Google Security Operations
Integration Overview
Identify your service account email address




Grant IAM Access to Dropzone AI







Obtain Account Details






Cloud Identity Mapping
Enable Google SecOps
Dropzone Field
Source












Last updated
Was this helpful?
Google Security Operations is a SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.
Dropzone integrates with Google Security Operations to investigate different security alerts across many of Google's security products.
To enable these integrations you will perform the following actions:
Identify your service account address
Grant IAM access to the Dropzone service account
Obtain your Google Account Details
Complete Google Cloud Mapping
Enable the Alert and Data sources
Alternatively, Dropzone also supports Service Account Impersonation as a method of authentication. This allows an already-authenticated principal to temporarily act as a target service account and use its permissions, often by requesting short-lived credentials instead of downloading long-lived keys. See Google Cloud's documentation for further information.
If you choose to use Service Account Impersonation, be sure to grant (or ask your administrator to grant) the principal you're using the Service Account Token Creator role.
To obtain the email address of your Dropzone service account, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Library"
If you have previously integrated this application, click "Configured"

In the Search bar, search Google Security Operations, then click "Configure"

Copy the "SERVICE ACCOUNT EMAIL" field for use in the Google Console interface

Navigate to the Google Console page of the project your SecOps instance is in
In the upper left hand corner, open the navigation menu

Navigate to IAM & Admin > IAM

Under "View by principals," click "Grant Access"
To be able to complete this step, you will need the resourcemanager.projects.setIamPolicy permission.

Under "New principals," input the email address you copied earlier from the Dropzone UI "SERVICE ACCOUNT EMAIL"

Click "Select a role"

Search the "Chronicle API Viewer" role, then click it
If you want Dropzone to be able to edit Cases/Alerts after investigation (e.g. by changing stages, modifying priority, or adding comments) select the Chronicle API Editor role.

Click "Save"

To obtain your Instance Name, do the following:
Return to the Google Console page of the project your SecOps instance is in
In the upper left hand corner, open the navigation menu

Navigate to Security > Detection and Controls > Google SecOps

In the Google SecOps page, click the carrot next to "Instance Details"

Copy the Customer ID shown for use later in the Dropzone UI where it is called "Instance Name"

To obtain your Project ID, do the following:
In the upper left, click on the project icon

Using the search bar, locate the project your SecOps instance is in
Under "ID," copy the ID value shown for use later in the Dropzone UI where it is called "Project ID"

If you want Dropzone to be able to have SOAR access, (e.g. managing cases), you must map the service account to your platform's access control parameters. This will provide the service account with access to SOC Roles and Environments required to perform automated tasks or API operations.
To do Cloud Identity mapping, do the following:
As an admin, log into your Google SecOps instance
In the left sidebar, navigate to Settings > SOAR Settings
Navigate to Advanced > Group Mapping
Click "+ Add"
In the IDP/User group field, enter the full service account email address or the workload identity principle string
Assign the service account the appropriate SOC role and Environments
Dropzone needs read access to all security event data and case/alert content in your tenant, plus the ability to comment on, tag, and change the status of cases and alerts it has been given for investigation.
Click "Save"
To enable the Alert Source integration, you will need the following information:
Instance Name
The "Customer ID" value you copied earlier
Project ID
The "Project ID" value you copied earlier
Customer-Owned Service Account
The email of the service account Dropzone will be impersonating
The Customer-Owned Service Account is only necessary if you wish to use Service Account Impersonation as your authentication method.
To enable the Alert Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Library"
If you have previously integrated this application, click "Configured"

In the Search bar, search Google Security Operations, then click "Configure"

Under the Alert Source heading, input the Instance Name and Project ID
If you are using Service Account Impersonation, input the Customer-Owned Service Account value

To enable Dropzone to investigate alerts, check the box labeled "Enable alerts." If you wish to enable Dropzone to filter by priority, check the box labeled "Enable priority filtering," then check the priority levels you wish for Dropzone to ingest

To enable Dropzone to investigate cases, check the box labeled "Enable cases"
Input your SOAR API Key and SOAR Instance Hostname
Check the box labeled "Include Closed Cases" to include closed cases in Dropzone investigations

If you wish to only include certain stages in Dropzone investigation, check the box labeled "Enabled stage filtering," then check the stages you wish for Dropzone to ingest

If you wish to enable priority filtering, check the box labeled "Enable priority filtering," then check the priority levels you wish for Dropzone to ingest

If you wish to enable filtering by case title, check the box labeled "Enable case title filtering," then click "Add Item"
Input case titles individually by clicking "Add Item" for each one
Under "Filter Mode," select whether to include or exclude the cases matching the filters

If you wish to enrich Dropzone investigation with CrowdStrike Recon information, check the box labeled "Enable case enrichment options," then check the box labeled "Fetch Crowdstrike Recon notifications"

Input your desired Poll interval and lookback

If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
Contact your Dropzone AI support representative for more information about this feature

If you have any errors, engage your Dropzone AI support representative.
Last updated
Was this helpful?
Was this helpful?