Google Cloud unveiled an agentic defense strategy that combines Wiz, Gemini, Mandiant, and Google Security Operations to automate threat detection, investigation, and remediation. The company said the approach is designed to counter attackers' growing use of AI, citing Mandiant data showing the average time from initial breach to access handoff has fallen to 22 seconds. Google also tied the strategy to broader code and application security efforts, including CodeMender, an AI agent for code security, and new protections such as Wiz AI Application Protection Platform and AI-BOM.
The announcement places Google more directly in the fast-growing market for AI-driven and agentic SOC platforms, where vendors including CrowdStrike, Microsoft, Palo Alto Networks, and SentinelOne are also pushing automation-heavy security operations. Google said it has integrated Wiz attack surface management with Google Threat Intelligence and added SecOps agents for triage, threat hunting, and detection engineering, while rivals such as CrowdStrike are promoting agentic MDR and an agentic SOC model to help enterprises scale managed detection and response.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
As part of the strategy announcement, Google said it integrated Wiz attack surface management with Google Threat Intelligence and expanded its portfolio with Wiz AI Application Protection Platform, AI-BOM, and new SecOps agents for triage, threat hunting, and detection engineering.
Google Cloud announced an agentic defense strategy combining Wiz, Gemini, Mandiant, and Google Security Operations to automate threat detection, investigation, and remediation.
CrowdStrike published a blog post describing how its services and Agentic MDR can help organizations implement an agentic SOC model.
Google DeepMind published a blog post introducing CodeMender, an AI agent focused on code security.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcecrowdstrike.com
Open sourcedeepmind.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.