Google Security Operations release notes

This page documents production updates to Google Security Operations. You can periodically check this page for announcements related to new or updated features, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 18, 2026

Feature

Resizable side panels in the Investigation Management experience

You can now dynamically resize the Case preview and Alert and detection preview side panels in the revamped Investigation Management experience in Google SecOps. You can adjust the panel width using your mouse or keyboard shortcuts to view detailed telemetry, parsed UDM records, and raw logs without navigating away from your main case queue.

To explore the complete triage workflow, see Investigation and case management overview.

September 15, 2026

Feature

Grok filter match_all option in parser syntax

The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match.

For more information, see Parser syntax reference.

September 14, 2026

Feature

[Spotlight Feature] GoogleSQL query support in Search

This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and powerful industry-standard alternative to YARA-L 2.0. GoogleSQL is optimized for broad data exploration, statistical aggregation, and deep-dive ad hoc investigations. You can query telemetry tables including but not limited to UDM events, entity graphs, detection rules, and case management data—using either standard declarative SQL or the linear, sequential Piped SQL syntax.

For more information, see Get started with GoogleSQL.

Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

September 11, 2026

Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

September 06, 2026

Feature

[Spotlight Feature] Case playbooks

This feature is in preview. Google SecOps now supports case playbooks. You can run playbooks or execute manual actions across an entire case container rather than individual alerts, consolidating response tasks and reducing redundant operations during investigations.

For more information, see Case playbooks overview.

Feature

[Spotlight Feature] Reaction triggers

This feature is in preview. Google SecOps now supports reaction triggers. As post-ingestion triggers, they allow playbooks to automatically fire in response to real-time case or alert updates during active investigations, such as changes to the case assignee, case tags, alert priority, or newly added entities.

For more information, see Use reaction triggers in playbooks.

September 03, 2026

Feature

Self-service Bindplane Enterprise license download

This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents.

For more information, see Bindplane Enterprise (Google Edition).

August 31, 2026

Feature

[Spotlight Feature] Customizable schedules for multi-event rules general availability

The customizable schedules for multi-event rules feature is now in General Availability (GA).

Customizable schedules give security teams granular control and transparency over how multi-event rules execute in Google SecOps, and provide the following capabilities:

  • Configure settlement delays: Set first-run delay offsets (from 1 minute up to 48 hours) to account for log ingestion latency and reduce false negatives.
  • Leverage automated true-up runs: Automatically re-evaluate time windows at 4 hours (and optionally 30 hours for full context enrichment) to capture late-arriving logs.
  • Migrate legacy rules: Upgrade existing custom multi-event rules to customizable schedules directly from the Rules Dashboard.

To manage rule schedules with custom IAM roles, make sure your roles include chronicle.rules.modifyRules and chronicle.ruleDeployments.update. Predefined IAM roles include these permissions automatically.

For more information, see Configure customized schedules for rules and Understand rule run scheduling.

August 27, 2026

Announcement

Scheduled maintenance

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 30. During this window, your system will experience a brief period of downtime. You don't need to take any action.

August 26, 2026

Feature

[Spotlight Feature] Mandiant Frontline Threats rule packs

Curated Detections has been enhanced with additional Mandiant Frontline Threats detections for Linux, MacOS, and Google Cloud. The following rule packs have been added to the Content Hub:

August 24, 2026

Feature

Unroll Processor for Data Processing Pipelines

Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing arrays or slices of events into multiple individual log events prior to parsing and ingestion.

Key details:

  • Event Breaking Capability: Automatically expands log arrays into discrete log events.
  • Pre-parsing Requirement: The Unroll processor requires structured data inputs. Raw string payloads must first be parsed using a Transform processor (e.g., set(body, ParseJSON(body))) positioned prior to the Unroll processor in the pipeline execution sequence.

For details on configuring data processing pipelines and processors, see Set up and manage data processing pipelines.

Feature

[Spotlight Feature] Operations in Emerging Threats Center

Google SecOps now supports Operations in the Emerging Threats Center feed to provide rapid visibility into threat activity details involving the targeting of a single organization. Operations complement global Campaigns by providing granular threat intelligence derived from frontline investigations, such as Managed Threat Defense (MTD) engagements. For more information, see Operations in Emerging Threats.

Key capabilities include:

  • Focused threat insights: Zero in on localized adversary activity and personalized attack vectors specific to individual missions.
  • Holistic threat mapping: View Operations alongside global Campaigns to see the full scope of adversary tactics, techniques, and procedures (TTPs).

August 21, 2026

Feature

[Spotlight Feature] Relative time filtering in Google SecOps

This feature is in public preview. Google SecOps has updated how relative time filters calculate data ranges. You can now choose from three distinct, mathematically precise operators: Past, Previous, and Current. This change eliminates ambiguity between rolling windows and calendar-aligned periods, ensuring consistent behavior across all time units (like seconds, minutes, hours, days, weeks, months, years) and aligning SecOps dashboards with Search and other Google tools (such as Looker).

For more information, see the Relative time range section of the Understand search guide.

August 20, 2026

Feature

Side-by-side view on the Alerts & Detections tab in Cases

This feature is in public preview. The Alerts & Detections tab in the revamped Investigation Management experience now supports a Side-by-side view layout.

You can switch between the default List view and the Side-by-side view to inspect an alert or detection's detailed metadata, status, priority, creation date, and Gemini investigation insights in an adjacent side pane without navigating away from the main list.

For more information, see Investigation and case management overview.

August 18, 2026

Feature

[Spotlight Feature] Evaluate threat coverage and generate rules with the Detection Engineering Agent

This feature is in public preview. You can now evaluate and strengthen your Google SecOps security posture against emerging threats using the Detection Engineering Agent. This AI-powered assistant helps you extract threat intelligence and automatically draft YARA-L detection rules, drastically improves time-to-value for custom security automation and accelerating risk mitigation. The agent is accessible using Model Context Protocol (MCP) tools operated by compatible AI clients (such as Google Antigravity or Claude Code). For more information, see Evaluate threat coverage with the Detection Engineering Agent.

Feature

[Spotlight Feature] Event simulation for detection coverage evaluation

This feature is in public preview. You can now programmatically deliver realistic threat sequences into the live ingestion pipeline using event simulation. Event simulation provides a full-funnel detection coverage evaluation framework embedded directly within Google SecOps, enabling detection engineering and SOC teams to verify the entire detection lifecycle—from UDM normalization to multi-event correlation and alerting—while preserving production SOC workflows.

As a core capability of the Detection Engineering Agent (DEA) architecture, event simulation connects Google SecOps MCP tools with AI assistance (such as Gemini) to automate threat intel processing, synthetic telemetry generation, and YARA-L 2.0 rule coverage evaluation.

For more information, see Use event simulation for detection coverage evaluation.

August 14, 2026

Feature

[Spotlight Feature] Monitor your data latency with the Health Hub

This feature is in public preview. The Health Hub now includes two new tables to track the ingestion latency at both the source level and the log-type level. In addition, you can select a specific source or log type to open the Data Health Deep Dive page and view detailed information about ingestion latency. For more information, see Monitor health of data sources.

Key capabilities include:

  • Improve end-to-end visibility and reduce mean time to debug (MTTD): Google SecOps calculates latency at both the source level and the log type level to improve end-to-end visibility and help reduce the mean time to debug (MTTD) for delayed logs.
  • Monitor ingestion latency by source: View the ingestion latency for each individual data source.
  • Monitor ingestion latency by log type: View the ingestion latency for each individual log type.
  • View detailed information about ingestion latency: Select a specific source or log type to open the Data Health Deep Dive page and view detailed information about ingestion latency.

August 13, 2026

Announcement

Scheduled Maintenance

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 16. During this window, your system will experience a brief period of downtime. No customer action is required.

August 12, 2026

Feature

[Spotlight Feature] Analyze feed activity with Cloud Logging

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in the Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

  • Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
  • Debug feeds: Use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
  • Filter routed logs: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.

For more information, see Analyze feed activity with Cloud Logging.

August 09, 2026

Feature

Updated rich-text editor

Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.

Key changes include:

  • Simplified typography: Choose font sizes using semantic options (Small, Normal, Large, Huge). Legacy font sizes on existing text are preserved.
  • Streamlined tables: You can insert or remove entire tables. Formatting inside table cells is no longer supported.
  • Toolbar cleanup: Removed the Cut, Copy, and Paste buttons from the toolbar. Standard OS keyboard shortcuts remain supported.
  • Visual alignment: Improved visual consistency between editor content during editing and after submission.

August 03, 2026

Feature

[Spotlight Feature] Threat Hunt Agent

The Threat Hunt Agent is now available in Public Preview for Google SecOps Enterprise Plus customers. Powered by Gemini and grounded in Google Threat Intelligence (GTI), Mandiant frontline expertise, and the MITRE ATT&CK® framework, the Threat Hunt Agent autonomously automates proactive threat hunting across your historical security telemetry. For more information, see Threat Hunt Agent.

Key capabilities include:

  • Autonomous hunt planning: Generates structured hunting plans tailored to specific threat actors, campaigns, malware families, software toolkits, or MITRE ATT&CK techniques.
  • Automated case creation and determinations: Synthesizes findings into summaries, assigns a verdict (Substantial Evidence, Evidence Found, or Threat Not Found), and automatically creates a dedicated case in Case Management.
  • Automated query translation and execution: Converts investigative hypotheses into YARA-L 2.0 search queries and executes against historical security telemetry.
  • AI-driven evidence extraction: Filters out routine background noise to isolate high-fidelity forensic evidence (hostnames, user accounts, and command lines).
Announcement

The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026. For more information, refer to the SOAR migration guide.

July 29, 2026

Change

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • Airlock Digital Application Allowlisting (AIRLOCK_DIGITAL)
  • AIX system (AIX_SYSTEM)
  • Akamai DataStream 2 (AKAMAI_DATASTREAM_2)
  • Akamai SIEM Connector (AKAMAI_SIEM_CONNECTOR)
  • Apache (APACHE)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Armis Alerts (ARMIS_ALERTS)
  • Aruba Switch (ARUBA_SWITCH)
  • Atlassian Cloud Admin Audit (ATLASSIAN_AUDIT)
  • Linux Auditing System (AuditD) (AUDITD)
  • Avaya Aura Experience Portal (AVAYA_AURA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Control Tower (AWS_CONTROL_TOWER)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Azure AD (AZURE_AD)