SEC536: Adversarial AI - Penetration Testing AI Systems

SIEM's complicated evolution has resulted in unsustainable cost increases, scope creep, and the occasional declaration that the product space is essentially dead. Thanks to deep expertise in search and data management, access to OSINT and frontline intelligence, and AI-infused features, Google SecOps demonstrates that the SIEM still has plenty of gas in the tank. Discover how SecOps is ushering in the "SIEM's Third Act" by addressing the limitations of traditional SIEMs and empowering security teams with cutting-edge tools for threat-informed defense.

Google SecOps is a SIEM platform that consolidates data ingestion, threat detection, investigation, and SOAR automation, built on Google's search infrastructure and enhanced with Gemini AI, aiming to avoid the complexity and scope creep common in older SIEM products.
Yes — analysts can enter questions in plain English, and Gemini automatically converts them into Unified Data Model (UDM) search syntax, eliminating the need to write native query syntax.
Google SecOps integrates Google Threat Intelligence, which draws on Mandiant frontline incident response data, VirusTotal crowd-sourced intelligence, and Chrome Safe Browsing data from billions of devices.
Google SecOps includes SOAR automation built on the Siemplify platform, featuring a graphical Playbook Designer and a Gemini-powered Playbook Assistant that can generate or modify playbooks from natural language prompts.