u30b0\u30eb\u30fc\u30d7\u5316\u3057\u3001\u30a4\u30d9\u30f3\u30c8\u9593\u306e\u76f8\u95a2\u95a2\u4fc2\u3092\u7279\u5b9a\u3059\u308b\u969b\u306b\u5229\u7528\u3059\u308b\u30eb\u30fc\u30eb\u306e\u4f8b\u3067\u3059\u3002<\/li>\n<\/ol>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__523f1d61b848d\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__523f1d61b848d\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fdetection%2Fyara-l-2-0-overview%3Fhl%3Dja%23multiple_event_rule\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<div class=\"code-block-container\">\n<pre class=\"language-yaral\"><code class=\"language-yaral code-line\" data-line=\"338\">rule multi_event_rule {\n  meta:\n    author = \"example@example.com\"\n\n  events:\n    $e.metadata.event_type = \"USER_LOGIN\"\n    $e.principal.user.userid = $user\n\n  match:\n    $user over 10m\n\n  condition:\n    #e &gt;= 10\n}\n<\/code><\/pre>\n<\/div>\n<ol start=\"3\" data-line=\"355\" class=\"code-line\">\n<li data-line=\"355\" class=\"code-line\">\n<strong>\u5916\u90e8 IoC \u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306e\u6d3b\u7528<\/strong>\uff1a<br \/>\u30d5\u30a3\u30fc\u30c9\u3092\u901a\u3058\u3066\u53d6\u308a\u8fbc\u3093\u3060 MISP \u306e IoC \u30c7\u30fc\u30bf\u3068\u76f8\u95a2\u3059\u308b\u30a4\u30d9\u30f3\u30c8\u3092\u691c\u51fa\u3059\u308b\u30de\u30eb\u30c1 \u30a4\u30d9\u30f3\u30c8 \u30eb\u30fc\u30eb\u306e\u4f8b\u3067\u3059\u3002<\/li>\n<\/ol>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__e37d2867cc1cd\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__e37d2867cc1cd\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fingestion%2Fdefault-parsers%2Fmisp%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__08e8857355d1d\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__08e8857355d1d\" data-content=\"https%3A%2F%2Fsecurity.googlecloudcommunity.com%2Fcommunity-blog-42%2Fnew-to-google-secops-building-rules-with-your-own-threat-intel-part-1-4039\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__185059e78b027\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__185059e78b027\" data-content=\"https%3A%2F%2Fmedium.com%2F%40thatsiemguy%2Fmisp-bindplane-and-google-secops-262f48f9bdbd\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<div class=\"code-block-container\">\n<pre class=\"language-yaral\"><code class=\"language-yaral code-line\" data-line=\"362\">rule ioc_detection {\n  events:\n    $dns.metadata.event_type = \"NETWORK_DNS\"\n    $dns.network.dns.questions.name = $dns_query\n\n    $ioc.graph.metadata.product_name = \"MISP\"\n    $ioc.graph.metadata.entity_type = \"DOMAIN_NAME\"\n    $ioc.graph.metadata.source_type = \"ENTITY_CONTEXT\"\n    $ioc.graph.metadata.threat.summary = \"C2 domains\"\n    $ioc.graph.entity.hostname = $dns_query\n\n  match:\n    $dns_query over 5m\n\n  condition:\n    $dns and $ioc\n}\n<\/code><\/pre>\n<\/div>\n<hr data-line=\"382\" class=\"code-line\"\/>\n<h4 id=\"siem-%E3%81%AE%E3%83%87%E3%83%BC%E3%82%BF%E5%8F%96%E3%82%8A%E8%BE%BC%E3%81%BF\" data-line=\"384\" class=\"code-line\">\n SIEM \u306e\u30c7\u30fc\u30bf\u53d6\u308a\u8fbc\u307f<\/h4>\n<h5 data-line=\"385\" class=\"code-line\">Feed<\/h5>\n<p data-line=\"386\" class=\"code-line\">Google SecOps \u306e Feed \u306f\u3001\u69d8\u3005\u306a\u30c7\u30fc\u30bf\u30bd\u30fc\u30b9\u304b\u3089\u81ea\u52d5\u7684\u306b\u30ed\u30b0\u30c7\u30fc\u30bf\u3092\u53d6\u308a\u8fbc\u3080\u305f\u3081\u306e\u6a5f\u80fd\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__d602058d75a28\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__d602058d75a28\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fadministration%2Ffeed-management\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h6 data-line=\"390\" class=\"code-line\">Feed \u306e\u52d5\u4f5c\u30d7\u30ed\u30bb\u30b9<\/h6>\n<ol data-line=\"391\" class=\"code-line\">\n<li data-line=\"391\" class=\"code-line\">\n<strong>\u30c7\u30fc\u30bf\u30bd\u30fc\u30b9\u63a5\u7d9a<\/strong>: \u8a2d\u5b9a\u3055\u308c\u305f\u30bd\u30fc\u30b9\u304b\u3089\u5b9a\u671f\u7684\u306b\u30c7\u30fc\u30bf\u3092\u53d6\u5f97<\/li>\n<li data-line=\"392\" class=\"code-line\">\n<strong>\u6b63\u898f\u5316\u51e6\u7406<\/strong>: \u53d6\u5f97\u3057\u305f\u30c7\u30fc\u30bf\u3092 UDM(Unified Data Model) \u5f62\u5f0f\u306b\u5909\u63db<\/li>\n<li data-line=\"393\" class=\"code-line\">\n<strong>\u53d6\u308a\u8fbc\u307f\u5b9f\u884c<\/strong>: \u6b63\u898f\u5316\u3055\u308c\u305f\u30c7\u30fc\u30bf\u3092 Google SecOps \u306b\u4fdd\u5b58<\/li>\n<\/ol>\n<h6 data-line=\"395\" class=\"code-line\">Feed \u30a8\u30e9\u30fc\u306e\u7a2e\u985e\u3068\u5bfe\u51e6\u6cd5<\/h6>\n<p data-line=\"396\" class=\"code-line\">Feed \u306e\u30a8\u30e9\u30fc\u3068\u5bfe\u51e6\u65b9\u6cd5\u3092\u4e00\u90e8\u629c\u7c8b\u3057\u3066\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n<ul data-line=\"397\" class=\"code-line\">\n<li data-line=\"397\" class=\"code-line\">\n<strong>LOGIN_FAILED<\/strong><\/p>\n<ul data-line=\"398\" class=\"code-line\">\n<li data-line=\"398\" class=\"code-line\">\u30a8\u30e9\u30fc\u6982\u8981: \u30c7\u30fc\u30bf\u30bd\u30fc\u30b9\u3078\u306e\u63a5\u7d9a\u306f\u78ba\u7acb\u3055\u308c\u305f\u304c\u3001\u8a8d\u8a3c\u60c5\u5831\u304c\u8aa4\u3063\u3066\u3044\u308b<\/li>\n<li data-line=\"399\" class=\"code-line\">\u5bfe\u51e6: \u8a8d\u8a3c\u60c5\u5831\u306e\u78ba\u8a8d\u30fb\u518d\u8a2d\u5b9a<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"400\" class=\"code-line\">\n<strong>PERMISSION_DENIED<\/strong><\/p>\n<ul data-line=\"401\" class=\"code-line\">\n<li data-line=\"401\" class=\"code-line\">\u30a8\u30e9\u30fc\u6982\u8981: \u8a8d\u53ef\u3055\u308c\u3066\u3044\u306a\u3044\u305f\u3081\u3001\u30a2\u30af\u30bb\u30b9\u304c\u62d2\u5426\u3055\u308c\u305f<\/li>\n<li data-line=\"402\" class=\"code-line\">\u5bfe\u51e6: \u5fc5\u8981\u306a\u30a2\u30af\u30bb\u30b9\u6a29\u9650\u306e\u8ffd\u52a0\u30fb\u78ba\u8a8d<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"403\" class=\"code-line\">\n<strong>INVALID_FEED_CONFIG<\/strong><\/p>\n<ul data-line=\"404\" class=\"code-line\">\n<li data-line=\"404\" class=\"code-line\">\u30a8\u30e9\u30fc\u6982\u8981: Feed \u69cb\u6210\u306b\u8aa4\u308a\u304c\u3042\u308b<\/li>\n<li data-line=\"405\" class=\"code-line\">\u5bfe\u51e6: Feed \u69cb\u6210\u306e\u898b\u76f4\u3057<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"406\" class=\"code-line\">\n<strong>HTTP_404<\/strong><\/p>\n<ul data-line=\"407\" class=\"code-line\">\n<li data-line=\"407\" class=\"code-line\">\u30a8\u30e9\u30fc\u6982\u8981: \u30d5\u30a1\u30a4\u30eb\u3084\u30ea\u30bd\u30fc\u30b9\u304c\u5b58\u5728\u3057\u306a\u3044<\/li>\n<li data-line=\"408\" class=\"code-line\">\u5bfe\u51e6: \u30d5\u30a1\u30a4\u30eb\u30fb\u30ea\u30bd\u30fc\u30b9\u306e\u5b58\u5728\u78ba\u8a8d\u3001\u30a2\u30af\u30bb\u30b9\u6a29\u306e\u78ba\u8a8d<\/li>\n<\/ul>\n<\/li>\n<li data-line=\"409\" class=\"code-line\">\n<strong>CONNECTION_FAILED<\/strong><\/p>\n<ul data-line=\"410\" class=\"code-line\">\n<li data-line=\"410\" class=\"code-line\">\u30a8\u30e9\u30fc\u6982\u8981: \u30c7\u30fc\u30bf\u30bd\u30fc\u30b9\u306e IP \u30a2\u30c9\u30ec\u30b9\u3068\u30dd\u30fc\u30c8\u306b\u5230\u9054\u3067\u304d\u306a\u3044\u72b6\u614b<\/li>\n<li data-line=\"411\" class=\"code-line\">\u5bfe\u51e6: \u63a5\u7d9a\u5148\u306e\u78ba\u8a8d\u3001\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u8a2d\u5b9a\u306e\u78ba\u8a8d<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__ddcf36273a1aa\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__ddcf36273a1aa\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fadministration%2Ffeed-management%3Fhl%3Dja%23troubleshooting\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"415\" class=\"code-line\">\u76f4\u63a5\u53d6\u308a\u8fbc\u307f<\/h5>\n<p data-line=\"416\" class=\"code-line\">Google Workspace\u3001Google Cloud \u306e Audit Log\u3001SCC \u306e Security Health Analytics \u3084 Threat Detections \u306e\u691c\u51fa\u7d50\u679c (Findings) \u306a\u3069\u3092\u53d6\u308a\u8fbc\u3080\u969b\u306b\u5229\u7528\u3057\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__29c252441ec87\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__29c252441ec87\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fingestion%2Fcloud%2Fingest-gcp-logs%3Fhl%3Dja%23option_1_direct_ingestion\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"420\" class=\"code-line\">\u30af\u30e9\u30a6\u30c9\u53d6\u308a\u8fbc\u307f<\/h5>\n<p data-line=\"421\" class=\"code-line\">Cloud Storage\u3001S3 \u3084 Azure Blob \u30d0\u30b1\u30c3\u30c8\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u30c7\u30fc\u30bf\u3092\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u306b\u5f93\u3063\u3066 Feed \u3067\u8ee2\u9001\u3057\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__19614bbfe282c\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__19614bbfe282c\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fingestion%2Fcloud%2Fingest-gcp-logs%3Fhl%3Dja%23gcp-storage\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"425\" class=\"code-line\">Ingestion API<\/h5>\n<p data-line=\"426\" class=\"code-line\">\u30ed\u30b0\u30c7\u30fc\u30bf\u3092 Google SecOps \u306b\u76f4\u63a5\u9001\u4fe1\u3059\u308b\u305f\u3081\u306e\u6a5f\u80fd\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__7bf5a9960d072\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__7bf5a9960d072\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Freference%2Fingestion-api\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"430\" class=\"code-line\">Forwarder<\/h5>\n<p data-line=\"431\" class=\"code-line\">\u30aa\u30f3\u30d7\u30ec\u30df\u30b9\u3084\u30af\u30e9\u30a6\u30c9\u4e0a\u306e\u5404\u7a2e\u30ed\u30b0\u3092 Google SecOps \u306b\u8ee2\u9001\u3059\u308b\u5c02\u7528\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u3067\u3059\u3002<br \/>\u591a\u69d8\u306a\u30c7\u30fc\u30bf\u30bd\u30fc\u30b9 (Syslog\u3001\u30d5\u30a1\u30a4\u30eb\u3001\u30af\u30e9\u30a6\u30c9 \u30b9\u30c8\u30ec\u30fc\u30b8\u7b49) \u306b\u5bfe\u5fdc\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\u73fe\u5728\u306f\u5f8c\u8ff0\u3059\u308b Bindplane \u3067\u3059\u3079\u3066\u306e\u5f79\u5272\u3092\u62c5\u3046\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__91ed7be6f3513\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__91ed7be6f3513\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fforwarder%2Foverview%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__64ae751d6da48\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__64ae751d6da48\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fadministration%2Ffeed-management%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"439\" class=\"code-line\">Bindplane<\/h5>\n<p data-line=\"440\" class=\"code-line\">\u30aa\u30f3\u30d7\u30ec\u30df\u30b9\u3084\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3 \u30b7\u30b9\u30c6\u30e0\u304b\u3089\u30ed\u30b0\u3092\u53ce\u96c6\u3067\u304d\u308b\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u3067\u3059\u3002<br \/>Google SecOps \u306e\u30e9\u30a4\u30bb\u30f3\u30b9\u3092\u6301\u3063\u3066\u3044\u308b\u3068\u7121\u6599\u3067\u5229\u7528\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__8be290fd43c97\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__8be290fd43c97\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fstackdriver%2Fbindplane%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__3cd3efa73efb8\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__3cd3efa73efb8\" data-content=\"https%3A%2F%2Fbindplane.com%2Fgoogle\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"446\" class=\"code-line\">Bindplane \u306b\u3064\u3044\u3066\u3084\u3001Bindplane \u3092\u4f7f\u3063\u305f\u30ed\u30b0\u53d6\u308a\u8fbc\u307f\u65b9\u6cd5\u306f\u4ee5\u4e0b\u306e\u8a18\u4e8b\u3067\u89e3\u8aac\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__2e2c33323a2ff\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__2e2c33323a2ff\" data-content=\"https%3A%2F%2Fzenn.dev%2Fcloud_ace%2Farticles%2Fgoogle-secops-bindplane\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"450\" class=\"code-line\">Bindplane Agent \u304c\u6b62\u307e\u308b\u3068\u30ed\u30b0\u304c\u9001\u3089\u308c\u306a\u304f\u306a\u308b\u305f\u3081\u3001Events Per Second(EPS) \u3092\u76e3\u8996\u3057\u3001\u30ed\u30b0\u53ce\u96c6\u72b6\u6cc1\u3092\u76e3\u8996\u3067\u304d\u308b\u3088\u3046\u306b\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3092\u304a\u3059\u3059\u3081\u3057\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__e3eb81e228a8\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__e3eb81e228a8\" data-content=\"https%3A%2F%2Fmedium.com%2F%40thatsiemguy%2Fobserviq-bindplane-the-otel-agent-and-google-secops-e6ab00bdb580%23%3A~%3Atext%3DVerify%2520with%2520UDM%2520Search\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"454\" class=\"code-line\"\/>\n<h4 id=\"%E3%82%B1%E3%83%BC%E3%82%B9%E7%AE%A1%E7%90%86\" data-line=\"456\" class=\"code-line\">\n \u30b1\u30fc\u30b9\u7ba1\u7406<\/h4>\n<p data-line=\"457\" class=\"code-line\">SOAR \u3067\u306f SIEM \u3067\u767a\u5831\u3055\u308c\u305f\u30a2\u30e9\u30fc\u30c8\u3092\u81ea\u52d5\u7684\u306b 1 \u3064\u306e\u30b1\u30fc\u30b9\u3068\u3057\u3066\u307e\u3068\u3081\u3001\u512a\u5148\u9806\u4f4d\u4ed8\u3051\u3001\u62c5\u5f53\u8005\u306e\u5272\u308a\u5f53\u3066\u3001\u30a8\u30b9\u30ab\u30ec\u30fc\u30b7\u30e7\u30f3\u3092\u5b9f\u65bd\u3059\u308b\u305f\u3081\u306e\u30b1\u30fc\u30b9\u7ba1\u7406\u6a5f\u80fd\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__487e250b73e2\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__487e250b73e2\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fsoar%2Finvestigate%2Fworking-with-cases%2Fcases-overview\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"461\" class=\"code-line\">\u30b1\u30fc\u30b9\u7ba1\u7406\u65b9\u6cd5\u306b\u3064\u3044\u3066\u306f\u3001\u4ee5\u4e0b\u306e\u8a18\u4e8b\u3067\u89e3\u8aac\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__d5e99cfcf8db9\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__d5e99cfcf8db9\" data-content=\"https%3A%2F%2Fzenn.dev%2Fcloud_ace%2Farticles%2Fgoogle-secops-soar-case-management\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"465\" class=\"code-line\"\/>\n<h4 id=\"playbook\" data-line=\"467\" class=\"code-line\">\n Playbook<\/h4>\n<p data-line=\"468\" class=\"code-line\">\u81ea\u52d5\u5316\u3055\u308c\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u5fdc\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u3067\u3042\u308a\u3001\u30a2\u30e9\u30fc\u30c8\u691c\u8a3c\u3001\u5bfe\u5fdc\u3001\u30a8\u30b9\u30ab\u30ec\u30fc\u30b7\u30e7\u30f3\u3092\u81ea\u52d5\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__911cda19165a2\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__911cda19165a2\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fsoar%2Foverview-and-introduction%2Fgetting-started-with-chronicle-soar%23playbooks\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"472\" class=\"code-line\"><strong>\u4f7f\u7528\u4f8b<\/strong>:<\/p>\n<ul data-line=\"473\" class=\"code-line\">\n<li data-line=\"473\" class=\"code-line\">\n<strong>\u81ea\u52d5\u30a8\u30f3\u30ea\u30c3\u30c1<\/strong>: VirusTotal\u3001\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9 API \u3067\u306e IoC \u8abf\u67fb<\/li>\n<li data-line=\"474\" class=\"code-line\">\n<strong>\u5c01\u3058\u8fbc\u3081<\/strong>: \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u9694\u96e2\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u7121\u52b9\u5316\u306e\u81ea\u52d5\u5b9f\u884c<\/li>\n<li data-line=\"475\" class=\"code-line\">\n<strong>\u5916\u90e8\u30c1\u30b1\u30c3\u30c8\u7ba1\u7406\u30b5\u30fc\u30d3\u30b9\u9023\u643a<\/strong>: Service Now \u3084 Jira \u306a\u3069\u3078\u306e\u9023\u643a<\/li>\n<\/ul>\n<hr data-line=\"477\" class=\"code-line\"\/>\n<h4 id=\"virustotal-integration\" data-line=\"479\" class=\"code-line\">\n VirusTotal Integration<\/h4>\n<p data-line=\"480\" class=\"code-line\">\u30de\u30eb\u30a6\u30a7\u30a2\u5206\u6790\u3068\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306e\u30a8\u30f3\u30ea\u30c3\u30c1\u306b\u5229\u7528\u3067\u304d\u308b\u91cd\u8981\u306a\u5916\u90e8\u9023\u643a\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002<\/p>\n<h5 data-line=\"482\" class=\"code-line\">\u4e3b\u8981\u7528\u9014<\/h5>\n<ul data-line=\"483\" class=\"code-line\">\n<li data-line=\"483\" class=\"code-line\">\n<strong>\u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u5206\u6790<\/strong>: \u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u3092\u7528\u3044\u305f\u8105\u5a01\u5224\u5b9a<\/li>\n<li data-line=\"484\" class=\"code-line\">\n<strong>URL\u30fb\u30c9\u30e1\u30a4\u30f3\u5206\u6790<\/strong>: URL \u3084\u30c9\u30e1\u30a4\u30f3\u306e\u5b89\u5168\u6027\u78ba\u8a8d<\/li>\n<li data-line=\"485\" class=\"code-line\">\n<strong>Entity Graph Integration<\/strong>: \u81ea\u52d5\u30a8\u30f3\u30ea\u30c3\u30c1\u3001VirusTotal \u306e\u60c5\u5831\u306b\u3088\u308b\u7cbe\u5ea6\u5411\u4e0a<\/li>\n<li data-line=\"486\" class=\"code-line\">\n<strong>SOAR Playbook<\/strong>: \u81ea\u52d5\u5316\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u3067\u306e\u6d3b\u7528<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__b53891e39beab\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__b53891e39beab\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fsoar%2Fmarketplace-integrations%2Fvirustotal-v3\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"490\" class=\"code-line\"\/>\n<h4 id=\"false-positive-(%E5%81%BD%E9%99%BD%E6%80%A7)-%E5%AF%BE%E7%AD%96%E3%80%90%E9%87%8D%E8%A6%81%EF%BC%81%E3%80%91\" data-line=\"492\" class=\"code-line\">\n False Positive (\u507d\u967d\u6027) \u5bfe\u7b56\u3010\u91cd\u8981\uff01\u3011<\/h4>\n<p data-line=\"493\" class=\"code-line\">SecOps \u3092\u52b9\u679c\u7684\u306b\u904b\u7528\u3059\u308b\u306b\u306f\u3001<strong>False Positive (\u507d\u967d\u6027)<\/strong> \u3092\u9069\u5207\u306b\u51e6\u7406\u3057\u3001\u5c06\u6765\u306e\u767a\u751f\u3092\u6291\u6b62\u3059\u308b\u4ed5\u7d44\u307f\u304c\u4e0d\u53ef\u6b20\u3067\u3059\u3002<\/p>\n<p data-line=\"495\" class=\"code-line\">\u507d\u967d\u6027\u3068\u306f\u3001\u5b9f\u969b\u306b\u306f\u8105\u5a01\u3067\u306f\u306a\u3044\u6b63\u5e38\u306a\u6d3b\u52d5\u3092\u3001\u8aa4\u3063\u3066\u8105\u5a01\u3068\u3057\u3066\u691c\u77e5\u3057\u3066\u3057\u307e\u3046\u3053\u3068\u3067\u3059\u3002<br \/>\u507d\u967d\u6027\u304c\u591a\u767a\u3059\u308b\u3068\u3001\u30a2\u30ca\u30ea\u30b9\u30c8\u306e\u75b2\u5f0a\u3084\u672c\u5f53\u306b\u91cd\u8981\u306a\u30a2\u30e9\u30fc\u30c8\u306e\u898b\u9003\u3057\u306b\u3064\u306a\u304c\u308b\u305f\u3081\u3001SecOps \u306e\u904b\u7528\u306b\u304a\u3044\u3066\u91cd\u8981\u8996\u3055\u308c\u308b\u30c8\u30d4\u30c3\u30af\u3067\u3059\u3002<\/p>\n<p data-line=\"498\" class=\"code-line\">\u4e00\u65b9\u3067\u3001\u507d\u967d\u6027\u3092\u6e1b\u3089\u3059\u305f\u3081\u306b\u691c\u51fa\u3057\u304d\u3044\u5024\u3092\u4e0b\u3052\u308b\u306a\u3069\u306e\u5bfe\u5fdc\u3092\u884c\u3063\u3066\u3057\u307e\u3046\u3068\u3001\u4eca\u5ea6\u306f <strong>False Negative (\u507d\u9670\u6027)<\/strong> \u304c\u767a\u751f\u3057\u3001\u5b9f\u969b\u306e\u653b\u6483\u3092\u898b\u9003\u3057\u3066\u3057\u307e\u3046\u30ea\u30b9\u30af\u304c\u9ad8\u307e\u308a\u307e\u3059\u3002<br \/>\u507d\u9670\u6027\u306f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4fb5\u5bb3\u3092\u62db\u304f\u53ef\u80fd\u6027\u304c\u3042\u308b\u305f\u3081\u3001\u507d\u9670\u6027\u306e\u767a\u751f\u30ec\u30d9\u30eb\u3092\u5909\u3048\u305a\u306b\u507d\u967d\u6027\u3060\u3051\u3092\u6e1b\u3089\u3059\u3053\u3068\u304c\u91cd\u8981\u3067\u3059\u304c\u3001\u3053\u308c\u306f\u975e\u5e38\u306b\u96e3\u3057\u3044\u8ab2\u984c\u3067\u3059\u3002<\/p>\n<p data-line=\"501\" class=\"code-line\">\u307e\u305f\u3001\u507d\u967d\u6027\u306f\u5229\u7528\u74b0\u5883\u3084\u7d44\u7e54\u306e\u7279\u6027\u306b\u4f9d\u5b58\u3059\u308b\u9762\u3082\u5927\u304d\u304f\u3001\u691c\u51fa\u30eb\u30fc\u30eb\u306e\u8abf\u6574\u3060\u3051\u3067\u306f\u5b8c\u5168\u306b\u89e3\u6c7a\u3067\u304d\u307e\u305b\u3093\u3002<br \/>\u305d\u306e\u305f\u3081\u3001\u904b\u7528\u9762\u3067\u306e\u5bfe\u7b56\u306b\u3088\u308a\u540c\u3058\u507d\u967d\u6027\u304c\u7e70\u308a\u8fd4\u3057\u691c\u51fa\u3055\u308c\u306a\u3044\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u3067\u3001\u904b\u7528\u8ca0\u8377\u3092\u6539\u5584\u3057\u3001\u30a2\u30ca\u30ea\u30b9\u30c8\u304c\u3088\u308a\u91cd\u8981\u306a\u8105\u5a01\u306b\u96c6\u4e2d\u3067\u304d\u308b\u74b0\u5883\u3092\u6574\u5099\u3059\u308b\u3053\u3068\u304c\u6c42\u3081\u3089\u308c\u307e\u3059\u3002<\/p>\n<p data-line=\"504\" class=\"code-line\"><strong>False Positive \u306b\u5bfe\u3059\u308b\u30a2\u30d7\u30ed\u30fc\u30c1<\/strong><\/p>\n<ul data-line=\"505\" class=\"code-line\">\n<li data-line=\"505\" class=\"code-line\">\n<strong>\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u306e\u5206\u5c90<\/strong>: Playbook \u306e\u521d\u671f\u6bb5\u968e\u3067\u3001\u30a2\u30e9\u30fc\u30c8\u304c\u300cTrue Positive(\u5b9f\u969b\u306e\u8105\u5a01)\u300d\u304b\u300cFalse Positive(\u507d\u967d\u6027)\u300d\u304b\u3092\u5224\u65ad\u3059\u308b\u30b9\u30c6\u30c3\u30d7\u3092\u8a2d\u3051\u307e\u3059\u3002<\/li>\n<li data-line=\"506\" class=\"code-line\">\n<strong>\u30bf\u30b0\u4ed8\u3051\u306b\u3088\u308b\u53ef\u8996\u5316<\/strong>: \u8aa4\u691c\u77e5\u3068\u5224\u65ad\u3055\u308c\u305f\u30b1\u30fc\u30b9\u306f\u3001\u30af\u30ed\u30fc\u30ba\u3059\u308b\u969b\u306b\u300cFalse Positive\u300d\u306a\u3069\u306e\u4e00\u8cab\u3057\u305f\u30b1\u30fc\u30b9\u30bf\u30b0\u3092\u4ed8\u4e0e\u3059\u308b\u3053\u3068\u3067\u3001\u5f8c\u304b\u3089\u8aa4\u691c\u77e5\u306e\u50be\u5411\u3092\u5206\u6790\u3057\u305f\u308a\u3001\u30ec\u30dd\u30fc\u30c8\u3084\u30c0\u30c3\u30b7\u30e5\u30dc\u30fc\u30c9\u3067\u95a2\u9023\u30e1\u30c8\u30ea\u30af\u30b9\u3092\u8ffd\u8de1\u3059\u308b\u969b\u306b\u6d3b\u7528\u3067\u304d\u307e\u3059\u3002<\/li>\n<li data-line=\"507\" class=\"code-line\">\n<strong>\u30ab\u30b9\u30bf\u30e0\u30ea\u30b9\u30c8\u306b\u3088\u308b\u518d\u767a\u9632\u6b62<\/strong>: \u65e2\u77e5\u306e\u8aa4\u691c\u77e5\u3067\u3042\u308b\u3068\u7279\u5b9a\u3055\u308c\u305f\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3(IP \u30a2\u30c9\u30ec\u30b9\u3084\u30d5\u30a1\u30a4\u30eb \u30cf\u30c3\u30b7\u30e5\u306a\u3069)\u306f\u3001\u30ab\u30b9\u30bf\u30e0\u30ea\u30b9\u30c8\u306b\u8ffd\u52a0\u3057\u307e\u3059\u3002\u30ab\u30b9\u30bf\u30e0\u30ea\u30b9\u30c8\u3092\u6d3b\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u7279\u5b9a\u306e\u30a2\u30e9\u30fc\u30c8\u306b\u3001\u30ab\u30b9\u30bf\u30e0\u30ea\u30b9\u30c8\u306b\u5b58\u5728\u3059\u308b\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u3092\u542b\u3080\u5834\u5408\u3001\u540c\u3058\u8981\u56e0\u306b\u3088\u308b\u91cd\u8907\u3057\u305f\u30a2\u30e9\u30fc\u30c8\u306e\u767a\u751f\u3092\u6291\u5236\u3067\u304d\u307e\u3059\u3002<\/li>\n<li data-line=\"508\" class=\"code-line\">\n<strong>\u5b66\u3073\u306e\u8a18\u9332<\/strong>: False Positive \u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u306b\u306f\u3001Lessons Learned Block (\u6559\u8a13\u30d6\u30ed\u30c3\u30af) \u3092\u8ffd\u52a0\u3057\u3001\u5b66\u3073\u3092\u8a18\u9332\u3059\u308b\u3053\u3068\u3067\u691c\u51fa\u30eb\u30fc\u30eb\u306e\u30c1\u30e5\u30fc\u30cb\u30f3\u30b0\u3084\u30d7\u30ed\u30bb\u30b9\u306e\u6539\u5584\u306b\u7e4b\u3052\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/li>\n<li data-line=\"509\" class=\"code-line\">\n<strong>\u305d\u306e\u4ed6<\/strong>: YARA-L \u691c\u51fa\u30eb\u30fc\u30eb\u306e <code>condition<\/code> \u30bb\u30af\u30b7\u30e7\u30f3\u3067\u9069\u5207\u306a\u3057\u304d\u3044\u5024\u3092\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3067\u3001False Positive \u3092\u6e1b\u3089\u3059\u3053\u3068\u304c\u671f\u5f85\u3067\u304d\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__414ae2cadd761\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__414ae2cadd761\" data-content=\"https%3A%2F%2Fsecurity.googlecloudcommunity.com%2Fgoogle-security-operations-66%2Fsecurity-operations-designing-and-building-your-first-playbooks-5635\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__711a1b0ad0241\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__711a1b0ad0241\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fsoar%2Fadmin-tasks%2Fconfiguration%2Fcreate-custom-lists\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"514\" class=\"code-line\"\/>\n<h3 id=\"security-command-center(scc)\" data-line=\"516\" class=\"code-line\">\n Security Command Center(SCC)<\/h3>\n<p data-line=\"517\" class=\"code-line\">Security Command Center(SCC) \u306f\u3001Google Cloud \u4e0a\u3067\u4f7f\u7528\u3057\u3066\u3044\u308b\u30b5\u30fc\u30d3\u30b9\u306e\u8106\u5f31\u6027\u3084\u8105\u5a01\u3068\u306a\u308a\u3046\u308b\u8a2d\u5b9a\u3092\u691c\u77e5\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002<\/p>\n<h4 id=\"%E3%83%86%E3%82%A3%E3%82%A2%E6%A7%8B%E6%88%90-1\" data-line=\"519\" class=\"code-line\">\n \u30c6\u30a3\u30a2\u69cb\u6210<\/h4>\n<p data-line=\"520\" class=\"code-line\">SCC \u306b\u306f\u5229\u7528\u898f\u6a21\u3084\u30cb\u30fc\u30ba\u306b\u5fdc\u3058\u3066 3 \u3064\u306e\u30c6\u30a3\u30a2\u304c\u7528\u610f\u3055\u308c\u3066\u304a\u308a\u3001\u305d\u308c\u305e\u308c\u6a5f\u80fd\u3084\u30b5\u30dd\u30fc\u30c8\u7bc4\u56f2\u304c\u7570\u306a\u308a\u307e\u3059\u3002<\/p>\n<h4 id=\"%E4%B8%BB%E8%A6%81%E6%A9%9F%E8%83%BD\" data-line=\"534\" class=\"code-line\">\n \u4e3b\u8981\u6a5f\u80fd<\/h4>\n<ul data-line=\"535\" class=\"code-line\">\n<li data-line=\"535\" class=\"code-line\">\n<strong>Security Health Analytics(SHA)<\/strong>: \u8a2d\u5b9a\u30df\u30b9\u691c\u51fa<\/li>\n<li data-line=\"536\" class=\"code-line\">\n<strong>Event Threat Detection<\/strong>: \u30ea\u30a2\u30eb\u30bf\u30a4\u30e0\u8105\u5a01\u691c\u51fa<\/li>\n<li data-line=\"537\" class=\"code-line\">\n<strong>Virtual Machine Threat Detection<\/strong>: Compute Engine VM \u4e0a\u306e\u30af\u30ea\u30d7\u30c8\u30de\u30a4\u30cb\u30f3\u30b0\u3001\u30de\u30eb\u30a6\u30a7\u30a2\u306a\u3069\u306e\u8105\u5a01\u691c\u51fa<\/li>\n<li data-line=\"538\" class=\"code-line\">\n<strong>Container Threat Detection<\/strong>: Google Kubernetes Engine \u30b3\u30f3\u30c6\u30ca\u3084 Cloud Run \u306e\u8105\u5a01\u691c\u51fa<\/li>\n<li data-line=\"539\" class=\"code-line\">\n<strong>Web Security Scanner<\/strong>: Web \u30a2\u30d7\u30ea\u8106\u5f31\u6027\u8a3a\u65ad<\/li>\n<li data-line=\"540\" class=\"code-line\">\n<strong>Attack Path Simulation<\/strong>: \u653b\u6483\u30d1\u30b9 \u30b7\u30df\u30e5\u30ec\u30fc\u30b7\u30e7\u30f3<\/li>\n<li data-line=\"541\" class=\"code-line\">\n<strong>AI Protection<\/strong>: Model Armor \u306a\u3069\u3001AI \u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u3092\u4fdd\u8b77\u3059\u308b\u6a5f\u80fd<\/li>\n<li data-line=\"542\" class=\"code-line\">\n<strong>CIEM<\/strong>: ID \u306b\u95a2\u3059\u308b\u69cb\u6210\u30df\u30b9\u691c\u51fa<\/li>\n<li data-line=\"543\" class=\"code-line\">\n<strong>DSPM<\/strong>: Sensitive Data Protection \u3068\u9023\u643a\u3057\u3066\u30c7\u30fc\u30bf\u3092\u4fdd\u8b77<\/li>\n<li data-line=\"544\" class=\"code-line\">\n<strong>Assured OSS<\/strong>: Google \u304c\u8106\u5f31\u6027\u306e\u30b9\u30ad\u30e3\u30f3\u3001\u5206\u6790\u3001\u30d5\u30a1\u30b8\u30f3\u30b0 \u30c6\u30b9\u30c8\u3092\u884c\u3063\u305f OSS \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u3001\u81ea\u793e\u306e\u958b\u767a\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306b\u5b89\u5168\u306b\u7d44\u307f\u8fbc\u3080\u3053\u3068\u304c\u3067\u304d\u308b\u6a5f\u80fd\u3067\u3059\u3002\u7279\u306b\u30b3\u30f3\u30c6\u30ca\u74b0\u5883\u3067\u306f\u3001Container Threat Detection \u3068\u7d44\u307f\u5408\u308f\u305b\u308b\u3053\u3068\u3067\u3001\u4fe1\u983c\u3067\u304d\u308b OSS \u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u4f7f\u7528\u3068\u5b9f\u884c\u6642\u306e\u8105\u5a01\u691c\u51fa\u306b\u3088\u308b\u591a\u5c64\u9632\u5fa1\u3092\u5b9f\u73fe\u3067\u304d\u307e\u3059\u3002<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__7f7cf69e582ed\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__7f7cf69e582ed\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fsecurity-command-center%2Fdocs%2Fsecurity-command-center-overview%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"548\" class=\"code-line\">\u95a2\u9023\u8a18\u4e8b\u306f\u3053\u3061\u3089\u3067\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__8f8edf03d06b7\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__8f8edf03d06b7\" data-content=\"https%3A%2F%2Fzenn.dev%2Fcloud_ace%2Farticles%2Fscc-enterprise-overview\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"551\" class=\"code-line\"\/>\n<h3 id=\"google-threat-intelligence(gti)\" data-line=\"553\" class=\"code-line\">\n Google Threat Intelligence(GTI)<\/h3>\n<p data-line=\"554\" class=\"code-line\">Google Threat Intelligence (\u4ee5\u964d\u3001GTI) \u306f\u3001Google \u72ec\u81ea\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3068\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u306e\u8105\u5a01\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3092\u7d71\u5408\u3057\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30c1\u30fc\u30e0\u304c\u8105\u5a01\u3092\u7279\u5b9a\u3001\u8abf\u67fb\u3001\u5bfe\u5fdc\u3059\u308b\u306e\u3092\u652f\u63f4\u3059\u308b\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002<\/p>\n<h4 id=\"%E4%B8%BB%E8%A6%81%E6%A9%9F%E8%83%BD%E8%A9%B3%E7%B4%B0\" data-line=\"556\" class=\"code-line\">\n \u4e3b\u8981\u6a5f\u80fd\u8a73\u7d30<\/h4>\n<p data-line=\"557\" class=\"code-line\"><strong>Threat Landscape<\/strong>: \u696d\u754c\u3067\u6d3b\u52d5\u3057\u3066\u3044\u308b\u8105\u5a01\u30b0\u30eb\u30fc\u30d7\u3092\u7279\u5b9a\u3057\u3001\u305d\u306e IoC\u3001MITRE ATT&amp;CK \u6226\u8853\u3001TTPs \u306a\u3069\u3092\u8abf\u67fb<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__63c459266c11c\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__63c459266c11c\" data-content=\"https%3A%2F%2Fgtidocs.virustotal.com%2Fdocs%2Fget-started-threat-landscape\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"561\" class=\"code-line\"><strong>Digital Threat Monitoring<\/strong>: \u30c0\u30fc\u30af\u30a6\u30a7\u30d6\u3001\u30c7\u30a3\u30fc\u30d7\u30a6\u30a7\u30d6\u306b\u63b2\u8f09\u3055\u308c\u305f\u60c5\u5831(\u653b\u6483\u4e88\u544a\u3084\u9867\u5ba2\u60c5\u5831)\u3092\u76e3\u8996\u3057\u3001\u81ea\u793e\u30d6\u30e9\u30f3\u30c9\u3084\u88fd\u54c1\u540d\u3068\u3044\u3063\u305f\u30ad\u30fc\u30ef\u30fc\u30c9\u8a2d\u5b9a\u306b\u3088\u308b\u30e2\u30cb\u30bf\u30ea\u30f3\u30b0<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__d9f4006b7de0e\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__d9f4006b7de0e\" data-content=\"https%3A%2F%2Fgtidocs.virustotal.com%2Fdocs%2Fget-started-dtm\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"565\" class=\"code-line\"><strong>IoC Collections<\/strong>: IoC \u5171\u6709\u30fb\u7ba1\u7406<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__a9db6427d6c08\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__a9db6427d6c08\" data-content=\"https%3A%2F%2Fgtidocs.virustotal.com%2Fdocs%2Fioc-collections\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<p data-line=\"569\" class=\"code-line\">\u79c1\u304c Google Threat Intelligence \u306e\u30ef\u30fc\u30af\u30b7\u30e7\u30c3\u30d7\u306b\u53c2\u52a0\u3057\u305f\u969b\u306e\u8a18\u4e8b\u3067 GTI \u306e\u6a5f\u80fd\u306b\u3064\u3044\u3066\u7d39\u4ecb\u3057\u3066\u3044\u308b\u305f\u3081\u3001\u3053\u3061\u3089\u3082\u53c2\u8003\u306b\u306a\u308b\u304b\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__3f6bbc9e89c1d\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__3f6bbc9e89c1d\" data-content=\"https%3A%2F%2Fzenn.dev%2Fcloud_ace%2Farticles%2Fb51235dcb8f006%23google-threat-intelligence-%25E3%2581%25A8%25E3%2581%25AF\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"573\" class=\"code-line\"\/>\n<h3 id=\"%E3%81%9D%E3%81%AE%E4%BB%96-google-cloud-%E3%83%97%E3%83%AD%E3%83%80%E3%82%AF%E3%83%88\" data-line=\"575\" class=\"code-line\">\n \u305d\u306e\u4ed6 Google Cloud \u30d7\u30ed\u30c0\u30af\u30c8<\/h3>\n<h4 id=\"cloud-audit-logs\" data-line=\"576\" class=\"code-line\">\n Cloud Audit Logs<\/h4>\n<p data-line=\"577\" class=\"code-line\">\u30a2\u30af\u30bb\u30b9\u304c\u8a31\u53ef\u3055\u308c\u305f\u3068\u304d\u3001\u62d2\u5426\u3055\u308c\u305f\u3068\u304d\u7b49\u3001\u30a4\u30d9\u30f3\u30c8\u767a\u751f\u6642\u306b Cloud Logging \u306b\u30ed\u30b0\u3092\u8a18\u9332\u3057\u307e\u3059\u3002<br \/>\u4e3b\u8981\u30ed\u30b0\u30bf\u30a4\u30d7\u306b\u3042\u308b\u30bf\u30a4\u30d7\u5225\u306b\u8a2d\u5b9a\u304c\u53ef\u80fd\u3067\u3059\u3002Google Cloud \u3092\u76e3\u8996\u3059\u308b\u4e0a\u3067\u6700\u3082\u91cd\u8981\u306a\u30c7\u30fc\u30bf\u30bd\u30fc\u30b9\u3067\u3059\u3002<\/p>\n<h4 id=\"%E4%B8%BB%E8%A6%81%E3%83%AD%E3%82%B0%E3%82%BF%E3%82%A4%E3%83%97\" data-line=\"580\" class=\"code-line\">\n \u4e3b\u8981\u30ed\u30b0\u30bf\u30a4\u30d7<\/h4>\n<ul data-line=\"581\" class=\"code-line\">\n<li data-line=\"581\" class=\"code-line\">\n<strong>Admin Activity audit logs<\/strong>: VM \u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306e\u4f5c\u6210\u30fb\u5909\u66f4\u306a\u3069\u306e\u30ea\u30bd\u30fc\u30b9\u8a2d\u5b9a\u5909\u66f4\u306e\u8a18\u9332(\u8981\u8a2d\u5b9a)<\/li>\n<li data-line=\"582\" class=\"code-line\">\n<strong>Data Access audit logs<\/strong>: \u30ea\u30bd\u30fc\u30b9\u69cb\u6210\u3084\u30c7\u30fc\u30bf\u306e\u8aad\u307f\u66f8\u304d\u30a2\u30af\u30bb\u30b9\u306e\u30ed\u30b0(\u8981\u8a2d\u5b9a)<\/li>\n<li data-line=\"583\" class=\"code-line\">\n<strong>System Event audit logs<\/strong>: \u30ea\u30bd\u30fc\u30b9\u69cb\u6210\u3092\u5909\u66f4\u3059\u308b Google Cloud \u30b7\u30b9\u30c6\u30e0\u306b\u3088\u3063\u3066\u66f8\u304d\u8fbc\u307e\u308c\u308b\u30ed\u30b0(\u30c7\u30d5\u30a9\u30eb\u30c8\u6709\u52b9)<\/li>\n<li data-line=\"584\" class=\"code-line\">\n<strong>Policy Denied audit logs<\/strong>: \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30dd\u30ea\u30b7\u30fc\u9055\u53cd\u3092\u7406\u7531\u306bGoogle Cloud \u30b5\u30fc\u30d3\u30b9\u304c\u30e6\u30fc\u30b6\u30fc\u307e\u305f\u306f\u30b5\u30fc\u30d3\u30b9 \u30a2\u30ab\u30a6\u30f3\u30c8\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u62d2\u5426\u3057\u305f\u3068\u304d\u306b\u66f8\u304d\u8fbc\u307e\u308c\u308b\u30ed\u30b0(\u30c7\u30d5\u30a9\u30eb\u30c8\u6709\u52b9)<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__241c1f6559191\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__241c1f6559191\" data-content=\"https%3A%2F%2Fcloud.google.com%2Flogging%2Fdocs%2Faudit%3Fhl%3Dja%23types\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"588\" class=\"code-line\"\/>\n<h4 id=\"audit-manager\" data-line=\"589\" class=\"code-line\">\n Audit Manager<\/h4>\n<p data-line=\"590\" class=\"code-line\">Audit Manager \u306f\u3001\u7d44\u7e54\u306e\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u8981\u4ef6\u306b\u57fa\u3065\u3044\u3066\u5404\u7a2e\u30ea\u30bd\u30fc\u30b9\u306e\u8a2d\u5b9a\u3092\u76e3\u67fb\u3057\u3001\u30ec\u30dd\u30fc\u30c8\u751f\u6210\u3092\u81ea\u52d5\u5316\u3059\u308b\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002<br \/>\u81ea\u52d5\u3067\u30ef\u30fc\u30af\u30ed\u30fc\u30c9\u3092\u8a55\u4fa1\u3057\u3001PCI DSS\u3001CIS Controls\u3001ISO 27001:2022 \u306a\u3069\u306e\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u57fa\u6e96\u3092\u6e80\u305f\u3057\u3066\u3044\u308b\u3053\u3068\u306e\u691c\u8a3c\u3084\u3001\u30e6\u30fc\u30b6\u30fc\u72ec\u81ea\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u57fa\u6e96\u3092\u6e80\u305f\u3057\u3066\u3044\u308b\u3053\u3068\u306e\u691c\u8a3c\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__db8a9381fa7b9\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__db8a9381fa7b9\" data-content=\"https%3A%2F%2Fcloud.google.com%2Faudit-manager%2Fdocs%2Foverview\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"595\" class=\"code-line\"\/>\n<h4 id=\"bigquery\" data-line=\"597\" class=\"code-line\">\n BigQuery<\/h4>\n<p data-line=\"598\" class=\"code-line\">SecOps \u306e\u30c7\u30fc\u30bf \u30a8\u30af\u30b9\u30dd\u30fc\u30c8\u5148\u3068\u3057\u3066 BigQuery \u30c7\u30fc\u30bf\u30bb\u30c3\u30c8\u3092\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002(Enterprise Plus \u30c6\u30a3\u30a2\u306e\u307f)<br \/>UDM \u30ec\u30b3\u30fc\u30c9\u3084\u3001\u30d5\u30a9\u30ef\u30fc\u30c0\u30fc\u306e\u7d71\u8a08\u60c5\u5831\u3001\u30a8\u30f3\u30c6\u30a3\u30c6\u30a3\u306b\u95a2\u3059\u308b\u60c5\u5831\u306a\u3069\u3092\u4fdd\u5b58\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__cdabd6647a4af\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__cdabd6647a4af\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Freports%2Foverview-chronicle-bigquery%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<hr data-line=\"603\" class=\"code-line\"\/>\n<h4 id=\"%E6%A8%A9%E9%99%90%E7%AE%A1%E7%90%86\" data-line=\"605\" class=\"code-line\">\n \u6a29\u9650\u7ba1\u7406<\/h4>\n<p data-line=\"606\" class=\"code-line\">SecOps \u7528\u306e IAM \u30ed\u30fc\u30eb\u3068\u3001SecOps \u7279\u6709\u306e\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u306b\u3064\u3044\u3066\u306f\u51fa\u984c\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u305f\u3081\u6291\u3048\u3066\u304a\u304d\u307e\u3057\u3087\u3046\u3002<\/p>\n<h5 data-line=\"608\" class=\"code-line\">SecOps \u306e\u4e8b\u524d\u5b9a\u7fa9\u30ed\u30fc\u30eb\u3068\u6a29\u9650<\/h5>\n<p data-line=\"609\" class=\"code-line\">\u30c0\u30c3\u30b7\u30e5\u30dc\u30fc\u30c9\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3084\u3001\u30d1\u30fc\u30b5\u30fc\u7ba1\u7406 UI \u306a\u3069\u3078\u306e\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u3092\u3057\u305f\u3044\u5834\u5408\u3001Google SecOps \u7528\u306e Google Cloud \u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e IAM \u3067\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u3092\u884c\u3044\u307e\u3059\u3002<\/p>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__80289d2c13a7d\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__80289d2c13a7d\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fonboard%2Fconfigure-feature-access%3Fhl%3Dja%23concepts\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__3a8522ee0c9e8\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__3a8522ee0c9e8\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fiam%2Fdocs%2Froles-permissions%2Fchronicle\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"614\" class=\"code-line\">Workforce Identity Federation<\/h5>\n<p data-line=\"615\" class=\"code-line\">Google SecOps \u306e\u8a8d\u8a3c\u306b\u7d44\u7e54\u306e Cloud Identity \u3084 Google Workspace \u4ee5\u5916\u306e\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u30fc\u306e IdP \u3092\u5229\u7528\u3057\u305f\u3044\u5834\u5408\u3001Workforce Identity Federation \u3092\u5229\u7528\u3057\u307e\u3059\u3002<\/p>\n<p data-line=\"617\" class=\"code-line\"><strong>\u8a2d\u5b9a\u65b9\u6cd5<\/strong><\/p>\n<ol data-line=\"618\" class=\"code-line\">\n<li data-line=\"618\" class=\"code-line\">Identity Provider(IdP) \u306e\u6e96\u5099: \u30e6\u30fc\u30b6\u30fc\u8a8d\u8a3c\u3001\u30e6\u30fc\u30b6\u30fc \u30b0\u30eb\u30fc\u30d7\u306e\u5b9a\u7fa9\u3001SAML 2.0 \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u305f\u3081\u306b\u3001Okta\u3001Entra ID \u306a\u3069\u306e IdP \u3092\u5229\u7528\u3059\u308b\u3002<\/li>\n<li data-line=\"619\" class=\"code-line\">Cloud IAM Workforce Identity Federation \u306e\u8a2d\u5b9a: IdP \u3068 Google Cloud \u3092\u9023\u643a\u3055\u305b\u308b\u305f\u3081\u306e Workforce Identity Pool \u3068 Workforce Identity Provider \u3092 Organization \u30ec\u30d9\u30eb\u3067\u8a2d\u5b9a\u3002<\/li>\n<li data-line=\"620\" class=\"code-line\">Cloud IAM \u30dd\u30ea\u30b7\u30fc\u306e\u4f5c\u6210: IdP \u3067\u5b9a\u7fa9\u3055\u308c\u305f\u30e6\u30fc\u30b6\u30fc \u30b0\u30eb\u30fc\u30d7\u3068 SecOps \u306e IAM \u30ed\u30fc\u30eb(\u5f79\u5272)\u3092\u7d10\u4ed8\u3051\u308b\u30dd\u30ea\u30b7\u30fc\u3092\u3001SecOps \u306b\u7d10\u4ed8\u3051\u3089\u308c\u305f Google Cloud \u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u5185\u306b\u8a2d\u5b9a\u3002<\/li>\n<li data-line=\"621\" class=\"code-line\">SecOps \u30a2\u30af\u30bb\u30b9\u7528\u306e\u7ba1\u7406\u8005\u30b0\u30eb\u30fc\u30d7\u306e\u4f5c\u6210\u3084\u3001SAML \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u4f5c\u6210\u3001SAML \u5c5e\u6027(groups, first name, last name, email \u306a\u3069)\u306e\u30de\u30c3\u30d4\u30f3\u30b0\u3092\u884c\u3046\u3002<\/li>\n<\/ol>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__c64efcf9c63cc\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__c64efcf9c63cc\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fonboard%2Fconfigure-authentication%3Fhl%3Dja\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><br \/>\n<span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__f19cbe1aae3cb\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__f19cbe1aae3cb\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fsoar%2Fadmin-tasks%2Fuser-secops%2Fmap-users-in-the-secops-platform\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h5 data-line=\"626\" class=\"code-line\">\u30c7\u30fc\u30bf RBAC \u3068\u6a5f\u80fd RBAC \u306e\u9055\u3044<\/h5>\n<p data-line=\"627\" class=\"code-line\">Google SecOps \u306b\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u30ed\u30fc\u30eb\u306b\u57fa\u3065\u3044\u3066\u30c7\u30fc\u30bf\u3092\u8868\u793a\u3001\u7de8\u96c6\u3001\u524a\u9664\u3067\u304d\u308b\u304b\u3069\u3046\u304b\u3092\u5236\u5fa1\u3059\u308b\u30c7\u30fc\u30bf RBAC \u3068\u3001\u30c0\u30c3\u30b7\u30e5\u30dc\u30fc\u30c9\u306a\u3069\u306e\u7279\u5b9a\u306e\u6a5f\u80fd\u3078\u306e\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u3092\u884c\u3046\u3001\u6a5f\u80fd RBAC \u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ul data-line=\"628\" class=\"code-line\">\n<li data-line=\"628\" class=\"code-line\">\n<strong>\u30c7\u30fc\u30bf RBAC<\/strong>: \u7279\u5b9a\u306e\u30c7\u30fc\u30bf\u3084\u60c5\u5831\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5236\u5fa1<\/li>\n<li data-line=\"629\" class=\"code-line\">\n<strong>\u6a5f\u80fd RBAC<\/strong>: \u7279\u5b9a\u306e\u6a5f\u80fd\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5236\u5fa1<\/li>\n<\/ul>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__9448c3473534e\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__9448c3473534e\" data-content=\"https%3A%2F%2Fcloud.google.com%2Fchronicle%2Fdocs%2Fadministration%2Fdatarbac-overview%3Fhl%3Dja%23difference-dataRBAC-feature-RBAC\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h2 id=\"%E8%A9%A6%E9%A8%93%E6%BA%96%E5%82%99\" data-line=\"633\" class=\"code-line\">\n \u8a66\u9a13\u6e96\u5099<\/h2>\n<h3 id=\"%E5%85%88%E3%81%AB%E5%8F%96%E5%BE%97%E3%81%97%E3%81%A6%E3%81%8A%E3%81%8F%E3%81%B9%E3%81%8D%E8%B3%87%E6%A0%BC\" data-line=\"634\" class=\"code-line\">\n \u5148\u306b\u53d6\u5f97\u3057\u3066\u304a\u304f\u3079\u304d\u8cc7\u683c<\/h3>\n<p data-line=\"635\" class=\"code-line\">\u5192\u982d\u3067\u3082\u8ff0\u3079\u305f\u3068\u304a\u308a\u3001\u4ee5\u4e0b\u306e\u8cc7\u683c\u306b\u3064\u3044\u3066\u306f\u5fc5\u9808\u77e5\u8b58\u3068\u8a00\u3048\u308b\u307b\u3069\u57fa\u790e\u7684\u306a\u3082\u306e\u3067\u3059\u3002<br \/>\u307e\u3060\u53d6\u5f97\u3057\u3066\u3044\u306a\u3044\u65b9\u306f\u307e\u305a\u306f\u3053\u3061\u3089\u3092\u53d6\u5f97\u3057\u3066 Google Cloud \u306e\u57fa\u790e\u3092\u5b66\u3073\u3001\u305d\u306e\u3046\u3048\u3067\u5fdc\u7528\u3068\u3057\u3066\u672c\u8a66\u9a13\u306b\u30c1\u30e3\u30ec\u30f3\u30b8\u3059\u308b\u3053\u3068\u3092\u5f37\u304f\u63a8\u5968\u3057\u307e\u3059\u3002<\/p>\n<ul data-line=\"637\" class=\"code-line\">\n<li data-line=\"637\" class=\"code-line\">Professional Cloud Security Engineer(PCSE)<\/li>\n<li data-line=\"638\" class=\"code-line\">Associate Cloud Engineer(ACE)<\/li>\n<\/ul>\n<h3 id=\"%E6%A8%A1%E6%93%AC%E8%A9%A6%E9%A8%93\" data-line=\"640\" class=\"code-line\">\n \u6a21\u64ec\u8a66\u9a13<\/h3>\n<p data-line=\"641\" class=\"code-line\">\u516c\u5f0f\u6848\u5185\u306b\u3082\u3042\u308b\u901a\u308a\u3001\u6a21\u64ec\u8a66\u9a13\u3092\u53d7\u9a13\u3057\u3066\u3054\u81ea\u8eab\u306e\u7406\u89e3\u5ea6\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\u307f\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\u5fc5\u305a\u3057\u3082\u6a21\u64ec\u8a66\u9a13\u306e\u50be\u5411\u3084\u554f\u984c\u305d\u306e\u3082\u306e\u304c\u305d\u3063\u304f\u308a\u51fa\u984c\u3055\u308c\u308b\u308f\u3051\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u304c\u3001\u3042\u304f\u307e\u3067\u53c2\u8003\u5024\u3068\u3057\u3066\u7406\u89e3\u5ea6\u3092\u77e5\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<br \/>(\u3053\u3053\u3067\u70b9\u6570\u304c\u53d6\u308c\u306a\u304f\u3066\u3082\u843d\u3061\u8fbc\u3080\u307b\u3069\u306e\u3082\u306e\u3067\u306f\u3042\u308a\u307e\u305b\u3093)<\/p>\n<blockquote data-line=\"645\" class=\"code-line\">\n<p data-line=\"645\" class=\"code-line\"><a target=\"_blank\" href=\"https:\/\/docs.google.com\/forms\/d\/e\/1FAIpQLScryxTOcaqWaPwxsQ-yjq29xRpYGpsAdy9L0XtIXtZy0s3miQ\/viewform\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">\u6a21\u64ec\u8a66\u9a13<\/a>\u3092\u53d7\u3051\u3066\u3001Security Operations Engineer \u8a66\u9a13\u3067\u51fa\u984c\u3055\u308c\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u8cea\u554f\u306e\u5f62\u5f0f\u3068\u5185\u5bb9\u3092\u628a\u63e1\u3057\u307e\u3059\u3002<\/p>\n<\/blockquote>\n<p><span class=\"embed-block zenn-embedded zenn-embedded-card\"><iframe id=\"zenn-embedded__d936b779c5f1d\" src=\"https:\/\/embed.zenn.studio\/card#zenn-embedded__d936b779c5f1d\" data-content=\"https%3A%2F%2Fdocs.google.com%2Fforms%2Fd%2Fe%2F1FAIpQLScryxTOcaqWaPwxsQ-yjq29xRpYGpsAdy9L0XtIXtZy0s3miQ%2Fviewform\" frameborder=\"0\" scrolling=\"no\" loading=\"lazy\"><\/iframe><\/span><\/p>\n<h3 id=\"%E8%A9%A6%E9%A8%93%E7%94%B3%E3%81%97%E8%BE%BC%E3%81%BF\" data-line=\"649\" class=\"code-line\">\n \u8a66\u9a13\u7533\u3057\u8fbc\u307f<\/h3>\n<p data-line=\"650\" class=\"code-line\">\u3053\u3053\u307e\u3067\u304d\u305f\u3089\u8a66\u9a13\u3092\u7533\u3057\u8fbc\u3080\u3060\u3051\u3067\u3059\u3002<br \/>Webassessor \u306b\u3066\u4efb\u610f\u306e\u65e5\u6642\u3067\u53d7\u9a13\u7533\u3057\u8fbc\u307f\u3092\u3057\u3001\u5f53\u65e5\u53d7\u9a13\u3092\u3059\u308c\u3070\u5b8c\u4e86\u3067\u3059\u3002<br \/>\u8cc7\u683c\u8a66\u9a13\u3042\u308b\u3042\u308b\u3067\u3059\u304c\u3001\u53d7\u9a13\u7533\u3057\u8fbc\u307f\u3092\u3059\u308b\u307e\u3067\u306b\u81ea\u3089\u3092\u596e\u3044\u7acb\u305f\u305b\u308b\u306e\u304c 1 \u756a\u306e\u96e3\u95a2\u3067\u3059\u3002<\/p>\n<h3 id=\"%E7%B5%90%E6%9E%9C%E5%8F%97%E9%A0%98\" data-line=\"654\" class=\"code-line\">\n \u7d50\u679c\u53d7\u9818<\/h3>\n<p data-line=\"655\" class=\"code-line\">\u5408\u683c\u3059\u308b\u3068\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30e1\u30fc\u30eb\u304c\u5c4a\u304d\u307e\u3059\u3002<br \/><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/zenn\/image\/fetch\/s--_CEu570O--\/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_1200\/https:\/\/storage.googleapis.com\/zenn-user-upload\/deployed-images\/9113fd4550df8d852a3648bb.png%3Fsha%3Db42da7413e1ce957eddcfb0e1c694dcd6cc133d5\" alt=\"pse_successfull_mail_noti\" class=\"md-img\" loading=\"lazy\"\/><br \/><em>SS:\u5408\u683c\u901a\u77e5<\/em><\/p>\n<h2 id=\"%E3%81%8A%E3%82%8F%E3%82%8A%E3%81%AB\" data-line=\"659\" class=\"code-line\">\n \u304a\u308f\u308a\u306b<\/h2>\n<h3 id=\"%E3%83%99%E3%83%BC%E3%82%BF%E7%89%88%E3%81%AE%E8%A9%A6%E9%A8%93%E3%82%92%E5%8F%97%E9%A8%93%E3%81%97%E3%81%9F%E6%84%9F%E6%83%B3-(2025%2F08)\" data-line=\"661\" class=\"code-line\">\n \u30d9\u30fc\u30bf\u7248\u306e\u8a66\u9a13\u3092\u53d7\u9a13\u3057\u305f\u611f\u60f3 (2025\/08)<\/h3>\n<p data-line=\"662\" class=\"code-line\">Google SecOps \u3092\u5168\u304f\u89e6\u3063\u305f\u3053\u3068\u304c\u306a\u3044\u65b9\u306b\u3068\u3063\u3066\u306f\u76f8\u5f53\u96e3\u6613\u5ea6\u304c\u9ad8\u304f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u904b\u7528\u306b\u3064\u3044\u3066\u306e<strong>\u5b9f\u8df5\u7684\u306a\u5224\u65ad\u529b<\/strong>\u304c\u554f\u308f\u308c\u308b\u8a66\u9a13\u3067\u3059\u3002<br \/>\u300c\u306a\u305c\u305d\u306e\u9078\u629e\u80a2\u304c\u6700\u9069\u306a\u306e\u304b\u300d\u306e\u7406\u7531\u3092\u6df1\u304f\u7406\u89e3\u3057\u3066\u3044\u306a\u3044\u3068\u56de\u7b54\u3067\u304d\u306a\u3044\u554f\u984c\u304c\u591a\u304b\u3063\u305f\u5370\u8c61\u3067\u3059\u3002<br \/>\u4f8b\u3048\u3070\u3001\u691c\u51fa\u30eb\u30fc\u30eb\u306e YARA-L \u8a00\u8a9e\u306e\u69cb\u6587\u3084\u9069\u5207\u306a UDM \u30d5\u30a3\u30fc\u30eb\u30c9\u306e\u9078\u629e\u3001SOAR Playbook \u306e\u8a2d\u8a08\u5224\u65ad\u306a\u3069\u3067\u3059\u3002<\/p>\n<p data-line=\"666\" class=\"code-line\">\u4e00\u65b9\u3067\u3001Google SecOps \u306e\u57fa\u672c\u6982\u5ff5\u3092\u3057\u3063\u304b\u308a\u7406\u89e3\u3057\u3001Google SecOps \u306e\u904b\u7528\u306b\u6163\u308c\u89aa\u3057\u3093\u3067\u3044\u308c\u3070\u3001\u6c7a\u3057\u3066\u624b\u306e\u5c4a\u304b\u306a\u3044\u8a66\u9a13\u3067\u306f\u306a\u3044\u3068\u601d\u3044\u307e\u3059\u3002<br \/>\u305d\u306e\u305f\u3081\u3001\u30c7\u30e2\u74b0\u5883\u3067\u3082\u826f\u3044\u306e\u3067 Google SecOps \u3092\u89e6\u3063\u3066\u3044\u305f\u3060\u304f\u3053\u3068\u3092\u304a\u3059\u3059\u3081\u3057\u307e\u3059\u3002<\/p>\n<h3 id=\"%E3%81%BE%E3%81%A8%E3%82%81\" data-line=\"669\" class=\"code-line\">\n \u307e\u3068\u3081<\/h3>\n<p data-line=\"670\" class=\"code-line\">\u6700\u5f8c\u307e\u3067\u8aad\u3093\u3067\u3044\u305f\u3060\u304d\u3042\u308a\u304c\u3068\u3046\u3054\u3056\u3044\u307e\u3059\u3002<br \/>\u3053\u3053\u307e\u3067\u8aad\u3093\u3067\u7406\u89e3\u3092\u6df1\u3081\u308b\u3053\u3068\u304c\u3067\u304d\u308c\u3070\u3001\u5408\u683c\u306b\u5fc5\u8981\u306a\u77e5\u8b58\u306b\u3064\u3044\u3066\u306f\u5341\u5206\u304a\u6301\u3061\u306e\u306f\u305a\u3067\u3059\u3002<br \/>\u3088\u3044\u7d50\u679c\u3092\u8fce\u3048\u3089\u308c\u308b\u3053\u3068\u3092\u7948\u308a\u307e\u3059\u3002<\/p>\n<p data-line=\"674\" class=\"code-line\">\u307e\u305f\u3001Google Cloud \u8a8d\u5b9a\u8a66\u9a13\u306f\u968f\u6642\u5185\u5bb9\u304c\u66f4\u65b0\u3055\u308c\u308b\u305f\u3081\u3001\u3053\u306e\u8a18\u4e8b\u3092\u95b2\u89a7\u3055\u308c\u305f\u65b9\u306f\u53ef\u80fd\u306a\u9650\u308a\u304a\u65e9\u3081\u306e\u53d7\u9a13\u3092\u63a8\u5968\u3057\u307e\u3059\u3002<\/p>\n<\/div>\n\n<br \/><a href=\"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe\">\u5143\u306e\u8a18\u4e8b\u3092\u78ba\u8a8d\u3059\u308b <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\u3053\u3093\u306b\u3061\u306f\u3001\u30af\u30e9\u30a6\u30c9\u30a8\u30fc\u30b9\u306e\u5c0f\u7530\u3067\u3059\u3002 2025 \u5e74 9 \u6708 16 \u65e5\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f Google Cloud \u306e\u6700\u65b0\u8a8d\u5b9a\u8cc7\u683c\u3067\u3042\u308b Professional Security Operations Engineer  [&hellip;]","protected":false},"author":1,"featured_media":6256,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-6255","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-company-tec"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025 - \u30dd\u30b1\u30b3\u30f3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025 - \u30dd\u30b1\u30b3\u30f3\" \/>\n<meta property=\"og:description\" content=\"\u3053\u3093\u306b\u3061\u306f\u3001\u30af\u30e9\u30a6\u30c9\u30a8\u30fc\u30b9\u306e\u5c0f\u7530\u3067\u3059\u3002 2025 \u5e74 9 \u6708 16 \u65e5\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f Google Cloud \u306e\u6700\u65b0\u8a8d\u5b9a\u8cc7\u683c\u3067\u3042\u308b Professional Security Operations Engineer [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe\" \/>\n<meta property=\"og:site_name\" content=\"\u30dd\u30b1\u30b3\u30f3\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-20T11:20:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/09\/1758367212_og-base-w1200-v2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"info@pokecon.jp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u57f7\u7b46\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"info@pokecon.jp\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"4\u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/6255\\\/\"},\"author\":{\"name\":\"info@pokecon.jp\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#\\\/schema\\\/person\\\/16c9f07b1ba984d165d9aee259bda997\"},\"headline\":\"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025\",\"datePublished\":\"2025-09-20T11:20:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/6255\\\/\"},\"wordCount\":758,\"image\":{\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/1758367212_og-base-w1200-v2.png\",\"articleSection\":[\"\u4f01\u696d\u30c6\u30c3\u30af\"],\"inLanguage\":\"ja\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/6255\\\/\",\"url\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe\",\"name\":\"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025 - \u30dd\u30b1\u30b3\u30f3\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/1758367212_og-base-w1200-v2.png\",\"datePublished\":\"2025-09-20T11:20:13+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#\\\/schema\\\/person\\\/16c9f07b1ba984d165d9aee259bda997\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#breadcrumb\"},\"inLanguage\":\"ja\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#primaryimage\",\"url\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/1758367212_og-base-w1200-v2.png\",\"contentUrl\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/1758367212_og-base-w1200-v2.png\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zenn.dev\\\/cloud_ace\\\/articles\\\/howtoget-certified-psoe#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u30db\u30fc\u30e0\",\"item\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#website\",\"url\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/\",\"name\":\"\u30dd\u30b1\u30b3\u30f3\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ja\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#\\\/schema\\\/person\\\/16c9f07b1ba984d165d9aee259bda997\",\"name\":\"info@pokecon.jp\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g\",\"caption\":\"info@pokecon.jp\"},\"url\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/author\\\/infopokecon-jp\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025 - \u30dd\u30b1\u30b3\u30f3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe","og_locale":"ja_JP","og_type":"article","og_title":"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025 - \u30dd\u30b1\u30b3\u30f3","og_description":"\u3053\u3093\u306b\u3061\u306f\u3001\u30af\u30e9\u30a6\u30c9\u30a8\u30fc\u30b9\u306e\u5c0f\u7530\u3067\u3059\u3002 2025 \u5e74 9 \u6708 16 \u65e5\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f Google Cloud \u306e\u6700\u65b0\u8a8d\u5b9a\u8cc7\u683c\u3067\u3042\u308b Professional Security Operations Engineer [&hellip;]","og_url":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe","og_site_name":"\u30dd\u30b1\u30b3\u30f3","article_published_time":"2025-09-20T11:20:13+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/09\/1758367212_og-base-w1200-v2.png","type":"image\/png"}],"author":"info@pokecon.jp","twitter_card":"summary_large_image","twitter_misc":{"\u57f7\u7b46\u8005":"info@pokecon.jp","\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593":"4\u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#article","isPartOf":{"@id":"https:\/\/pokecon.jp\/job\/6255\/"},"author":{"name":"info@pokecon.jp","@id":"https:\/\/pokecon.jp\/job\/#\/schema\/person\/16c9f07b1ba984d165d9aee259bda997"},"headline":"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025","datePublished":"2025-09-20T11:20:13+00:00","mainEntityOfPage":{"@id":"https:\/\/pokecon.jp\/job\/6255\/"},"wordCount":758,"image":{"@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#primaryimage"},"thumbnailUrl":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/09\/1758367212_og-base-w1200-v2.png","articleSection":["\u4f01\u696d\u30c6\u30c3\u30af"],"inLanguage":"ja"},{"@type":"WebPage","@id":"https:\/\/pokecon.jp\/job\/6255\/","url":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe","name":"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025 - \u30dd\u30b1\u30b3\u30f3","isPartOf":{"@id":"https:\/\/pokecon.jp\/job\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#primaryimage"},"image":{"@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#primaryimage"},"thumbnailUrl":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/09\/1758367212_og-base-w1200-v2.png","datePublished":"2025-09-20T11:20:13+00:00","author":{"@id":"https:\/\/pokecon.jp\/job\/#\/schema\/person\/16c9f07b1ba984d165d9aee259bda997"},"breadcrumb":{"@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#primaryimage","url":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/09\/1758367212_og-base-w1200-v2.png","contentUrl":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/09\/1758367212_og-base-w1200-v2.png","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/zenn.dev\/cloud_ace\/articles\/howtoget-certified-psoe#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u30db\u30fc\u30e0","item":"https:\/\/pokecon.jp\/job\/"},{"@type":"ListItem","position":2,"name":"Professional Security Operations Engineer \u8a66\u9a13 \u5b8c\u5168\u653b\u7565\u30ac\u30a4\u30c9 2025"}]},{"@type":"WebSite","@id":"https:\/\/pokecon.jp\/job\/#website","url":"https:\/\/pokecon.jp\/job\/","name":"\u30dd\u30b1\u30b3\u30f3","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/pokecon.jp\/job\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/pokecon.jp\/job\/#\/schema\/person\/16c9f07b1ba984d165d9aee259bda997","name":"info@pokecon.jp","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/secure.gravatar.com\/avatar\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g","caption":"info@pokecon.jp"},"url":"https:\/\/pokecon.jp\/job\/author\/infopokecon-jp\/"}]}},"_links":{"self":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts\/6255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/comments?post=6255"}],"version-history":[{"count":1,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts\/6255\/revisions"}],"predecessor-version":[{"id":6257,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts\/6255\/revisions\/6257"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/media\/6256"}],"wp:attachment":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/media?parent=6255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/categories?post=6255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/tags?post=6255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}