Skip to content
Notifications
Clear all

Just built a workflow to auto-enrich alerts with vulnerability data.

1 Posts
1 Users
0 Reactions
42 Views
(@crm_hopper_2028)
Honorable Member
Joined: 5 months ago
Posts: 354
Topic starter   [#15092]

Okay, so I've been using Chronicle for about six months now, after migrating from a Splunk-heavy setup at my last gig. The out-of-the-box alerting is decent, but I kept hitting a wall: I'd get a detection alert on an asset, but then I'd have to manually cross-reference it with our vuln scanner to see if it was actually exploitable. Too much context switching.

I finally carved out time to build an automated enrichment workflow, and it's working way better than I expected. Here's the basic flow:

* Chronicle detection rule fires on a suspicious process (e.g., `powershell.exe` with encoded args).
* That event includes the hostname or IP. I use a scheduled function to pull new alerts from the Chronicle API over the last 5 minutes.
* The function extracts the asset identifier, queries our external vulnerability management platform's API (Tenable.io in this case).
* It fetches the open CVEs for that asset and the overall vulnerability score.
* Then, it posts that vuln data back as a comment on the original Chronicle alert/UDM event.

The result? My SOC analysts now see a comment on the alert like:
```
Vuln Enrichment Result:
- Asset: SRV-WEB-01
- Last Scanned: 2024-10-26
- Overall VULN Score: 8.2
- Critical CVEs Present: CVE-2024-12345, CVE-2024-67890
```
This immediately tells them if they're looking at a truly vulnerable target or not. It's cut down initial triage time by a lot.

I'm curious how others are handling this. Has anyone else built something similar? I looked at SOAR options (like Chronicle's own built-in stuff), but found the API approach more flexible for our needs, especially since our vuln data lives outside Google Cloud.

Some things I'm still pondering:
* Is it better to post as a comment, or should I try to append the data to the UDM event itself (more complex)?
* Rate-limiting with the external vuln API – I had to add some throttling logic.
* Considering adding a second enrichment step to pull in asset owner/group from CMDB next.

Compared to doing similar in Splunk (where I used Phantom), this feels lighter weight, but the Chronicle API is definitely robust enough. The main hassle was getting the IAM permissions right between Chronicle, the cloud function, and the external API key management.


Still looking for the perfect one


   
Quote