During the Google Cloud Next '23 event, Google announced the integration of its generative artificial intelligence (AI) collaborator, dubbed Duet AI, with its security services, including Mandiant threat intelligence, Chronicle Security Operations and Security Command Center. The move aims to optimize the threat detection and response process, streamline security workflows and boost productivity among security professionals.

Duet AI is a generative AI technology that is embedded in Google Workspace and Google Cloud. The tech giant claims the tool can summarize and classify threat information, translate natural language searches into queries and offer suggested next steps for remediating issues.

This tool can be used to support security operations in three fundamental ways: first, stalking threats by detecting and stopping novel threats or offering smarter visibility into the degree of maliciousness or even security vulnerabilities in code. Second, reducing the burden of handling hundreds of security tools in daily operations. And third, scaling talent to help level-one operators be as productive as high-level ones, Jeff Reed, VP of product-cloud security at Google, explained during the pre-event press conference.

“Google Cloud is the only leading security provider that brings together the essential combination of frontline intelligence and expertise, a modern SecOps platform and a trusted cloud foundation, all infused with the power of gen Al, to help drive the security outcomes you're looking to achieve,” Google Cloud CEO Thomas Kurian touted in a blog post.

Google Cloud adds genAI features to Mandiant threat intelligence

Google Cloud is integrating Duet AI into Mandiant threat intelligence services, aiming to expedite threat assessment and operationalize threat intelligence across an organization.

The tech giant acquired the security vendor Mandiant in an all-cash deal valued at around $5.4 billion last October. Mandiant has more than 600 cybersecurity consultants and over 300 intelligence analysts powering Mandiant Advantage, its managed multivendor extended detection and response (XDR) platform.

Duet AI in Mandiant enables quick summaries of intelligence reports, allowing security teams to customize threat intelligence based on their specific needs. The function is now in preview and expected to be released later this year.

“With Mandate threat intelligence, you get some of the absolute best threat intelligence in the world. We're involved in incident response, and we have the newest and freshest understanding of TTPs [tactics, techniques, and procedures] and IOCs [indicators of compromise],” Reed said.

With the new genAI features, “we've enabled the Mandiant threat intelligence to be summarized using Duet AI, and so you can quickly and easily use it to look at thousands of Mandiant finished intelligence reports, summarize that for what's most specific to you, [and] customize it to the type of audience you want,” he added.

Updates to Chronicle Security Operations

Google Cloud also announced the addition of Duet AI to its Chronicle Security Operations service. Introduced last year, Chronicle is a cloud software suite that unifies Chronicle’s security information and event management (SIEM) tech with the security orchestration, automation and response (SOAR) solutions from Google’s Siemplify acquisition and threat intelligence from Google Cloud.

Integrating with genAI allows natural language queries to be translated into system queries within Chronicle Security Operations. It also summarizes cases and recommends the next steps for investigators.

“So you don't have to be conversant in our unified data model syntax, and you can ask natural language queries, you can then adjust those and it will not only show you the query that we generate, but then you can run it within Chronicle,” Reed said.

At the Google Cloud Next event, Google Cloud also previewed the Mandiant Hunt for Chronicle service, which uses the expertise of Mandiant experts to do threat hunting on top of the Chronicle environments. This enhances the threat detection, investigation and response capabilities of Chronicle Security Operations.

“This service integrates the latest insights into attacker behavior from Mandiant's frontline experts with Chronicle Security Operations' ability to quickly analyze and search security data, helping customers gain elite-level support without the burden of hiring, tooling and training,” Kurian wrote.

Integrating generative AI with Security Command Center

In the Security Command Center, Duet AI will help in summarizing attack paths, making it easier for security teams to understand potential vulnerabilities and make quick decisions for remediation.

Attack path analysis is a growing technique that essentially mimics how a real-world threat actor could exploit security gaps. This helps security teams identify how and where they could be attacked.

Google Cloud had announced in June the addition of attack path simulation to its built-in risk management tool — Security Command Center. That new capability simulates the many ways attackers attempt to infiltrate a cloud environment, then generates attack graphs for security teams along with detailed information on how to remediate issues.

With the help of generative AI, “we're helping to summarize those attack paths so the security teams can quickly understand what are the attack paths and what are the recommended steps to remediate some of those issues,” Reed said.