Google Cloud today announced its latest enhancement to the Chronicle Security Operations to streamline and automate threat detection, investigation and response (TDIR) by unifying its components into a single console, which includes its security information and event management (SIEM), security orchestration, automation and Response (SOAR) and attack surface management technology from Mandiant.

The tech giant introduced the Chronicle Security Operations last year, which is a cloud software suite that unifies Chronicle’s SIEM, SOAR from Google’s Siemplify acquisition and threat intelligence from Google Cloud.

The new update, now in preview, offers a user interface and experience unification, Chris Corde, director of product management of security operations at Google Cloud, told SDxCentral.

Each component such as SIEM, SOAR and attack surface management has its own console/dashboard. This unification eliminates the need for users to toggle between separate interfaces or products, streamlining the workflow for security operations. Alerts in Chronicle are now automatically grouped into cases on behalf of the users, making it easier for them to focus on triage and allowing for a more enriched and contextualized understanding of security events, he added.

“The real difference now is we basically completely removed any idea of SOAR being a separate category or a separate product, and now it's truly a unified experience from top to bottom where cases are now natively integrated into Chronicle,” Corde said.

Chronicle Security Operations offers applied intelligence

Chronicle Security Operations also groups its “brokered intelligence” from various data sources like VirusTotal, Mandiant, Google Cloud and third-parties and automates the event matching.

The vendor added the new Applied Threat Intelligence feature into the platform, currently available in preview. It leverages Chronicle's scalability, these threat intelligence sources, and artificial intelligence (AI) capabilities to prioritize threats and enrich a relevant event that matches a threat indicator with threat actors, threat campaigns, or malware family associations that can be used for custom searches or detections.

"What you're getting in Chronicle is basically the best of all of those intel [intelligence] sources,” Corde said. “We're actually taking every single event that comes in and matching that against the intel platforms that we have available to us, and that can be across our customer base, trillions of events that are being ingested at any given time.”

Google Chronicle adds Mandiant attack surface management

At this week’s Mandiant mWISE Conference 2023, Google Cloud also announced the integration of Mandiant attack surface management technology into Chronicle Security Operations.

The integration comes after Google completed its all-cash acquisition of the cybersecurity firm for around $5.4 billion last September. Besides the security technologies, Mandiant also brings more than 300 intelligence analysts and other security experts to the table.

The Mandiant attack surface management technology is designed to correlate and enrich investigations with contextual awareness and business risk understanding.

“In many cases, traditional SIEMs are not very good at understanding context. And what I mean by context is kind of business risks — What is my environment? How is my environment setup that might be presenting or creating additional risks that I should be aware of?”Corde said.

With this understanding, security teams can now prioritize their investigations and remediation efforts based on the exposures that could potentially have the most significant business impact. "We can bring a lot of that proactive intelligence to you, so that you understand what things are the most risky inside of your environment," he added.