Hey Google Cloud Security Community!
Whether you are a security engineer building custom parsers, a SOC analyst hunting threats, or a security leader keeping up with rapid product releases, staying ahead of the threat landscape requires continuous learning.
To help you stay sharp, informed, and ahead of the curve, we are thrilled to introduce a brand-new, centralized section in our community: The Weekly Brief!
🎯 What is "The Weekly Brief"?
The Weekly Brief is your structured, one-stop resource for technical guidance, product updates, and expert strategies across Google Security Operations (SecOps) and Google Threat Intelligence.
Instead of searching multiple documentation pages or release notes, you can tune in every week to get highly actionable, bite-sized updates directly from Google security experts and community leaders.
The Weekly Brief is organized into three specialized pillars:
📢 What's New in SecOps
Your weekly briefing on everything evolving across the Google SecOps ecosystem.
-
What you’ll get: Stay on top of the latest feature releases, API updates, integration highlights (including Wiz and AI advancements), and documentation refreshes.
-
Recent Highlight: We recently announced that the multi-event rules limit has increased to 200 for Enterprise and 400 for Enterprise+ customers, alongside highly anticipated previews for Case-Level Playbooks and Data RBAC using Scopes!
🛡️ #GoogleTIMondays
Start your week with bite-sized tips, platform overviews, and how-to guides for Google Threat Intelligence.
-
What you’ll get: Practical knowledge to help you master the platform, leverage Mandiant intelligence, and optimize your overall analyst workflows.
-
Recent Highlight: Our recent deep dive on Transforming Operational Intelligence showed how security teams can build machine learning-powered Threat Profiles to filter out generic threat noise, map active campaigns directly to a localized MITRE ATT&CK TTP heatmap, and automatically generate custom Indicator of Compromise (IOC) feeds.
💡 Tuesday's Tip of the Week
The ultimate weekly technical clinic written specifically for security engineers and SOC analysts.
-
What you’ll get: Step-by-step technical guides covering data onboarding, mapping to the Unified Data Model (UDM), troubleshooting ingestion pipelines with BindPlane, and writing custom CBN parsers.
-
Recent Highlight: Don't miss our tactical breakdown of "Finding and Fixing Unparsed Logs"—the silent failure of SIEM. We outline the step-by-step "Cut & Drop" method in the parser editor to quickly isolate broken logic blocks, and share how to configure alerts for sudden ingestion volume drops to keep your SOC resilient.
💎 Why You Should Subscribe
To make sure you get these updates the second they go live, we highly recommend subscribing to our three dedicated pages.
-
📢 What's New in SecOps: Subscribe to stay ahead of rapid platform evolution. You'll get instant alerts on new feature releases, API updates, AI and Wiz integration breakthroughs, and fresh documentation to keep your security stack fully optimized.
-
🛡️ #GoogleTIMondays: Subscribe to ground your team in Mandiant-grade intelligence. You'll receive actionable tutorials on building custom Threat Profiles, mapping active campaigns to MITRE ATT&CK, and streamlining analyst threat-hunting workflows.
-
💡 Tuesday's Tip of the Week: Subscribe to master the mechanics of SOC engineering. You'll get hands-on technical clinics covering features like UDM mapping, BindPlane ingestion troubleshooting, and custom parser writing to eliminate SIEM blind spots and maintain ingestion health, and more!
💬 We want to hear from you! What technical hurdles are you facing in your SOC this week? What parser, UDM, or threat intelligence topic or topic of your choice would you like us to break down in an upcoming #GoogleTIMondays or Tuesday's Tip?
Let us know in the comments below, and welcome to your new security routine!



