Stay Informed
Recently active
Hello Community Members, We are excited to announce a small refresh of the Community structure, navigation and design coming early Thursday morning Dec 12th US Pacific time zone. You'll notice some basic changes to the layout. We are simplifying and consolidating the nav bar so it's easier for you to access the information you need. We are structuring the content in a much more organized way. There will be a Security Forums section where all our forums will live. Tips & Resources will include product Onboarding Guides, product Best Practices, Learning, and a Cloud Support page. Articles & Information will include the Community Blog, News & Announcements, Security Podcast and Community Resources. The Community Blog will have a slightly new look with 3 tiles at the top of the page. Events and User Groups will remain the same. Once we launch, we welcome any and all feedback. We look forward to hearing what you think of the new updates. And, thanks for continuing to
This third quarter of 2024, Google Security Operations focused on fueling efficiency and collaboration for our customers. We’ve rolled out a host of key enhancements including: Threat profile sharing Private collection sharing New curated detections IDE staging A single YL2 language 34 new YARA-L2.0 functions (Preview) Data export from Google SecOps to BigQuery Mandiant Managed Defense for Google SecOps To access the details of our Q3 additions to Google Security Operations, visit this blog. To find a comprehensive list of recent Google Security Operations Release Notes/Changes, go here.
With a busy end of September you may have missed this exciting announcement - Google named a Leader in the IDC MarketScape: Worldwide SIEM for Enterprise 2024 Vendor Assessment! We believe this recognition is a reflection of our significant investments in Google Security Operations over the past three years. Our efforts include the acquisition and integration of Mandiant, the world’s leading threat intelligence and incident response provider, and Siemplify, a leading security orchestration, automation and response (SOAR) provider. The report noted, “Google Security Operations is a cloud-native SIEM that is integrating previous point products such as SOAR and ASM, enriching all alerts with Google Threat Intelligence, and offering a gen AI assistant to alleviate mundane security analyst tasks. It is built on the search, data visualization, and storage services of Google Cloud.”Download a complimentary excerpt of the IDC MarketScape: Worldwide SIEM
What’s New in Google SecOps today? Introducing the SecOps product release digest, designed to keep you informed about the latest advancements in Google Security Operations (formerly Chronicle). Discover the latest SecOps product features and how they can empower your team.______________________________________________________________________________________________________________ Gemini AI Playbook Assistant (Public Preview)Gemini AI Playbook Assistant can help you streamline the process of creating playbooks by turning your prompts into a functional playbook that helps resolve security issues. Users can leverage Gemini to build and configure playbooks, or ask Gemini to suggest flows to cover specific use cases leveraging industry standard approaches. Read More >> (Gemini AI Playbook Assistant) Data RBAC (Generally Available)Data RBAC enhances your data security by allowing role-based access control, customizable permissions based on UDM fields and ingestion parameters, and eff
Mandiant Managed Defense, our 24/7 managed detection and response (MDR) service, is now generally available for Google Security Operations (SecOps) customers in the US. Managed Defense now uses built-in curated detections and risk scores from Google Security Operations for comprehensive, up-to-the-minute threat coverage, automated threat identification, and faster threat identification. These capabilities allow our experts to prioritize rapid investigation and incident remediation. Our proactive approach is continuously enriched with insights from Managed Defense's own threat hunts, protecting our customers against the latest attack techniques. Managed Defense supports native Google SecOps features designed to identify potential compromise and seamlessly integrates with your existing security tools, offering flexibility and choice. Managed Defense for Google SecOps supports Crowdstrike Falcon Insight XDR, Microsoft Defender for Endpoint, and SentinelOne Singularity XDR. Additionally, w
Hi community members,Are you a Google Security Operations customer? If so, we would sincerely appreciate it if you took a few minutes to share your positive experiences with the platform on Gartner Peer Insights. By leaving us a review, you can help other security technology buyers make informed decisions, and as a thank you, Gartner will send you a $25 gift card. Anyone on your team can complete the review as it is not limited to 1 person per company, so please invite your team to participate! All reviews are verified and posted anonymously.Write a review for Google SecOps SIEM: goo.gle/GoogleSecOpsSIEM Write a review for Google SecOps SOAR: goo.gle/GoogleSecOpsSOARThank you for your support!Ahnna
Building on the strong product momentum of Google Security Operations in the first quarter of 2024, our second quarter brought a host of significant enhancements focused on providing customers with an advanced AI and intel-driven experience. But we didn’t stop there. We also introduced a number of improvements to everyday processes, prioritizing the ease of use and efficiency of Google SecOps. To access a list of our Q2 additions to Google Security Operations, visit this blog. To find a comprehensive list of recent Google Security Operations Release Notes/Changes, go here.
We're excited to introduce a game-changing feature within the Google Security Operations platform: IDE Staging. 👋 Say goodbye to the fear of pushing an integration update live, only to discover it disrupted your existing playbooks and connectors. With IDE Staging, you can now thoroughly test your integrations in a safe, isolated environment before they hit production. Key Benefits of IDE Staging: Risk-Free Testing: Upgrade integrations, test them in a secure staging environment, and then confidently push them to production, replacing existing integrations without disrupting operations. Enhanced Confidence: Validate changes and gain full visibility into how updates will behave in your production environment before deployment. Streamlined Python Upgrades: Aligned with the Python version upgrade process for easy maintenance and proactive security vulnerability management. How to Get Started: For a detailed walkthrough of how to use the IDE in staging mode, please refer to our do
We are thrilled to announce the addition of two new data regions for Google Security Operations: Italy and Qatar. This brings our total number of EMEA data regions for Google SecOps to 10, demonstrating our ongoing commitment to protecting customer data and privacy. Since the start of 2024, we have added five new data regions, including Japan, Canada, India, and now Qatar and Italy. Our expansion highlights Google Cloud's dedication to delivering top-notch security solutions across the globe. One Italian customer, Telepass, is already benefiting from Google Security Operations, using it as their single point of truth for security, greatly simplifying their analysts' tasks. Another EMEA CISO was interviewed by IDC and shared, "Our cybersecurity teams deal with issues faster with Google Security Operations, but they also identify more issues. The real question is, ‛How much safer do I feel as a CISO with Google Security Operations versus my old platform?’ and I would say 100 times safer.
As we forged into the first quarter of 2024, Google Security Operations (formerly Chronicle) unveiled a series of updates centered around streamlining operations for our customers. We understand the challenges faced by security operations teams dealing with time-consuming and intricate processes. That’s why we’re excited to introduce enhancements that simplify workflows and enhance efficiency. To access a list of our Q1 additions to Google Security Operations, visit this blog. To find a comprehensive list of recent Google Security Operations Release Notes/Changes, go here.
Today we introduced a host of new innovations in Google Security Operations (formerly known as Chronicle) designed to make everyone in the SOC more productive from security analysts, to security engineers, to managers. You might have also noticed we announced that Chronicle is now Google Security Operations. The name may have changed, but our focus on providing a unified, AI and intelligence-driven platform that modernizes threat detection, investigation, and response (TDIR) has not! Read the blog to learn more about what's new in Google Security Operations. Or come meet us in person at our RSA Conference booth (N5644). You can also catch us at our keynotes, presentations, and meetups including our session, “Bye-Bye DIY: Frictionless Security Operations with Google,” on Tuesday, May 7, at 1:15 p.m. PDT.
Hi everyone, as shared in a previous announcement, we're excited to share the revamped community ranking system and badges are now live! Please see our community resource article, Understanding Community Ranks and Badges and the announcement post for further details. With the new ranking system, we want to emphasize that: Badges are unlocked by completing a certain amount of an activity, whereas ranks are tied to completing a combination of activities, including giving and receiving likes, authoring posts and solutions, and engaging in the comments. Avatar icons are assigned to members to signify a unique status, role, or achievement in the broader Google Cloud ecosystem, including Google Staff, Innovators, Innovators Plus, and Champion Innovators. Tip 👉 If you want to climb the ranks, take a look at your contributions, as shown on your profile page, to see if there are any comm
Hey everyone, get ready for an exciting evolution to our Google Cloud Community! Based on your valuable feedback, we’re revamping and revitalizing the community’s ranking system and badges, going into effect on April 5th. Community email notifications will be paused on April 5th between 5AM and 12PM PT as we make these updates, but you will still be able to use the Community as usual. Why the change? We heard that you want a community ranking system that recognizes the quality of your contributions, not just the quantity. You want clearer naming conventions and visual representations of ranks so you can quickly see where someone falls in the ranking structure. You also wouldn’t mind a few more rungs to climb on the ranking ladder. We hear you! Here’s what we’re doing about it. What’s changing? Quality over quantity: The new ranking system will place greater emphasis on the value and impact of your contributions acr
It’s not time to put 2023 in the rearview mirror just yet, at least not until we’ve shared our last set of Chronicle Security Operations highlights. We do like to end things with a bang and we think you’ll like how we’re closing the year out. To access a list of our Q4 additions to Chronicle Security Operations, visit this blog. To find a comprehensive list of recent Chronicle Release Notes/Changes, go here.
Uncover threats missed by traditional detection methods. Mandiant expert hunters will proactively scour your Chronicle Security Operations data, armed with the latest knowledge of adversary tactics, techniques, and procedures (TTPs). Mandiant Hunt is fueled by continuous intelligence from Mandiant frontline experts, VirusTotal’s intelligence community, and Google security telemetry, ensuring your hunt leverages the latest insights. Findings come with clear explanations of the hunt process and are mapped to the MITRE ATT&CK framework, empowering you with actionable context for decisive action. For more information, refer to the Mandiant Hunt documentation and explore how proactive hunting can mitigate business impact.
We’re glad that you’ve decided to explore our flourishing group of peers and industry experts who are here to network, share knowledge, and have fun together. Here, you can find support or network and find educational content, inspiration and encouragement, whether you are brand-new to the world of Google Cloud Security or you are a seasoned Google Cloud Security veteran. If you have not yet registered, please visit here to learn how to register. Now that you are a member, you can enjoy the following resources: The Mandiant Forums As a community member, you have the ability to post, reply and give "likes" on the Google Cloud Security community forums. If you are looking for support with any part of Mandiant, our forums are the place to go. They are titled "Mandiant Forums" and there you will find technical professionals with years of experience who are ready and eager to answer your questions. Conduct a quick search, by using keywords, before creating a new post b
Today, we are announcing that Duet AI for Developers and Duet AI in Security Operations are now generally available (GA). These offerings join Duet AI in Google Workspace, which has been generally available since August. All of our Duet AI services will be incorporating Gemini, our most capable model, over the next few weeks. To learn more, read our Google Cloud Blog about it: Announcing General Availability of Duet AI for Developers and Duet AI in Security Operations
Chronicle Security Operations is coming off a pivotal third quarter. Not only did we announce a modern, AI-powered approach to TDIR, but continued to make enhancements towards everyday functionality. To find a comprehensive list of our Q3 additions, visit this blog. To find a comprehensive list of recent Chronicle Release Notes/Changes, go here.
See @jstoner's most recent article about Getting to Know Chronicle SIEM: YARA-L Rule Options in the Chronicle Best Practices page. To stay up to date on the latest in Chronicle Best Practices, consider Subscribing under Topic Options.
See @jstoner's most recent article about Getting to Know Chronicle SIEM: YARA-L Rule Options in the Chronicle Best Practices page. To stay up to date on the latest in Chronicle Best Practices, consider Subscribing under Topic Options.
At Google Cloud, we’re on a mission to accelerate security outcomes for every organization. Today, we’re thrilled to announce incredible progress towards this mission with curated detections. What are curated detections? We are excited to announce the general availability of curated detections in Chronicle. With this release, we are providing our customers high quality, actionable, out-of-the-box detection content curated and built by Google Cloud Threat Intelligence (GCTI) researchers. These rule sets cover threats in Windows including ransomware, remote-access tools (RAT), infostealers etc. We are also expanding our coverage to detect cloud specific threats including identifying potential exfiltration of data, suspicious activity, and weakened configurations. With curated detections in Google Chronicle, customers now have the ability to leverage the intelligence and expertise of our threat researchers natively within the console. Chronicle customers can now utilize high-
We are gearing up for our next Chronicle event and would love to hear what you want want us to cover. Please share your ideas by October 20th so we can generate content that matters most to you. Just drop a comment below! Or if you prefer, you can submit this anonymous form. Thank you and stay tuned for our next session on the events page here.
Hello SecOps Community, Stay up to date with everything going on in Chronicle Security Operations by reading the SecOps Customer Newsletter! Updated every other month, you can find a summary of major Product Updates, Learning and Training, Community Announcements, Best Practices, and Upcoming Events. Chronicle Security Operations Updates Introducing the unified Security Operations platform The newest version of Chronicle Security Operations introduces a modern, cloud-native, AI-powered platform that can help you stay ahead of modern threats with a focus on outcomes, a unified experience that puts proactive and reactive context at your fingertips, and practical application of AI to reduce daily toil. Here’s the highlights: Unified security operations experience. With our new consolidated experience for Chronicle SIEM and Chronicle SOAR, we can better provide rich context and easy pivoting between alerts, cases, investigations, and playbooks in a single console, for a more streamlined
Hi SecOps Community Throughout Q4 we released a lot of new security operations features that will help you get to your goals even faster. To find a comprehensive list of our Q4 additions to Chronicle Security Operations, visit this blog To find a comprehensive list of recent Chronicle Release Notes/Changes, go here
This post was originally sent by Shaked Tal Hi SecOps Community 🙂 I’m excited to share that our SecOps Community will have a new and improved home beginning September 25, 2023 , as part of the Google Cloud Community (GCC). My name is Shaked, your current Community Manager and together with @Willie Turney , @Lauren van & @Ray_a from the Google Cloud Community team , I’m thrilled to have the opportunity to help support you as we make this transition. We believe that a strong community is essential for both your success and ours and we want to ensure we provide you with the support, content, and space to allow you to connect and learn from each other. Moving to the GCC ensures long-term durability and sustainability of this community and its programs. This iteration will also allow us to manage and moderate the community more efficiently, which will enable us to offer more updates from the product team and more community events to learn and share best practices from Clo
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.