Requirements for publishing use case

  • The simulation alerts in the use case are based on real alerts from a real product.
  • All entities are extracted when running the simulation alert in a clean environment.
  • All entities are extracted when running the real alert with the connector.
  • The playbook runs end to end without errors.
  • The final delivery is a ZIP file export that can be imported without errors into the Google Security Operations Marketplace.
  • When deployed, all the user has to do is configure the integrations to make the playbook run end to end with simulation alerts.