Skip to main content

Announcing Public Preview of the Google Security Operations Threat Hunt Agent

  • August 13, 2026
  • 1 reply
  • 38 views

johnamurray
Staff

Author: John Murray, Senior Product Manager

 

Proactive threat hunting is an essential pillar of a mature security posture. Yet for most Security Operations Centers (SOCs), it remains an elusive goal. Translating high-level threat intelligence (such as a campaign report on a new threat actor) into tangible, cross-telemetry analysis is historically a manual, high-expertise task reserved for senior analysts. Due to the sheer complexity of manual log analysis across weeks of historical data, most SOCs remain purely reactive.

Today, we are excited to announce the SecOps Threat Hunt agent is now available in public preview.

The Threat Hunt agent is an autonomous AI-driven capability powered by Gemini, Google Threat Intelligence, Mandiant Frontline analyst insights and the MITRE ATT&CK® framework embedded directly within Google Security Operations. It transforms threat hunting from a time-consuming, manual process into a scalable, proactive, automated force multiplier. What used to take senior analysts hours or days of writing complex queries and piecing together disparate logs can now be completed autonomously by the agent in a fraction of the time.
 

Real-World Use Cases: Moving from Reactive to Proactive

The Threat Hunt agent is designed to streamline day-to-day operations by addressing critical, high-pressure scenarios that SOCs face every day. For instance, consider the common challenge of the "Executive Fire Drill" When leadership or your CISO reads about a high-profile, emerging threat campaign like "ClickFix Social Engineering" or a newly discovered zero-day vulnerability, their immediate question is almost always, "Are we affected?" Instead of pulling your most senior incident responders away from active investigations to manually comb through logs, analysts can now select the emerging campaign and launch an automated hunt. The Threat Hunt agent sweeps up to 30 days of historical telemetry across your entire environment and returns an explicit, evidence-backed verdict, delivering rapid and reliable assurance directly to leadership.

Another frequent scenario involves Targeted Intelligence Hunting. When fresh threat intelligence indicates that a specific actor such as FIN7 or a malware loader like FAKEUPDATES is actively targeting your industry, your SOC needs to move quickly. The Threat Hunt agent automatically maps the target threat to its corresponding Tactics, Techniques, and Procedures (TTPs), runs multi-stage investigations across your enterprise data, and isolates compromised hosts or command-line activity. Once complete, it populates all of its findings into a dedicated case in Case Management, allowing your team to instantly pivot to remediation.
 

Key Capabilities in Public Preview

The Threat Hunt agent generates a multi-step hunt plan, executes complex queries across UDM and other data sources, and synthesizes findings into a report.

The agent can be launched through the Detections > Emerging Threats tab, GTI drawers, or the MITRE ATT&CK Matrix drawer, and can target various categories including threat actors, campaigns, malware families, software tools and specific MITRE TTPs.
 

 

The hunt will run fully autonomously in the background for approximately 60-90 minutes, and after analyzing historical data up to 30 days, every hunt automatically spins up a dedicated tracking case in Case Management, prefixed with Threat Hunt for [Subject Name] and tagged with Threat Hunt for clear organization.
 


The agent delivers explicit verdicts accompanied by full transparency with step-by-step execution rationales, underlying YARA-L 2.0 query details, and extracted entity summaries (IPs, hostnames, command lines, and hashes).
 


How to Get Started

Public Preview of the Threat Hunt agent is available for Google Security Operations Enterprise Plus customers. Administrators can enable the Threat Hunt agent via the in-product Manage Preview Features settings page. (Please note: The agent relies on the New Case Management experience, which must be enabled. This is currently in Public Preview and available via the Preview Features Opt-In page.)
 


To get the most out of your Threat Hunt agent, we recommend deploying it in telemetry-rich environments with ample, high-density security logs (such as endpoint activity, process execution command lines, cloud audit logs, and network authentication events). Rich telemetry allows the agent’s AI planning engine to execute deep, multi-stage queries and extract the highest-fidelity forensic proof.

For more information, review  the Google Cloud SecOps Threat Hunt agent Docs page and the Google SecOps Preview Features Guide. As we approach general availability, please share your experience and suggestions in the comments section below.  

1 reply

thineth_dasun
Forum|alt.badge.img+6

 

Hi  ​@johnamurray ,

Thanks for sharing the preview details of the Threat Hunt agent. This is a powerful capability, but to get maximum value there are a few advanced considerations worth highlighting:

🔑 Why telemetry‑rich environments matter

  • Endpoint activity → Process execution, command lines, and registry changes provide granular forensic signals.

  • Cloud audit logs → IAM changes, API calls, and resource provisioning events enrich context for multi‑stage hunts.

  • Network authentication events → Kerberos, NTLM, and SAML flows help detect lateral movement and credential misuse.

🛠 Advanced deployment best practices

  1. Log normalization

    • Ensure logs are mapped into UDM consistently. Misaligned fields reduce the AI planner’s ability to correlate across sources.

  2. Data freshness

    • Stream logs in near real‑time. Stale telemetry weakens forensic proof and delays detection.

  3. Entity enrichment

    • Feed in CMDB, identity provider, and EDR context data via ImportEntities API to strengthen correlation.

  4. Query chaining

    • Use the agent’s AI planning engine to pivot across multiple log types (e.g., process → network → identity) for deep hunts.

⚠️ Considerations before GA

  • Performance trade‑offs → High‑density telemetry increases fidelity but also ingestion/storage costs.

  • Security of preview features → Monitor closely; preview agents may evolve rapidly before GA.

  • Feedback loop → Share anomalies, false positives, and usability notes back to the product team to shape GA readiness.

👉 In short: deploying the Threat Hunt agent in environments with rich, normalized, and fresh telemetry unlocks its full AI‑driven hunting capability. Combining endpoint, cloud, and identity data ensures multi‑stage queries produce high‑fidelity forensic proof.

Kind regards,