In this webinar, Google Cloud SecOps Deployment and Integration Engineer Tal Resnikov pulls back the curtain on how to design and deploy robust, self-healing playbooks in Google SecOps. If you’ve ever had a minor API key change break dozens of playbooks, you know the pain of "monolithic" design. This session walks through the exact methodology for stripping away that complexity and replacing it with clean, reusable Foundational Blocks.
Learn how to apply the Centaur Model, keeping humans firmly in the driver’s seat while letting AI do the heavy lifting, and how to integrate the new Triage and Investigation Agent (TINA) to investigate the alerts that static tools miss.
What You Can Expect:
- Save Time & Token Costs: Learn how to implement "short-circuiting" to bypass known-good entities early, reserving expensive AI processing strictly for genuine threats.
- Stop Coding Blindly: Understand why Tal’s Rule #1 is to never touch SOAR or SIEM until the end-to-end flow is fully mapped out in a paper Use Case Design Document.
- Master TINA: See step-by-step how to drag and drop the Triage and Investigation Agent into real workflows to go far beyond basic reputation checks.
- Create Human-in-the-Loop Safeguards: Discover how to configure manual out-of-band approval gates for high-impact actions like quarantining hosts or locking accounts.
Key Discussion Points & Timestamps
- 05:33 - Core Philosophy: Why abstraction is essential to protecting analyst sanity, saving time, and cutting down on token costs.
- 08:28 - The Monolithic Nightmare: Breaking down why repetitive playbook structures inevitably lead to major maintenance headaches.
- 09:42 - Rule #1 (The Design Doc): Why teams must map out log collection, parsing, detection, and feedback on paper before building in SOAR.
- 11:53 - The Centaur Model: Exploring the relationship between human-driven logic and AI-driven scale
- 12:59 - Foundational Blocks: Designing reusable playbook logic and ensuring blocks remain use-case agnostic.
- 14:16 - Playbook Priority Abstraction: The 3-tiered priority system (P1: Paved Paths, P2: Tool-Specific, P3: AI Catch-Alls).
- 16:50 - Short-Circuiting Best Practices: How using allowed lists early in a workflow quickly bypasses known-good behavior.
- 29:12 - Deploying TINA: Integrating the Triage and Investigation Agent directly into SOAR playbooks for deeper dynamic triage.
- 31:03 - The Feedback Loop: Why establishing feedback loops is the only way to continuously tune down false positives.
- 32:05 - Error Handling & Failure Recovery: How to configure "skip step" settings and handle offline or unresponsive API integrations.
- 38:10 - Live Demo - Building the Block: Step-by-step creation of a URL Triage block, extracting domains, and executing custom list checks in real time.
- 40:02 - Live Demo - Running TINA & Approvals: Dragging TINA onto the canvas, parsing JSON verdicts, and generating out-of-band approval links.
- 46:45 - Live Q&A: Tal answers live audience questions regarding TINA licensing, parallel branches, and tuning risk thresholds in VirusTotal.

