Hi everyone,
We are currently evaluating the Triage and Investigation Agent (TIN) in Google SecOps, but we haven't had the opportunity to test it in our environment yet.
We would mainly like to understand how well it works overall in a real SOC environment, and also how it performs with third-party security products such as Cortex XDR, CrowdStrike, Fortinet, etc.
For those already using it:
-
Overall, how has your experience with TIN been so far?
-
Does it genuinely help with triage and investigation, or is it still fairly limited?
-
How well does it investigate alerts coming from third-party products?
-
Does it understand and correlate the context properly once those logs are ingested into SecOps?
-
Have you tested it with Cortex XDR or similar EDR solutions?
-
Is the TP/FP verdict generally reliable, or do analysts still need to redo most of the investigation manually?
-
Does it work well with custom detections/YARA-L rules built on top of third-party data?
-
Are there any important limitations when the alert is not coming from Google's own security stack?
-
Has it actually reduced investigation time for your analysts?
We are considering a trial/PoC or potentially purchasing the capability, so any feedback on overall performance, investigation quality, third-party integrations, limitations and real SOC usage would be really useful.
Thanks!

