Author: Nolan Karpinski, Group Product Manager, Google Cloud Security
We are excited to share the latest leap forward in autonomous defense by announcing the Public Preview of the Detection Engineering agent in Google Security Operations.
Wondering if your organization is ready for the latest AI hack? Rather than entering into a marathon of drafting rules and hoping they trigger, the Detection Engineering agent brings a powerful new capability to security teams with the ability to safely simulate threat coverage at a moment's notice. Agentic AI makes a continuous detection-and-validation loop truly possible. The agent can generate realistic attack sequences and run them against your detection capabilities. This allows you to simulate a wide breadth of coverage and verify rule execution in production-safe environments, confirming your defenses stand strong before an actual attack occurs.
A Continuous and Autonomous Detection Lifecycle
Detection engineering is often constrained by a painful operational compromise: speed versus fidelity.
If you rush a rule into production to counter an active zero-day, you risk overwhelming analysts with false positives, skewing risk scores, and breaking dashboards. If you spend weeks carefully testing and tuning queries in staging labs, you leave your enterprise exposed during the adversary’s most lucrative exploitation window.
The Detection Engineering agent validates coverage while reducing the risks of testing in production. It can identify coverage gaps and create new detections for threat scenarios, reducing toil and transforming this manual craft into an automated science.
Key Features and Capabilities
-
Threat intelligence extraction in minutes: The Detection Engineering agent automatically extracts granular behavioral procedures and tactics from CTI reports emerging threat advisories to create structured Threat Detection Opportunities (TDOs).
-
Production-Safe Event Simulation: An embedded simulation harness generates synthetic, schema-valid Universal Data Model (UDM) events reflecting exact adversary procedures. Teams safely validate detection logic through their live ingestion pipeline without executing live malware.
-
Automated Coverage Evaluation: The agent runs simulated UDM events against BOTH Google SecOps Curated Detections (curated rules) and your existing customer-authored custom YARA-L rules to identify exactly which rules triggered and where gaps exist.
-
Detection Rule Generation: When gaps are found, the agent synthesizes and tunes production-ready YARA-L rules tailored to the specific missed behaviors.

Why This Matters for Your SOC
This launch addresses several critical challenges faced by modern SOCs. By accelerating the mean time to coverage, teams can drastically reduce turnaround times from a new zero-day advisory to active defense—moving from days to minutes. Organizations can also ensure a validated security posture by proactively testing all rules, to confirm they trigger successfully before an actual breach occurs. Additionally, strict telemetry isolation keeps simulation data hidden from daily analyst views, dashboards, and incident management systems. Finally, automated rule generation lowers the skill barrier by codifying complex threat logic, enabling analysts of all skill levels to author high-performance YARA-L rules.
Getting Started
The Public Preview is available for customers on the Google SecOps Enterprise and Enterprise Plus tiers.
Prerequisites and Activation
To begin using these features, administrators must enable the Preview Features opt-in setting within the Google SecOps console:
-
Navigate to Settings > Preview Features.
-
Toggle Detection Engineering Agent Features (detection_engineering_agent_enabled).
-
Toggle Event Simulation Enabled (ade_simsafe_detection_enabled).

Please note that access via the Google SecOps Remote Model Context Protocol (MCP) Server is required for full functionality.
Important Operational Guidance
As you explore these preview features, keep the following technical considerations in mind:
| Execution Window | End-to-end execution typically requires 15 to 30 minutes; ensure your AI harness timeouts are configured accordingly. |
| Input Quality | For best results, provide rich behavioral descriptions (TTPs) rather than simple atomic indicators like single IP addresses. |
| UDM Dependencies | Coverage evaluation depends on active UDM parsers for the log sources referenced in the threat reports. |
Looking Ahead
This Public Preview is just the beginning. Our roadmap includes integrating these capabilities into the new chat experience, enriching inputs with Google Threat Intelligence context, and expanding simulation realism to cover multi-stage, complex attack sequences.
For more detailed information, please refer to the Release Notes and Detection Engineering agent docs guide.
