SAN FRANCISCO — Google Cloud at this week's RSA Conference 2020 announced new security features that use Chronicle’s security analytics platform and threat response integration between Chronicle and Palo Alto Networks.

This comes a year after Chronicle’s product launch event during which executives insisted the startup was completely independent from sister company Google — and not going anywhere. “The important thing to realize is we’re in this for the long haul,” then CEO Stephen Gillett said at the event in Google’s San Francisco office. He added that the company's Backstory platform “is the first of what will be many offerings and capabilities over time.” And then three months later Chronicle merged with Google Cloud.

Backstory is Chronicle’s cloud-based security information and event management (SIEM) platform built on Google’s infrastructure. The platform now allows customers to detect threats using YARA-L, a rules language built specifically for modern threats and behaviors, including types described in Mitre ATT&CK. “This advanced threat detection provides massively scalable, real-time and retroactive rule execution,” wrote Google Cloud Security VP Sunil Potti in a blog post.

Google also added a new Chronicle capability it calls intelligent data fusion, which combines a new data model and the ability to automatically link multiple events into a single timeline. Palo Alto Networks Cortex XSOAR is Google’s first partner to integrate with this.

And finally, Google made available two new fraud prevention services. reCAPTCHA Enterprise, which is based on Google’s existing reCAPTCHA technology, helps protect websites from fraudulent activities like scraping, credential misuse, and automated account creation. This includes commercial-grad bot detection to ensure that a login attempt is being made by a legitimate user and not a bot.

Meanwhile, its Web Risk API, which is built on Google Safe Browsing that examines billions of URLs each day, is an enterprise service that checks URLs against Google list of unsafe web resources. The goal here is to protect businesses by preventing access to or inclusion of malicious content by employees or users.

Chronicle’s Two-Year Rollercoaster

This year’s RSA Conference caps a two-year rollercoaster for Chronicle, which was originally part of Alphabet’s secretive X research lab and then launched as an independent business in January 2018.

Since its launch, Chronicle has teased a “Google-level” security platform. It finally released the long-awaited Backstory platform last year the day before the RSA Conference 2019 officially started. And just months later, Google Cloud CEO Thomas Kurian announced that the security startup would merge with Google Cloud. Not everyone was happy about the merger, and reports soon surfaced that Chronicle “is dead,” and that “Stephen [Gillett] and Google killed it.”

A Motherboard report noted Gillett and the company’s chief security officer’s departures, and reported that other Chronicle workers quit because they believed Chronicle lost its original vision. It also said they felt betrayed by Gillett and the rest of Chronicle management.

While Google didn’t directly address these reports, it did appear to try to do some damage control shortly after, touting Chronicle’s mission to “give good the advantage.”

“Security is one of the key solutions we are focused on delivering at Google Cloud,  and with Chronicle we’ll reimagine enterprise security services to keep customers safe on GCP, on premises, or on other clouds,” Potti wrote in a November 2019 blog post.

Finally, the cloud provider has made good on its promise to integrate Chronicle’s security services into Google Cloud. But will this mean a smoother ride from here on out for the beleaguered security startup? That’s still up in the air.