Google SecOps Enhances Investigation and Case Management (Preview)
Google SecOps has launched a public preview of a revamped Investigation Management experience, designed to handle higher investigation volumes and support new investigation types like retrohunt and threat hunting. This update allows users to track UDM events and detections alongside alerts within cases, offering customizable views and integrated search workflows for improved navigation. The preview is currently limited to single-SIEM deployments and requires manual migration of existing configurations.
Features (1) ›
- Google SecOps [Spotlight Feature] Investigation and case management experience
[Spotlight Feature] Investigation and case management experience This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview . This preview is currently supported only fo
https://docs.cloud.google.com/release-notes#July_26_2026
Related releases
- Cloud SDK 578.0.0: Database Migration default change, AlloyDB backup DR GA, BigQuery improvements Google Cloud release notes ·
- GKE: Opt-out of Arm taint, CORS for Gateways Google Cloud release notes ·
- Confidential VM: August 2026 kernel update may impact AMD SEV-SNP instances Google Cloud release notes ·
- Security Command Center ServiceNow Integration Updates Google Cloud release notes ·
- Compute Engine C4D Instances Increase Hyperdisk Throughput Google Cloud release notes ·
- Spanner allows creating tables without explicit primary keys Google Cloud release notes ·