Skip to main content

Meet SecOps: Your Agentic SOC

  • August 18, 2026
  • 0 replies
  • 13 views

matthewnichols
Community Manager
Forum|alt.badge.img+20

 

In this webinar session, Regional Security Architects Sumit Patel and Ethan Gardiner dive deep into how generative AI and autonomous agentic workflows are transforming modern SOC.

As cyber adversaries leverage machine-scale automation and large language models (LLMs)—driving a 109% increase in threat campaigns year-over-year—traditional human-scale SOC workflows struggle to keep pace.

This session explores how Google SecOps operationalizes the Agentic SOC to achieve sub-hour detection and sub-minute mean time to remediation (MTTR). Built upon Google’s Unified Data Model (UDM) and full AI stack (from TPUs to Gemini), the platform introduces semi-autonomous agents that handle repetitive ingestion parsing, alert triage, proactive threat hunting, and threat intelligence synthesis—empowering analysts to make defendable, data-driven decisions faster.

 

What You Can Expect

  • The Architectural Foundation: Why a unified data model (UDM) with ingestion-time enrichment and decoupled cloud compute is vital for real-time AI performance.

  • A Day in the Life of an Analyst: Live walkthroughs of out-of-the-box Gemini case summaries, visual entity relationship graphs, and automated SOAR pending actions.

  • Autonomous Investigation in Action: How the Triage Agent applies Mandiant-tested methodologies to investigate process trees and command lines while maintaining full auditability.

  • Proactive Threat Hunting: Real-world execution of the new Threat Hunting Agent identifying complex threats (e.g., Mimikatz) in minutes rather than days.

  • Strategic Intel Generation: How the Google Threat Intelligence (GTI) Agent synthesizes curated Mandiant intel and VirusTotal telemetry into actionable industry briefings.

 

 

Key Discussion Points & Timestamps
 

08:50 - Speaker Intros & The Threat Landscape: Machine-scale threats vs. legacy SOC workflows; addressing increased volume and baseline attack sophistication.
14:15 - The Agentic SOC Vision & AI Stack: Moving from assistive AI to semi-autonomous agents; Google’s full-stack advantage (TPU hardware, cloud infrastructure, and Gemini).
21:48 - 3-Pillar Roadmap: Data, Detection & Alert: Upcoming agents including AI Log Parsing, Data Management, Threat Hunting, Triage, and Response.
25:41 - Data Architecture: UDM & Entity Graph: How 700+ parsers, continuous entity extraction, and VirusTotal enrichment feed contextual data into AI models without impacting search concurrency.
32:13 - Live Demo Analyst Workflow & Triage Agent:  Gemini multi-alert case summaries, interactive Security Graph timeline, and Mandiant-guided automated triage steps.
41:59 - AI Governance, Hallucinations & UEBA: Safety harness tuning, auditable reasoning trails, Google Secure AI Framework (SAIF), and entity risk analytics.
47:07 - Live Demo Autonomous Threat Hunting Agent: Executing a non-deterministic hunt across logs, scripts, and memory access events (Mimikatz use case).
51:45 - Google Threat Intelligence (GTI) & Intel Agent: Leveraging Mandiant curated profiles, dark web monitoring, natural language threat reports, and tenant IOC matching.
58:40 - Audience Q&A & Wrap-Up: Practical guidance on HIPAA/compliance, data redaction (BindPlane), Model Context Protocol (MCP) support, and token management strategies.