UPDATED 15:49 EDT / SEPTEMBER 19 2023

SECURITY

Google Cloud updates its Chronicle security tool for greater visibility in attack surface management

Google Cloud announced steps this week to help security operations teams analyze the tremendous amount of data now flowing through network operations.

On Monday, the cloud provider updated its Chronicle Security Operations platform to combine security information and event management, or SIEM, along with security orchestration automation and response, or SOAR, adding threat intelligence from Mandiant to help visibility for organizations in attack surface management.

“How do you prioritize those things that are the ones that are the most critical for you to work on?” asked Jeff Reed (pictured), vice president of product for cloud security at Google LLC. “If it’s both a potential problem and we think it’s exploitable externally, that increases the prioritization that you should put on that. That’s where bringing the visibility on the attack surface management combined with the richness and the alerts and findings that we have in the SIEM and SOAR environment really makes sense.”

Reed spoke with theCUBE industry analysts Rebecca Knight and Rob Strechay at the mWISE Conference, in an exclusive broadcast on theCUBE. They discussed the company’s most recent announcements and challenges facing enterprise security teams today. (* Disclosure below.)

Looking for compromise

The integration of Mandiant’s threat intelligence is designed to help customers more rapidly and accurately spot indicators of compromise, or IOC, according to Reed.

“We can retroactively search all the customers using Chronicle with Mandiant breach analytics for the past year,” he said. “Have we seen that IOC in their environment ever before? We’ve identified the specific vector of a threat and how we make sure that that’s not happening with any of our customers.”

The Chronicle updates include an ability to preview chatbot Duet AI’s natural language questions and summarization capabilities.

“What we do in Duet on Chronicle is the ability to use a natural language search for your unified data model query,” Reed said. “Instead of requiring someone who is just starting to understand that query language right away, you can just say: ‘Who are all the users that downloaded files that have personal identifiable information over the last seven days?’ We generate that query on behalf of the SOC analysts.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of the mWISE Conference:

(* Disclosure: Google Cloud sponsored this segment of theCUBE. Neither Google Cloud nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.