This community webinar explores the latest features in Google Threat Intelligence (GTI) designed to supercharge fraud prevention and brand protection. The presentation demonstrates how security teams can leverage Gemini and agentic AI capabilities to shift from reactive defense to proactive threat hunting, automate complex indicator of compromise (IOC) searches, and dramatically accelerate the collection and analysis phases of the intelligence lifecycle.
What You Can Expect to Learn
- Advanced Brand Protection: How to utilize new vision-based and document-object-model search modifiers to detect malicious pages mimicking your brand, even when they avoid using your brand name in the domain or title.
- AI-Powered Automation: Methods for using agentic AI prompts to automatically convert natural language queries into complex search syntaxes and Yara X live hunting rules.
- Accelerated Triage and Investigation: How to design an AI investigation playbook that synthesizes infrastructure analysis and aggregates necessary evidence to rapidly prepare automated takedown requests.
Key Discussion Points & Timestamps
11:11 - Vision-Forward Brand Detection Modifiers
How Google Threat Intelligence utilizes Gemini to analyze both webpage screenshots and document object model (DOM) trees to accurately identify malicious actors spoofing corporate logos and content.
15:26 - Boolean Logic and Multi-Layered Search Filters
A technical breakdown of isolating active, high-severity threats by stringing together search modifiers for HTTP 200 response codes, target brands, malicious behavior tags, and threat-actor-abused domain registrars.
21:02 - Proactive Automation via Yara X Live Hunting
How to continuously cross-reference every file, URL, IP address, and domain ingested by Google Threat Intelligence globally against persistent rules, such as monitoring for unauthorized use of a corporate favicon hash.
26:57 - Agentic AI Playbooks and Infrastructure Takedown Synthesis
Leveraging specialized triage analyst prompts to automatically investigate malicious domains, document technical evidence (resolving IPs, domain age, and registrar privacy parameters), and compile reports ready for rapid takedown requests.
34:32 - Interactive Q&A: Advanced Mechanics and MSSP Guidance
Audience discussion deep-diving into the programmatic generation of Yara X queries, the zero-token cost of running UI queries inside the platform, and recommendations for executing managed infrastructure takedowns with third-party providers.

