Stay Informed
Recently active
Hey Community,We have an exciting opportunity for you to uplevel your AI skills and strengthen your security defenses without adding more to your plate. If you live in or are near Los Angeles, Chicago, New York, or Toronto, you're invited to an exclusive, free half-day training event designed for security practitioners. Our theme is building the next class of security experts empowered by AI.Join us to explore how AI will transform security operations from a manual grind to more autonomous functions. We'll share our vision for the Agentic SOC—a future where AI, powered by Gemini, acts as your virtual security assistant, anticipating threats and guiding you to respond faster and more effectively.In this workshop, you will:Translate Vision into Action: Go beyond theory and learn how to transform security operations from a manual grind to autonomous functions. Get Hands-On with Gemini: Discover how to leverage Gemini as a virtual assistant to anticipate threats and guide your team to opti
It's time for our October Community Spotlight! This month, we are featuring Robert Parker, a Technical Solutions Consultant who is passionate about helping organizations build their security defenses.A true believer in the power of community, Robert shares some great advice on staying up-to-date with industry trends, networking with local cybersecurity groups, and the best career advice he ever received—from a soda koozie! Check out his story in this month's spotlight. Robert ParkerTechnical Solutions Consultant“Kindness and gratitude are free, so how about we sprinkle some of it everywhere we go?” Q: What sparked your interest in Security Operations? A: I first started in security during graduate school and while working at a Help Desk for a local healthcare provider. Knowing how sensitive our PII data was, and seeing the major breaches happening at the time, (think back to the LulzSec hacking days), I knew that security was an area I wanted to specifically pursue and specialize
CrowdStrike deprecated the Detects API on October 1, 2024 and this API will be decommissioned on September 30, 2025. This API has been superseded by the CrowdStrike Alerts API.Please continue reading if…You have active SIEM data feeds on Google SecOps using the CrowdStrike Detection Monitoring (“CS Detects”) API connector (mapped to the CS_DETECTS logtype), and Your CrowdStrike API Client mapped to this feed does not have permission to read ‘Alerts’.What action do I need to take?You are advised to take one of the following actions:Option 1 (recommended): Update permissions for your existing CrowdStrike API clients that are using the CS Detects API. This is a straightforward and simple approach, requiring changes only on your Falcon Tenant. It also provides a way to verify whether your feeds are still using the DETECTS API (verification steps provided below). This has the lowest downstream impact on any active Detection Rules that refer to the CS_DETECTS logtype. Option 2: Update yo
We're bringing to you another Community challenge and this time it's about Model Context Protocol. MCP is a hot topic in the security world right now. For those just hearing about MCP, it allows AI models to communicate with and leverage the capabilities of diverse security tools. This helps enhance security workflows by ensuring models are contextually aware across multiple downstream services. With the ability to interact with security data in natural language, security teams can produce insights faster and scale their security operations. If you’re just getting started with the SecOps MCP server, check out our SecOps MCPserver content to learn more.We're excited to launch this new challenge and can't wait to see all the different ways you are using the Google SecOps MCP server to boost your security operations. Knowing our expert Community users, we bet you're doing incredible things. And we want to see what you're up to! This is your chance to contribute to the Community, show off
🚀 📢 Ready to demonstrate your skills with Google Cloud security operations tools? Google Cloud is offering a beta for the new Professional Security Operations Engineer certification! The beta exam will be available until August 8. This professional-level technical certification tests your ability to protect cloud and on-premises environments from threats. This exam assesses your skills in data ingestion, log management, threat hunting, detection, incident response, and reporting/observability using the Google Cloud security operations toolset, which includes Google Security Operations (SecOps), Security Command Center (SCC), and Google Threat Intelligence (GTI). Learn more about the Professional Security Operations Engineer certification here. Why take the beta exam? Be among the first participants in the world to get access to this new exam. All beta exams are discounted at 40% off the retail price of the GA exam, and vouchers are accepted for this beta exam
For our latest spotlight, we're excited to feature Tom Ruff, a Technical Security Consultant who knows that "Defense wins championships, and a lack of defense empties your bank account." With a passion for defense that started on the playing field, Tom brings a unique perspective to the world of security operations.Discover how he helps customers improve their security posture, why he gets excited about defending against novel threats like BlackMamba, and what resource he recommends for "herding professional cats."Want to meet Tom in person and learn more? He'll be hosting a webinar on September 9th. Be sure to sign up for the webinar to secure your spot! Tom RuffTechnical Solutions Consultant"Defense wins championships, and a lack of defense empties your bank account" Questions and Answers Q: What sparked your interest in Security Operations? A: Growing up, I played basketball, volleyball and football. I always enjoyed defense more than offense. So once I moved past being a sof
Hello Community Goers! We are absolutely thrilled to welcome you to our brand-new Community home! This isn't just a move; it's an upgrade designed to make your experience more seamless, connected, and valuable than ever before. Ready to explore? Let's take a quick tour of what's waiting for you!"The Heart of Support: Security ForumsGot a burning product question? Head straight to our Security Forums (you'll find them under the 'Community' dropdown). Here, you can ask questions, connect with peers, and share solutions. It's the go-to place for both getting and giving support to our vibrant community. Your Central Hub for Learning: Resource CenterLooking to master Google Cloud Security? We've created the Resource Center as your centralized hub for all enablement needs. We've consolidated everything from best practices and getting started guides to comprehensive learning materials. Make sure to explore and bookmark the boards most relevant to your journey, including product Onboarding &a
We’re glad that you’ve decided to explore our flourishing group of peers and industry experts who are here to network, share knowledge, and have fun together. Here, you can find support or network and find educational content, inspiration and encouragement, whether you are brand-new to the world of Google Cloud Security or you are a seasoned Google Cloud Security veteran. If you have not yet registered, please set up your account or click here to learn more on how to register. Now that you are a member, you can enjoy the following resources: Community Forums As a community member, you have the ability to post, reply and give "likes" on the Google Cloud Security community forums. If you are looking for support with any Google Cloud Security products, our forums are the place to go. They are all listed under Security Forums. There you will find technical professionals with years of experience who are ready and eager to answer your questions. Conduct a quick search, by using keyword
At our core, we are a community built on the strength of individuals whose efforts lead to our mutual achievements. We invite you to explore the stories of the people at the heart of our organization. Meet David, our very own Technical Solutions Consultant! He's passionate about tackling alert fatigue and loves the constant challenge of security operations. David values practical and insightful content, from threat intel to automation scripts. Fun fact: He's also training for Mr. Olympia! Get to know David and his take on the ever-evolving world of cybersecurity. David Nehoda “Security Geek” - Technical Solutions Consultant “Learn what is to be taken seriously and laugh at the rest.” Questions and Answers Q: If you could change one thing about security operations with a snap of your finger, what would it be?A: I would eliminate alert fatigue. The sheer volume of alerts that security operations centers (SOCs) deal with daily is overwhelming. It leads to burnout,
Hello Google Cloud Security Community! Matt Nichols here. You may have seen me answering posts, starting conversations, hosting some webinars. It’s been an exciting last year building our Community together. A big kudos to all of you, our Community members, that have helped us make this a thriving marketplace for conversations, learning, Q&A, thought leadership and more. We have some exciting news to share with you. The Google Cloud Security Community will be moving to a new, dedicated platform on Gainsight at the end of the month! We strongly feel this move will significantly enhance your Google Cloud Security community experience. We believe that a powerful, connected Community is essential for your success in securing cloud environments. And this will empower us to deliver the best Google Cloud Security products and Community programs to you. We will always remain committed to providing you with the most relevant support, cutting-edge content, and a vibrant space to connect
Hey Community!Get ready to unpack your bags, because our big move is just around the corner! We're absolutely buzzing about the exciting new home we're creating for the Google Cloud Security Community. This guide is your personal roadmap, packed with answers to all your questions about our migration to the new Gainsight platform and a sneak peek at the incredible updates waiting for you! Have feedback? We want to hear it. Come share here. COMMUNITY FAQ: Why is the Google Cloud Security Community moving platforms? We determined that a dedicated and more focused platform would enhance our ability to support your cloud security needs. The new more modern platform meets our requirements to better support you and is designed to reduce clutter, improve discussion quality, centralize resources, while providing a more security focused lead approach. Community Structure Updates We've reorganized and restructured a bit. Like you would when you move to a new home. We’ve updated our structure,
Hey everyone! Remember that exciting news we dropped yesterday? Well, mark your calendars because Tuesday, July 22nd, is migration day! We're absolutely thrilled, and we hope you are too! Have feedback? We want to hear it. Come share here. As promised, we've got an FAQ ready to tackle your questions. But wait, there's more! We're also buzzing to share some awesome new Community programs launching with the platform, including a SecOps MCP Challenge! Dive in below for all the juicy details. --- First up, a quick peek at our timeline: July 16, 2025: We will put the Community in Read Only mode so we can start the migration process. We appreciate your patience during this process. July 22, 2025: Google Cloud Security Community will launch on the new platform! --- New Adventures Await: Programs Coming to Your Community! Community Contest July 22nd! To kick off our new platform with a bang, we're launching another Community contest on day one: the SecOps MCP Challenge! New to the SecOps
Hi Community, We've identified the root cause and applied appropriate mitigations. Our engineers have confirmed that the underlying dependency is recovered in all locations except us-central1. However, we understand you may still be experiencing varying degrees of impact on individual Google Cloud Services. All respective engineering teams are actively engaged and working on service recovery. The issue stemmed from an incorrect change to our API endpoints, which caused a crash loop and affected our global infrastructure, impacting all services. We do not have an ETA for full service recovery and are continuing to post updates on Google Cloud Status dashboard.
We are on a mission to drive the adoption for our Google SecOps Native Dashboard feature, and we want YOU, our amazing community, to lead the charge! Let’s unlock the full potential of this together! We also want you to empower your security operations with the new Native Dashboard, create insightful visualizations and gain better visibility using our out-of-the-box dashboards created by Google SecOps internal team!This isn't just any contest; it's your chance to shine and help shape the future of SecOps visibility! Your vote matters so be sure to check out the details below on how you can help us determine a winner!Duration: March 31st - April 30thAnnouncement date: Winners will be announced Mid-May 2025How to ParticipateCreate a dashboard using the Google SecOps Native Dashboard feature. Leverage the provided out-of-the-box dashboard samples as a foundation or inspiration. Share a screenshot or short video (you may blur out sensitive confidential information) of their dashboard by r
Big news! Our new white paper, "Securing Nations in the Digital Age: Google Cloud Cybershield™," is LIVE! This essential guide dives into: The Current Threat Landscape: Learn why governments and public sector entities are prime targets and the alarming trends in financially motivated attacks and state-sponsored cyber espionage. The Need for a Comprehensive Approach: Understand the challenges of siloed security tools, lack of real-time information sharing, and the persistent cybersecurity talent shortage. The Need for a Comprehensive Approach: Understand the challenges of siloed security tools, lack of real-time information sharing, and the persistent cybersecurity talent shortage. The Way Forward with Google Cloud Cybershield™: Explore our AI and intelligence-driven solution, built on three core pillars: Tailored and Applied Threat Intelligence: Learn how Google Threat Intelligence empowers teams with actionable insights most relevant to their environment with unparalleled, real-time
Hey Community! We have an upcoming webinar that you won't want to miss on May 21th 10AM EDT / 15:00 BST! This urgent webinar is focused on a critical cybersecurity threat: UNC3944, also known as Scattered Spider. As you may know, UNC3944 has resumed its ransomware and extortion operations, and they are currently targeting US retailers with the same aggressive tactics they used in the UK recently. I wanted to make sure you were aware of this immediate risk. These actors are particularly effective at circumventing mature security programs, using social engineering and third-party access to gain entry. We are hosting a webinar on May 21st at 10:00 AM EDT / 3:00 PM BST, Proactive defense against UNC3944: Hardening your enterprise, where Google Threat Intelligence Group and Mandiant experts will share actionable strategies to proactively defend against UNC3944's evolving tactics. In this webinar, you'll learn how to: Enhance Identity Security Fortify Endpoints & Cloud Strengthen
The strength of our community lies in the individuals who contribute to our shared achievements. Discover more about the people who make us who we are. Dive into the dynamic world of SecOps with our latest community highlight: Vasken Houdoverdov! As a Technical Solutions Consultant, Vasken thrives on the thrill of case analysis, rule creation, and big data insights. But his impact doesn't stop there – he's a valuable content creator across our forums, driving product adoption and connecting with security pros globally. Hear what sparks his passion, the rewarding aspects of his role, and why he's excited to be part of our growing Google Cloud Security Community. Plus, you won't believe his fascinating fun fact! Vasken Houdoverdov Technical Solutions Consultant “If something intimidates you, jump into it headfirst!” Questions and Answers Q: What sparked your interest in Security Operations? A: I enjoy being able to bounce between case analysis, writing and m
Have you considered the individuals who contribute to our collective success? We invite you to learn more about the driving forces within our community. Meet John Stoner, our Global Principal Security Strategist. He is all about making security teams more effective and does this by breaking down complex data, addressing new threats, and sharing his widely respected SecOps best practices. John is on a mission to simplify the complexities of security operations, starting with data understanding. From his love for insightful blogs to his passion for bridging the gap between business and security, John's insights are a valuable resource for our community. John Stoner Global Principal Security Strategist “Stay intellectually curious, it goes such a long way in security...” Questions and Answers Q: What makes you excited about going to work every day? A: Being able to build content that helps educate practitioners how Google SecOps can be used. Q: If you could change one th
Today we are excited to announce the general availability of Google Unified Security! Google Unified Security is our new AI-powered converged security solution, designed to address the challenges of fragmented data and siloed security tools of which threat actors are increasingly taking advantage. By integrating Google's leading threat intelligence, security operations, cloud security, secure enterprise browsing, and Mandiant expertise, Google Unified Security creates a single, scalable security data fabric across the entire attack surface. Gemini AI enhances threat detection with real-time insights and streamlines security operations, empowering organizations to shift from reactive to preemptive security and stay two steps ahead of increasingly sophisticated attackers. Learn more about the solution here.
Ensuring continuous data ingestion is critical for effective security operations. What happens when a collector stops sending logs to your Google SecOps instance? That's where Silent Host Monitoring comes in, allowing you to create alerts based on changes in ingestion rates via Google Cloud Monitoring. This way, you'll be notified if a collector stops functioning for any reason.Bindplane plays a key role in enabling this monitoring. Ensure that the SecOps Standardization Processor is active in your Bindplane workflow. The next step is to ensure the collector server's hostname is included as an attribute in your log entries. By implementing Silent Host Monitoring with Bindplane and Google Cloud Monitoring, you can proactively identify and address issues with your telemetry ingestion pipelines, ensuring you maintain complete visibility within your Google SecOps environment. This allows for quicker incident response and a more robust security posture Please review the following how-to gui
Google Security Operations finished 2024 strong with a wave of impactful features in Q4! We're empowering security teams to visualize, analyze, and act with confidence through our new native dashboards. But that's not all. We've also supercharged threat investigation with Gemini alert summarization in Digital Threat Monitoring and accelerated threat intelligence research with a new search experience in Google Threat Intelligence. Let’s explore some of the highlights: Cut Through the Noise with Gemini Alert Summarization Reduce alert fatigue and accelerate threat investigation with Gemini Digital Threat Monitoring alert summarization. Digital Threat Monitoring now provides concise summaries of all alerts from the open, deep, and dark web, enabling your security team to efficiently prioritize and assess potential threats. Quickly identify critical issues, even across multiple languages, and streamline your incident response workflow. Learn more in our documentation. Automatically
Ever wondered who's behind the scenes? Curious to know who makes our community tick? We're about to show you! From API roadblocks to the satisfaction of conquering a mountain of tasks, Andy Shepherd's journey in SecOps is anything but ordinary. He believes cybersecurity is born from constant change and tech evolution, and he's always looking for the next big challenge. Join us as we shine a light on Andy, our Global Architect, and his passion for solving "interesting problems for interesting people." Andy Shepherd Global Architect in SecOps “I wonder if cybersecurity's existence stems from the combination of constant business change and deployment of fresh technologies? Though without these, would we still be using standalone 1950s servers in basements?” Questions and Answers Q: What makes you excited about going to work every day? A: Using interesting technology to fix interesting problems for interesting people Q: If you could change one thing about security operati
We're excited to announce a Vertex AI integration is now available in the Google SecOps Marketplace! ✨ Combine the power of Google’s AI Platform, Vertex AI and models, to rapidly create custom response actions and meet enrichment needs. Gain deeper insights from your data and boost your team's efficiency and effectiveness, whether you're using Gemini in SecOps, built-in features, or creating custom solutions with Vertex AI. Here are the use cases you can address with this Vertex AI integration: Execute a Playbook Prompt (Generally Available): The sky's the limit! Use custom prompts to automate case management activities, summarize action responses, build curated emails and ITSM tickets with context from alerts, and streamline your workflows. Analyze EML (Preview): Automatically analyze suspicious emails for malicious behavior with an out-of-the-box (OOTB) widget. Generative AI provides an email threat level rating, recommended next steps, and a clear explanation of the id
We're thrilled to announce a fresh look and feel for the Google Cloud Security Community! This redesign aims to consolidate navigation, enhance organization, and provide a more focused experience. You’ll notice some older forums have been sunsetted to create a more streamlined space for discussion. Also, we’ve merged a few sections so you can access important updates and information all in one place. We advise that you resubscribe to these forum boards and the labels that excite you the most. What's New? Simplified Navigation: The new navigation bar makes it easier to find what you need. Security Forums: Your go-to place for discussions on SecOps SIEM, SOAR, Google Threat Intelligence, Attack Surface Management, Managed Defense, Security Validation, Security Command Center, and reCAPTCHA. Come ask questions, share your expertise, connect, network, help each other out, have fun and remember, please be respectful! Tips & Resources: Discover product onboarding guides, le
Wow! What an amazing year it has been for the Google Cloud Security Community. And thanks to all of you who have participated in helping us build this incredible network of security practitioners coming together all for the common cause of supporting each other! I just wanted to highlight few simple rules to continue to keep things friendly and productive: Be Respectful: Let's keep the vibes positive. Respectful and polite interactions make for a better community. Be Relevant: Keep your comments relevant to the thread. If you have a new question, start a new thread. Share the Love: Got a tip or trick? Share it! Help others and level up the community together. Be Responsible: Use common sense and good judgment in your interactions. Avoid sharing confidential information or breaking any rules. Protect Privacy: Let's keep personal information private. Don't share anything you wouldn't want publicly available. Remember, this is a user-generated community. You'll find plenty of good advice
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.