Google Cloud unveils Google Threat Intelligence, which uses Gemini and combines insights from Mandiant, VirusTotal, and Google to provide faster protection
Launched at RSAC 2024, the new Google Threat Intelligence offering provides faster protection against threats by combining insights from Mandiant …
Context & Ripple Effects
Google Cloud had already expanded Chronicle with threat detection and alerting; Google Threat Intelligence adds a shared intelligence layer built from Mandiant, VirusTotal and Google data, with Gemini as the interface for faster analysis. It also arrives shortly after Google described ways to ground Gemini responses in reliable enterprise sources, a relevant capability when analysts need answers tied to evidence.
The launch is an early step in Google Cloud’s effort to turn distinct security assets into a more unified operating surface—a direction later made explicit in Unified Security’s consolidation of operations, cloud security and threat intelligence.
First-order effects
- Security teams using Google Cloud gain a single offering intended to correlate threat signals from Mandiant, VirusTotal and Google, with Gemini helping accelerate investigation and protection workflows.
- Google Cloud makes its proprietary and acquired threat-intelligence assets more directly productizable, rather than leaving customers to assemble them across separate tools and feeds.
Second-order effects
- The combined offering raises the bar for security vendors that compete on individual data feeds or standalone analyst tools: they must show comparable intelligence breadth, workflow integration or AI-assisted triage.
- Customers may consolidate portions of their threat-intelligence and security-operations stack around Google Cloud if the shared data and Gemini workflow reduce manual correlation work.
Third-order effects
- If integrated intelligence proves more useful than disconnected tools, cloud-security competition will increasingly hinge on ownership of telemetry, research networks and AI interfaces—not only detection features.
- The later progression toward AI agents for threat hunting and detection engineering suggests this can evolve from analyst assistance toward more automated security operations, increasing the importance of trustworthy evidence and human oversight.
The trend: Cybersecurity platforms are converging threat telemetry, expert research and generative AI into integrated systems that aim to compress the time from signal to response.