← Back to list

What’s New in Google SecOps: 2026–03–22

What’s New in Google SecOps for the interval March 16th through March 22nd, 2026.

Chris Martin (@thatsiemguy) · 2026-03-22 11:57 · 2 claps · 7.3 min read
#google-secops #chronicle-siem #chronicle-soar #google-cloud-security #google-threat-intel
Open on Medium ↗

What’s New in Google SecOps: 2026–03–22

What’s New in Google SecOps for the interval March 16th through March 22nd, 2026.

What’s New in Google SecOps, March 22nd 2026

What’s New in Google SecOps, March 22nd 2026

Highlights

🎙️ I enjoyed the weekly Cloud Security podcast episode, **AI SOC or AI in a SOC?*, with [Raffael Marty](https://raffy.ch/).*

✍ Lots of good community content this week:

🤖 I’ve added a new section to the report going forward on AI related content that is applicable for Agentic SOC workflows.

🎉 And last but not least, **Register now for Google Cloud Next ‘26! **Google Cloud Security will be there with multiple booths:

  • Google Cloud Next ’26 is an upcoming event in Las Vegas, inviting developers to register and experience the latest in AI, security, and product launches [Read More]

Product Updates & New Features

Google SecOps

🚀 SecOps Release Notes

  • Google Chronicle SecOps has introduced a new feature, currently in preview, that allows users to view Triage and Investigation Agent (TIN) results and verdict summaries directly within the Case Summary view for real-time updates and automated verdicts [Read More]

Gemini TIN Agent results now visible with Gemini Case Summaries

Gemini TIN Agent results now visible with Gemini Case Summaries

  • Unified Feature Role-based Access Control (RBAC) is now generally available for Google SecOps, enabling administrators to manage feature access for SIEM and SOAR through Google Cloud IAM [Read More]
  • The second phase of the SOAR migration to Google Cloud has been extended by three months, with the new completion date set for September 30, 2026 [Read More]

📝 **New Docs: SecOps > Optimize detection and reporting performance**

  • This document outlines how to optimize detection and reporting performance within Google SecOps SIEM by focusing on reducing the Total Mean Time To Detect (MTTD): Log-ingestion latency, Rule-processing latency, and Case-acknowledgement latency [Read More]

SecOps SIEM

📝🚀 **New Docs: SIEM > Set Customized Schedule**

  • This document introduces customizable schedules for multi-event rules within Google SecOps SIEM, a Pre-GA feature.
  • Provides granular control over when multi-event detection rules run, allowing users to define specific buffer periods instead of relying on system defaults. This aims to improve detection latency, data integrity, and reduce false negatives caused by late-arriving data or delayed enrichment [Read More]

Configuring customized schedules for YL2 Rules

Configuring customized schedules for YL2 Rules

📑 **Updated Docs: SIEM > Detection: Run Frequency**

  • This document has been expanded into a comprehensive guide on managing Google SecOps rule schedules. Key updates include:
  • True-Up Runs & Enrichment: Introduces automatic background re-evaluations (at initial, 5-hour, and 24-hour marks) to capture late-arriving or newly enriched data.
  • Scheduling Mechanics: Details Real-time, Hourly, and Daily default schedules, clarifying how single-event versus multi-event rules process data.
  • Operational Guidance: Adds prerequisites (required roles, UDM mapping), specific use cases, and expanded troubleshooting for latency, error remediation, and detection discrepancies [Read More]
  • These docs provide additional clarity on SecOps functionality as related to the above Scheduled Rule private preview feature

📝 **New Docs: SIEM > Set up a SIEM HTTPS webhook feed**

  • This document outlines the process for setting up an HTTPS webhook feed to ingest data into Google SecOps SIEM
  • ⚠️ Batches of data sent through Webhook feeds may experience ingestion delays if the request size or QPS limits are set too low. The HTTPS push endpoint supports a maximum request size of 4 MB per request and a maximum throughput of 15 K QPS per Google SecOps instance [Read More]

📝 **New Docs: SIEM > Understand ingestion metrics**

  • This article from Google Security Operations explains how to understand ingestion metrics, specifically in the context of migrating legacy SIEM infrastructure to Google Cloud [Read More]

📝 **New Docs: SIEM > Ingestion methods and data types**

  • The article from Google Security Operations details data ingestion methods and types, focusing on how raw logs are converted into a consistent, vendor-agnostic Unified Data Model (UDM) format [Read More]

📑 **Updated Docs: SIEM > Data Health Monitoring And Troubleshooting Dashboard**

  • The key changes in this document revolve around the introduction and deep integration of “irregularity detection” into the Google Security Operations Health Hub, alongside existing “failure” detection.

Updated explanation of the Irregulatory Detection capabilities of the Health Hub preview dashboard

Updated explanation of the Irregulatory Detection capabilities of the Health Hub preview dashboard

📑 **Updated Docs: SIEM > VPC-SC For SecOps**

  • The document has been updated to provide more detailed and significantly expanded VPC Service Controls configuration instructions, particularly for SOAR, SIEM, and Security Command Center integrations.

SecOps SOAR

📝🚀 **New Docs: SOAR > Playbooks: Agentic Automation**

  • This document introduces Agentic Automation in Google Security Operations, a Pre-GA feature designed to embed AI Agents directly into security workflows.
  • It allows for dynamic, adaptive automation by combining AI agents with deterministic steps, enabling AI to “reason” through unplanned variables that traditional hard-coded automation struggles with (e.g., new use cases, failures, missing information). Users remain in control of critical actions [Read More]

Agentic Automation in SOAR Playbooks

Agentic Automation in SOAR Playbooks

Google Threat Intelligence

🚀 **March 16, 2026: SCIM Support, Incident Response Guide, Splunk Integration Updates and more**

  • This article is a changelog announcing new features like SCIM support and Splunk integration updates, alongside an incident response guide and ongoing ‘Google TI Mondays’ tips for product adoption. [Read More]

SCIM integration for user lifecycle management in Google TI

SCIM integration for user lifecycle management in Google TI

✍️** The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors**

  • Google Threat Intelligence Group has identified ‘DarkSword,’ a new iOS full-chain exploit leveraging multiple zero-day vulnerabilities to compromise devices, which has been adopted by various threat actors [Read More]

✍️** Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape**

  • This article analyzes the evolving tactics, techniques, and procedures (TTPs) of financially motivated ransomware threat actors within a shifting threat landscape [Read More]

BindPlane

🚀 **The AI-Driven Security Pipeline: Bindplane at RSAC 2026 Conference**

  • Bindplane is set to unveil new AI-driven security capabilities, including Pipeline Intelligence and Global Intelligence for automating security telemetry pipelines, at the RSAC 2026 conference. [Read More]

You can now test a raw log against a SecOps parser from within the BindPlane UI

You can now test a raw log against a SecOps parser from within the BindPlane UI

Adoption Guides & Deep Dives

** Automating Stale Account Suspensions with Google SecOps and Azure AD**

  • This article from Darren Swift details how Google SecOps can be used to automate the suspension of stale and inactive user accounts, integrating with Azure AD to reduce security liabilities and streamline compliance [Read More]

** New to Google SecOps: What Difference Does It Make?**

  • This article from John Stoner introduces timestamp.diff, a new function within Google SecOps designed to calculate the difference between two timestamps, building upon previously discussed timestamp manipulation functions [Read More]

✍️ **Anton’s Security Blog Quarterly Q1 2026**

  • This article is a quarterly review from Anton Chuvakin’s Security Blog, summarizing security-related topics and updates for the first quarter of 2026 [Read More]

✍️ **Raffy: SIEM Is Not Dead. It Just Stopped Moving Fast Enough**

  • The article from Raffael Marty asserts that SIEM is not dead but needs to evolve, discussing its current state, future alongside AI SOC, and the resurgence of network telemetry [Read More]

✍️ **Deciphering Google SecOps SOAR IAM Access Post Migration**

Community & Events

** New Mandiant special report: AI risk and resilience**

  • Mandiant and Google Threat Intelligence have released a special report on AI risk and resilience, detailing how adversarial misuse of AI is changing the speed and scale of attacks and urging defenders to adapt their strategies [Read More]

🎙️🔥 **EP267 AI SOC or AI in a SOC? Cutting Through Hype, Pricing Models, and SIEM Detection Efficacy with Raffy Marty**

  • This podcast episode features Raffael Marty discussing the role of AI within a SOC, contrasting it with traditional SIEMs, and evaluating the hype, pricing models, and detection efficacy of these technologies [Read More]

[embed]

Workshop + CTF Event Results

  • The Google Cloud Community successfully hosted a virtual workshop and CTF event, attracting 599 participants, and the results have now been published [Read More]
  • If you took part, see the results here 👏

AI

ℹ️ Introducing a new section to the weekly What’s New dedicated to Google’s AI ecosystem, including Gemini, the Gemini CLI, Google ADK, and Agents. Whether you are interested in learning about Agentic SOC workflows or are actively building them, you will find highly relevant content here

📝** Building Distributed AI Agents**

  • The article discusses the challenges and complexities of building reliable, production-ready distributed AI agents that integrate seamlessly with existing applications like React or Node.js, going beyond simple prototypes [Read More]

📝** Build a Multi-Agent System for Expert Content with Google ADK, MCP and Cloud Run — Part 1**

  • This article outlines how to build a multi-agent system for expert content using Google ADK, MCP, and Cloud Run, aimed at accelerating developer journeys for secure AI workloads on Google Cloud [Read More]

📝** Announcing the Colab MCP Server: Connect Any AI Agent to Google Colab**

  • Google has announced the Colab MCP Server, a new tool designed to connect any AI agent, such as Gemini CLI or Claude Code, to Google Colab for easier local prototyping [Read More]

📝** Developer’s Guide to AI Agent Protocols**

  • Google has introduced a suite of six AI agent protocols (like MCP and A2A) and an Agent Development Kit (ADK) to standardize how AI agents access data and communicate. This aims to eliminate custom integration code, simplifying complex task management for developers, exemplified by a ‘kitchen manager’ agent [Read More]

SecOps Platform Issues

** RESOLVED: Some customers using Mandiant Digital Threat Intelligence may be experiencing issues accessing certain alerts**

  • Some Mandiant Digital Threat Intelligence customers are experiencing issues accessing alerts generated on March 20, 2026, between 8 AM and 9 AM PDT. Google’s engineering team has identified the cause but does not yet have an ETA for resolution [Read More]

** RESOLVED: [Informational] Service update notification for Google SecOps.**

  • Google SecOps will perform a scheduled service update on March 19, 2026, between 18:00 PDT and 20:00 PDT [Read More]

메타데이터
post_id
fb5fe02b627b
slug
whats-new-in-google-secops-2026-03-22-fb5fe02b627b
url
https://medium.com/@thatsiemguy/whats-new-in-google-secops-2026-03-22-fb5fe02b627b
canonical_url
https://medium.com/@thatsiemguy/whats-new-in-google-secops-2026-03-22-fb5fe02b627b
author_url
https://medium.com/@thatsiemguy
status
ok
fetched_at
2026-07-11 17:44:30