John Stoner

Chauffeur for three hockey players | Reader of History and Non-Fiction | Principal Security Strategist @ Google Cloud

2024-02-07

After a January reset, we are back in a new location with more New to Chronicle goodness. Today, we are looking at how alerts and detections can be viewed in relation to its associated entities within the Alert Graph. The alert graph allows investigators to pivot across multiple alerts and entities to establish that larger picture while easily gathering context and drilling into entities to find additional supporting information. Check this out and much more at the Google Cloud hashtag#secops community website! googlecloudcommunity.com/gc/Co

2023-12-20

Today I'm going to wrap up our last New to Chronicle blog of the year and share the work we've been doing on getting community rules underway and looking ahead to next year! #secops chronicle.security/blog/posts/

2023-11-30

In this installment of the google Cloud New to Chronicle blog series, we take a look at saving, re-using, sharing and template-izing those well crafted searches for others in your organization to benefit from! #secops

chronicle.security/blog/posts/

2023-11-09

And now for the dramatic conclusion to our building our dashboard arc in the New to Chronicle series, here are tips on formatting and filtering to pass parameters into the dashboard. Then we cover how you can share your dashboards with your friends and neighbors! chronicle.security/blog/posts/ #secops #siem

2023-10-31

This is a bit delayed, but here is my talk from @sansforensics in Austin on logging and visibility around a Golden SAML attack and subsequent cloud activity in both Azure AD and O365. Big thanks to @heathermahalik, @PhilHagen and the team at SANS for giving me an opportunity to present! youtube.com/watch?v=VpgiwpySNu

2023-10-12

In our latest New to Chronicle blog, we continue to explore building dashboards in Chronicle. This time we add customization to create custom fields, aggregations and calculations! chronicle.security/blog/posts/

2023-09-29

Building dashboards in Google Chronicle and you are looking for a time chart? We’ve got you covered. Here’s my latest including an intro of the pivot function! chronicle.security/blog/posts/

2023-09-18

In case you missed it, here’s my latest New to Chronicle highlights building a tabular tile in your Chronicle dashboards. If you haven't tried it yet, you really should! chronicle.security/blog/posts/

2023-08-30

I know you want to hear about @googlecloud goodness like Duet AI for @chroniclesec and @Mandiant this week but I’ve posted my latest New to Chronicle blog in case you are getting started building dashboard tiles! chronicle.security/blog/posts/

2023-08-23

Thanks to the fine folks at @Antisy_Training and @eanmeyer for MC-ing track two for Blue Team Summit. I hope everyone enjoyed it as much as I did and thanks for letting me come and speak!

2023-08-15

In our latest New to Chronicle we cover building rules to detect tor exit nodes and remote access tools with data sets that we provide in Chronicle! Learn how to build rules to take advantage of these feeds! @GoogleCloudTech chronicle.security/blog/posts/

2023-08-03

Our team at Chronicle partnered with Okta to collaborate and develop a set of YARA-L rules that Okta users can apply to their Chronicle instance. Check out our blog which contains links to rules, their blog and more! chronicle.security/blog/posts/

2023-07-27

We're back with part two of our New To Chronicle mailbag for July. Check it out for tips that will help your rule writing in YARA-L! #secops #detectionengineering chronicle.security/blog/posts/

2023-07-14

Looking forward to presenting at SANS DFIR in August. I promise I won’t present in hat and sunglasses! #dfir #SANSDFIR

2023-07-14

I've been writing the New to Chronicle blog series for nearly a year now and realized that we've never posted user questions, so this month will be user mail bag posts (two parts) that I hope you all find helpful! chronicle.security/blog/posts/ #siem #secops #chronicle

2023-06-22

I mentioned it before but tracking entities within your environment is not computationally trivial. Every ip, file hash and domain for prevalence is nothing to sneeze at. Now add first and last seen and add in your assets and users. Chronicle can handle these data loads easily and make this available for you to build detections with. Here's my latest. #secops chronicle.security/blog/posts/

2023-06-08

More goodness from Chronicle with the addition of Grouped Fields. Check out how Google Cloud has added the capability to search quickly and easily through UDM for IP addresses, domains, hashes and much much more! #secops
chronicle.security/blog/posts/

2023-05-25

Before heading out for the weekend, take a few minutes and check out part 2 on the new pivot capability that #chronicle has added! #googlecloud chronicle.security/blog/posts/

2023-05-12

Just in time for the weekend we have a new New to Chronicle post (new New?) around a new capability built into our UDM search called Pivot. No this has nothing to do with a sofa and a stairwell for those who used to watch Friends. This is part one of two but really good stuff being added to Google Chronicle to help analysts work with their data! #googlecloud #chronicle #secops #threathunting chronicle.security/blog/posts/

2023-04-25

Wouldn't it be interesting to understand the prevalence of a domain, a file hash or an ip address within your environment? Take a look at my latest in our New to Chronicle series on how we gather this data and how it can be used to build rules to identify low prevalence entities that could be pivots into additional hunting or investigation! Google Cloud #secops #threathunting

chronicle.security/blog/posts/

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst