Google SecOps introduces AI-powered Detection Engineering Agent and Event Simulation
Google SecOps now offers new capabilities in public preview: the AI-powered Detection Engineering Agent and Event Simulation. The Detection Engineering Agent assists security teams in evaluating threat coverage, extracting intelligence, and automatically drafting YARA-L detection rules. Event simulation allows programmatic delivery of realistic threat sequences into the ingestion pipeline, enabling full-funnel detection coverage evaluation within Google SecOps. These features accelerate risk mitigation, improve custom security automation time-to-value, and help verify the entire detection lifecycle from UDM normalization to alerting.
- →[Spotlight Feature] Evaluate threat coverage and generate rules with the Detection Engineering Agent
- →[Spotlight Feature] Event simulation for detection coverage evaluation
Features (2) ›
- Google SecOps [Spotlight Feature] Evaluate threat coverage and generate rules with the Detection Engineering Agent
[Spotlight Feature] Evaluate threat coverage and generate rules with the Detection Engineering Agent This feature is in public preview. You can now evaluate and strengthen your Google SecOps security posture against emerging threats using the Detection Engineering Agent. This AI-powered assistant helps you extract threat intelligence and automatically draft YARA-L detection rules, drastically improves time-to-value for custom security automation and accelerating risk mitigation. The agent is accessible using Model Context Protocol (MCP) tools operated by compatible AI clients (such as Google A
- Google SecOps [Spotlight Feature] Event simulation for detection coverage evaluation
[Spotlight Feature] Event simulation for detection coverage evaluation This feature is in public preview. You can now programmatically deliver realistic threat sequences into the live ingestion pipeline using event simulation. Event simulation provides a full-funnel detection coverage evaluation framework embedded directly within Google SecOps, enabling detection engineering and SOC teams to verify the entire detection lifecycle—from UDM normalization to multi-event correlation and alerting—while preserving production SOC workflows. As a core capability of the Detection Engineering Agent (DEA)
https://docs.cloud.google.com/release-notes#August_18_2026
Related releases
- Bringing gVisor Sandboxes to Distributed Ray Clusters on Google Cloud Google Cloud Blog ·
- Introducing Gemini Enterprise for Financial Services Google Cloud Blog ·
- Google Cloud Introduces Gemini Enterprise for Legal AI Solution Google Cloud Blog ·
- Anthos Config Management gets security updates and monitoring controls Google Cloud release notes ·
- Google SecOps SIEM Adds Unroll Processor for Data Processing Pipelines Google Cloud release notes ·
- Container Optimized OS Updates Address Linux Kernel Vulnerabilities and Package Upgrades Google Cloud release notes ·