Learn about the latest news, product updates, and other events.
Recently active
Hi, Security Community!We’re happy to announce that Google has been named a Leader in the IDC MarketScape: Worldwide SIEM 2026 Vendor Assessment!According to the report, “Google operates one of the larger hyperscale infrastructure footprints in the technology industry; its security business sits within Google Cloud and draws on adjacent assets. The 2022 Mandiant acquisition added frontline research, a portfolio of services including incident response, MDR, consulting and advisory, and applied intelligence capabilities. These capabilities have been integrated across the portfolio. For example, Google Threat Intelligence (GTI) consolidates all threat research, including VirusTotal's crowdsourced intelligence.”The IDC MarketScape also noted, “Agentic capabilities, which use Google's Gemini, are central to Google SecOps. The Alert Triage and Investigation agent and Threat Intel agent entered public preview in late 2025 and reached general availability in 1Q26. Google SecOps was also among
Hello Community Members, We have noticed an increase in posts regarding Google Cloud/Firebase project suspensions (often due to suspected key misuse or account hijacking). We understand that these suspensions can lead to production outages, and waiting for an appeal to be processed can be timely for your business and customers. To help you get your project reinstated as smoothly and quickly as possible, we have compiled a list of Best Practices when working with the appeals team: 1. Submit a Comprehensive Initial AppealIncomplete appeals often require manual review or trigger automated emails asking for more information, which can significantly delay your reinstatement. To avoid this, ensure your very first appeal contains all necessary data.Based on our official Respond to Abuse and Misuse documentation, your appeal must contain:What caused the issue? The exact steps you have taken to resolve the issue (e.g., removing exposed credentials, rotating keys, moving secrets to Secret Manag
Hello, Security Community!We have some exciting news to share: Google has been named a Leader in the 2025 Gartner® Magic Quadrant™ for SIEM! In our second year of participation, we’ve been positioned in the Leaders quadrant, which can be attributed to our "Ability to Execute" and "Completeness of Vision." We're especially proud that Gartner recognized our vision as the furthest to the right among all vendors.Most importantly, none of this would be possible without your continued support and collaboration. You are at the heart of our innovation. Thank you for being a part of this journey!Access your complimentary copy of the report and read the full blog post. Source: The 2025 Gartner® Magic Quadrant™ for Security Information and Event Management, Andrew Davies, 8, October, 2025 GARTNER® is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates an
Hey Community!When it comes to building AI applications, the race to market often leaves security trying to catch up. But what if adhering to the right guardrails actually gave your development process a competitive boost?Our Mandiant offensive security teams are on the front lines stress-testing AI systems to understand their unique vulnerabilities. Recently, they conducted adversarial assessments on a pre-production banking chatbot. By uncovering an exposed API endpoint, our red team intercepted chat history data sent in easily modifiable JSON and injected fake "system" messages. The large language model, accepted this falsified history as fact, bypassed its primary instructions, and allowed the red team to make unauthorized account changes.The takeaway? Securing mere model prompts isn't enough. You have to secure the entire AI application.Based on these hands-on assessments, we've distilled our recent findings into five critical lessons to help you securely develop and deploy AI app
Hey Everyone!Welcome to the Google Cloud Security Community! We want to kick things off by getting to know each other better. This space is all about connecting, sharing, solving, and building the future of cloud security – and that journey starts with you!So, don't be shy! Drop a quick intro below and tell us:Who are you? (Your name, role, etc.) What's your cloud security superpower? (What area excites you most, or a cool project you're working on?) What are you hoping to learn or share here? (Let's help each other grow!)We're incredibly excited to learn from your unique experiences and build a vibrant hub where we can all protect, create, and innovate together.Can't wait to meet you all!Matt
Hey Community! I have some new updates for you! Get ready for an action-packed Google Cloud Next '25, April 9-11! We're thrilled to announce two hands-on Security Operations workshops sponsored by the Google Cloud Security Community. Check out the details and RSVP! These are in-person workshops at the event, so you'll need a Next '25 pass to attend. (Don't have one yet? Register for NEXT 25) But that's not all! We've also got a Google Threat Intelligence Capture the Flag and a hands-on Security Command Center workshop lined up. Check out all the exciting details below and RSVP to secure your spot! 👇 Here's the line up... Security Operations Workshops: The Visualizing Alerts will enhance your team's Google SecOps proficiency with our hands-on workshop. Learn to leverage the alert graph for streamlined triage, in-depth investigations, and optimized YARA-L rule modification. This hands-on session equips analysts with skills to efficiently manage alerts, improve detection accuracy,
Welcome to our quarterly look at the latest innovations within Google Security Operations. In Q1 2026, we focused on enhancing AI-driven automation, expanding our global footprint, and providing granular control over data management and compliance. The Agentic SOCAI remains a core strategic pillar, with several key updates reaching preview status to help analysts respond faster and more effectively. Agentic Automation (Public Preview):This enhancement facilitates the integration of AI-driven capabilities into both new and existing playbooks by merging AI agent steps with deterministic automation. This hybrid approach ensures analysts remain in control of critical actions while progressively adopting advanced AI. With this release, organizations can utilize the Triage and Investigation Agent, leveraging its outputs—such as verdict and confidence levels—within subsequent playbook steps to automate decision-making, remediation workflows, or alert closures. Learn more SecOps Labs for Enter
Create and Share Your Security Gemini Gems We're launching a new Community challenge, and this time you not only have a chance to win Google swag, but to also be featured on the Google Cloud Security podcast with Anton Chuvakin and Timothy Peacock. The goal is simple: create and share a Gemini Gem that streamlines security tasks and saves you time. How to Participate:We are looking for creativity and utility.1. Design a Gemini Gem that solves a specific security problem. Crucially, DO NOT put corporate sensitive data in your Gems! 2. Share your submission in the comments below or USE THIS FORM. Ensure your entry includes the following details: A link to your Gem. Learn about sharing Gems here. Who it is for (e.g., SOC analyst, CISO, Compliance Manager). A clear explanation of how to use it and the the value you derive from it (saves time, reduces risk, makes tasks easy, etc) 3. Determining the winner:The post with the most likes in the comment section below will win. Make su
The FLARE Learning Hub freely distributes quality educational content on reverse engineering and malware analysis from the FLARE team. We are excited to share with the wider security community FLARE’s nearly two decades of experience in instructing thousands of students and professionals across higher education, private industry, government, and premier conferences.Our content emphasizes hands-on practice. Modules include demonstrations and lab exercises that reinforce the material, helping you integrate practical skills into your workflow. The modules are hosted as web-published Google Docs, while the GitHub repository contains all corresponding artifacts, including lab binaries, scripts, and disassembler databases.We are launching today with three modules:Malware Analysis Crash Course: An adaptation of our foundational course that teaches the fundamental assembly skills and essential Windows knowledge necessary to begin reverse engineering Windows malware. The Go Reverse Engineering
Hey Community! We just launched our first Virtual Workshop + CTF with 599 people joining us for some fun SecOps learning and challenges! And what an event it was! A huge thank you to Keith Manville (kman) and JP (cybrshenanigans) for cohosting with me and building the two events! And to John Stoner (jstoner) for letting us use his enablement workshop content that went into all of our development for today’s live events. 🏆 Congratulations to the Top 3 contestants! 🏆 🥇 First Place: kushlendrasingh🥈 Second Place: Snickson🥉 Third Place: Juikalan And a HUGE thank you to everyone that participated in the workshop and CTF. You were all SUPER engaged, asked great questions, helped each other. Let’s do this AGAIN! Check out the Top 20 LeaderboardIt's ranked in order of who completed the challenge first. I’ll add more details on times to finish and other fun metrics soon. Be on the look out for more events like today! Thank you Community!Matt
Are you new to Chronicle or SecOps or SIEM? If you answered yes to any of those, this series is for you! When I started at Google in May, I had spent a good portion of my career working with SIEMs and MSSPs like Symantec, ArcSight and Splunk. However, I know from experience that different platforms have different capabilities and different ways to do build content, conduct investigations and hunt. So, this series is designed to provide some insight into how you can use Chronicle to effectively build rules, conduct searches and much much more. You can find the series at https://chronicle.security/blog/?filters=new-to-chronicle-series, we are at eight posts and growing. In fact, today we released a new blog around the improved search capabilities around UDM data. You can find the blog at https://chronicle.security/blog/posts/new-to-chronicle-a-new-view-for-search/ Stay tuned, there is more to come!
The promise of a future where intelligent agents assist human analysts with routine tasks, decision-making, and workflow automation, as outlined in our vision for the Agentic SOC, is now one step closer to reality. We are excited to announce the public preview of the Alert Triage and Investigation agent, a purpose-built AI agent natively embedded into Google Security Operations.The Alert Triage and Investigation agent helps security practitioners quickly and effectively identify threats by performing initial triage, saving valuable time. Designed to autonomously investigate alerts and provide comprehensive explanations, the agent represents a significant advancement in our vision to streamline alert management. It autonomously gathers evidence, runs analyses, and delivers verdicts, which means numerous alerts that might otherwise go untriaged can now be processed by agents – enabling security analysts to prioritize alerts which require human attention. Customer insights from private pr
Hey Community! Come elevate your career with the new Google Cloud Professional Security Operations Engineer Certification. Registration is now open! The new Google Cloud Professional Security Operations Engineer (PSOE) certification highlights the continuous and vigilant defense against ever-present threats that cloud security operations engineers and organizations face every day.If the Professional Cloud Security Engineer (PCSE) certification equips you to build a secure cloud fortress, the PSOE certification demonstrates that you are able to use the Google Cloud security tools such as Google Security Operations (SecOps), Security Command Center (SCC), and Google Threat Intelligence (GTI) to continuously defend it. This is critical because robust security isn't just about configuration; it's about the ongoing battle against evolving threats.The exam assesses your expertise across six core domains:Platform operations (~14%) Data management (~14%) Threat hunting (~19%) Detection enginee
Google Security Operations (SecOps) continues to push the boundaries of innovation, focusing on deep integration and intelligent automation. Our recently released features are designed to reduce noise, accelerate investigations, and ensure your security operations remain resilient and scalable. Agentic SOC Emerging Threat Center: (Public Preview)The Emerging Threat Center in SecOps helps customers immediately determine if their environment is impacted by new critical intelligence published by GTI, enabling them to quickly understand “Are we impacted?” and “Are we prepared?”, transforming the starting point for threat hunting workflows into a proactive, curated journey. As new Campaigns are published, Gemini processes the reports, determines detection coverage, and suggests new rules to add to Curated Detections. Learn more | Blog Image: The Emerging Threat CenterOneMCP: (Public Preview)SecOps OneMCP standardizes how AI agents (like Gemini CLI and Orcas) interact with SecOps SIEM and SO
For 16 years, the M-Trends report has served as a bellwether for the cybersecurity industry, providing an unvarnished look at the attackers, tactics, and techniques defining the modern threat landscape. We are proud to share the 2025 M-Trends Report, which distills observations and analysis from our latest incident response investigations into actionable guidance. This year's edition moves beyond standard metrics to explore how threat actors are adapting to cloud environments, exploiting decentralized finance, and leveraging human vectors in new ways. What You Will Learn: This comprehensive report offers a deep dive into the most critical trends of the past year, including:The Rise of Infostealers: Analysis of the growing risk posed by information-stealing malware and its role in precursor attacks. Nation-State Evolution: A detailed look at the Iranian threat landscape in 2024 and the persistent insider threat posed by DPRK (North Korea) IT workers. Cloud & SaaS Compromise: Frontl
Google Security Operations introduced a wave of significant features in Q2 2025, enhancing capabilities in data visualization, search, and case management. SecOps Dashboard and Reporting Platform: Now Offering Enhanced Visualization, Analysis, and MonitoringNow generally available, this release has added some exciting new capabilities to improve your visualization experience further. Learn moreKey Enhancements Include: SOAR Data Integration: Dashboards now natively integrate SOAR data, enabling powerful visualizations and monitoring of SOAR operations. This includes access to cases, case history, and playbook data, all queryable using YARA-L. Additionally, 30 days of historical SOAR data have been backfilled for all customers. Dashboard Export: Users can now easily download entire dashboards as PDF, CSV, or PNG files. Individual charts can also be exported as CSV for convenient sharing and offline analysis. Custom Drilldowns: Available across most chart types, custom drilldowns ca
Google SCC introduced significant innovations focused on helping customers prioritize risk, identify vulnerabilities, and protect AI workloads within their cloud environment. Below are the key features that achieved General Availability (GA) along with exciting Public Previews (PP). SCC comes in Premium (SCC-P) and Enterprise (SCC-E) editions. Premium provides the strongest security for Google Cloud, while Enterprise extends protection across multiple clouds and includes more robust automated responses. Risk Prioritization:Security Graph “Issues” (GA) - surfaces the most critical security risks in a customer’s environment, grouping them by severity and showing how assets, identities, and exposures are connected through an intuitive visual map. This helps customers quickly understand attack paths and the potential blast radius of each issue. Security Graph uses a graph database that incorporates cloud resources (like assets, identities, apps, and data) assigned to its nodes. The edges o
Hello, Security Community!We have introduced the Emerging Threats Center in Google Security Operations to address a specific friction point in the SOC: the lag between a high-profile threat hitting the news and the ability to detect it in your environment.When a "headline" vulnerability drops, analysts often lose hours or days to manual research and writing custom rules. The Emerging Threats Center is designed to streamline this workflow by leveraging Gemini to automate the heavy lifting of detection engineering.Here is the practical outcome for your team: Immediate Visibility: Rapidly answer "Are we impacted?" and "Are we prepared?" without manual query construction. Automated Research: The system analyzes threat intelligence articles and automatically converts them into valid detection rules. Faster Mitigation: Shift your focus from investigating if you are exposed to actually remediating the assets that are.We are keen to understand how this new workflow impacts your daily operation
Hello Community! I can't believe 2025 is almost over and 2026 is right around the corner. I don't know about you, but this year flew by! It has been a milestone year for us; we launched new programs, migrated to a new platform, and saw incredible growth in our membership and engagement. And I have all of you to thank for this success! This community is a massive puzzle, and every one of you is an essential piece. Whether you just registered your account, visited for the first time today, or browse our content to stay informed… THANK YOU for being here! To those who step up to ask questions, share solutions, and offer ideas: THANK YOU for making this a safe space for us to learn from one another and create connections. Your contributions are what allow us to build this powerful network of security practitioners. I am deeply grateful for your efforts. Lets continue this growth and momentum next year! I hope you enjoy your holidays, and I look forward to building even greater things toget
Welcome to the December edition of our Spotlight Series! For Darren Davis, Senior Security Consultant at Google SecOps, cybersecurity isn't just about prevention—it's about being ready to respond. In this month's feature, Darren opens up about the never-ending learning curve of the industry and why he loves seeing that "aha" moment when customers realize the true power of SecOps.From his top podcast recommendations (shoutout to Darknet Diaries!) to the Adoption Guides he swears by, get to know the expert behind the strategy.Join Darren for an exclusive webinar on December 10th, where he’ll share his expertise on Parsers and best practices. Register here: Parse Anything in Google SecOps: Parser Development Best Practices Darren DavisSenior Security Consultant, Google SecOps“It's not if, it's when. When you're compromised, make sure you are ready to respond” Q: What’s the most rewarding aspect of your job? A: Seeing the "aha" moment when customers grasp the power SecOps brings.
Our Spotlight for November is Jay Aware, our brilliant Customer Engineer in Security! Jay is passionate about tackling complex security challenges at a global scale and loves diving into nerdy topics like attacker methodology. He reminds us that "Security is a journey, not an end-state," and that continuous effort is key in the fight against bad actors. Want to learn more from Jay? He'll be hosting an exclusive webinar on November 11th where he'll share his insights and expertise. Don't miss this opportunity to hear from a pro.Register here: Community Webinar: Terraform-all-the-things: Google SecOps Authentication with 3rd party identity providers Jay AwareCustomer Engineer, Security“Security. Convenience. Pick one.” Q: What’s the most rewarding aspect of your job? A: I love working with my customers to solve complex security challenges at a global scale. Q: Which security content do you like sharing with others or appreciate that is shared with you? A: I love reading, so any dee
We're delighted to announce the expansion of Google Security Operations' regional support for data residency in two new locations: Brazil and France! This launch marks two significant milestones: A South American Debut: Brazil becomes our first data region in South America, extending our advanced security capabilities to this dynamic market. EMEA Expansion: France joins our growing network of data regions in EMEA, now totaling 11, underscoring our dedication to data privacy and security across the region. This expansion allows even more organizations to experience the benefits of Google Security Operations. In a recent IDC interview, a CISO at a European insurance agency shared how our platform helped them achieve a "pre-attack-based defensive posture," saving their team significant effort and allowing them to focus on higher-value tasks. They highlighted how Google Security Operations automated many of their manual SIEM tasks, freeing up their team to "work out how to get more busine
Hello Google Cloud Security Community!I'm thrilled to announce the launch of a new, dedicated space in our community: the CISO's Corner.This new section is a resource hub designed for CISOs, C-suite executives, and security leaders. It's a place to cut through the noise and find high-level, strategic guidance. What You'll Find Inside The Cloud Security Podcast: Join hosts Anton Chuvakin and Timothy Peacock as they talk with industry experts about some of the most interesting and challenging areas of cloud security. Executive Thought Leadership: A curated library of blogs and articles focused on the "why" and "how" of building modern security programs, with topics ranging from AI governance to SOC transformation.This new corner is designed to help you:Build Your Strategy: Find clear ideas for your cloud, AI, and compliance programs. Validate Your Thinking: Hear from industry experts on how they are tackling complex problems. Communicate Value: Get insights to articulate the "why" behind
Block out your calendar and stock up on instant ramen, because the FLARE-On 12 challenge is launching soon. This is the FLARE team’s CTF-style game for reverse engineers, aspiring reverse engineers, and anyone who likes to solve fun challenges for a meager amount of internet fame. This challenge will have 9 stages of increasingly difficult challenges for single players to solve in sequence. If you solve all stages, you may be eligible to receive a prize and have your name or handle etched into the fabled FLARE-On hall of fame for all to bask in the glory of your accomplishment. The contest starts at 8:00pm ET on Sept. 26th, 2025 and ends at 8:00pm ET on Oct. 24th, 2025. A live countdown timer is running at flare-on.com. Also check out the FLARE-On website for previous year’s challenges and official solutions to hone your skills at your leisure. As always, the FLARE-On contest covers a variety of architectures and file formats, with Windows binaries representing the largest share. This
This past quarter, Google Security Operations introduced significant innovations focused on AI-powered automation, next-generation detection, and enhanced operational efficiency for your Security Operations Center. Below are the key features that achieved General Availability (GA) in Q3, along with exciting public previews. Analyst ExperienceLegacy Stack (Non-BYOP, Federated Auth, Legacy RBAC) EoS: All new customers & partner tenants will no longer be onboarded into Non-BYOP project, Federated Auth and Legacy RBAC. So, every new customer instance needs to be set up in customer / partner’s GCP Project, configure Auth using Cloud Identity / BYOID, Feature RBAC to manage user roles and Data RBAC (optional) to manage Data access. Data Tables in Search: Introduces key new capabilities like Data Table Join & Filter support in Search, the ability to write search results into Data Tables, and RBAC for differentiated access control. Learn more SecOps Data RBAC Self-Service Enablement: Y
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.