SpyCloud’s integration with Google SecOps (formerly Chronicle SOAR) allows security teams to incorporate SpyCloud’s high-fidelity identity exposure data into Google’s security orchestration workflows. By connecting to SpyCloud’s API, analysts can access recaptured breach and malware data within automated playbooks – enabling faster investigation, detection, and response to identity-driven threats such as account takeover and session hijacking.
BENEFITS
Accelerate Response Enrich alerts and automate response actions using SpyCloud breach and malware data.
Improve Triage Add context to identity-related alerts with recaptured underground data – including compromised usernames, passwords, and malware-infected device-level exposures.
Automate Identity Checks Query SpyCloud’s API as part of SOAR playbooks to identify exposed credentials tied to incidents, reducing manual steps and alert fatigue.
HOW IT WORKS
Analysts use Google SecOps to create or modify playbooks that include SpyCloud API calls.
When triggered by an alert, the playbook queries SpyCloud for exposure data using selectors like email or username.
SpyCloud returns breach details and exposure context, which can be used to enrich the incident, trigger user notifications, escalate investigations, or kick off credential reset workflows.
NEW RESEARCH: Over 2/3 of orgs had an identity event last year – NHIs were the top cause. Read on→