MSSP, SOC, Threat Intelligence, Threat Management

Google’s Emerging Threats Center Aims to Speed Detection Engineering, MSSPs Benefit

Whether it's CISOs or MSSPs, they spend a lot of time trying to answer two questions for clients during fast-moving threat events: Are we exposed, and are we covered? Google’s new Emerging Threats Center in Google Security Operations is built to shorten that cycle. It gives organizations and MSSPs a clearer way to assess exposure, fill detection gaps, and act on frontline intelligence without the usual manual triage.

When a high-profile vulnerability breaks, teams often need days of cross-referencing reports, indicators, and alerts to figure out what matters. The Emerging Threats Center is designed to cut that work down by offering a single view of threat campaigns, the indicators tied to them, and the detections available to apply. It’s available now for licensed customers.

Reduced Manual Triage With Campaign-Based Prioritization

Threat intelligence usually arrives as long reports or scattered IOCs that detection engineers must translate into rules. Google cites research showing many teams struggle to turn that data into clear direction. The Center filters incoming intelligence from Google Threat Intelligence, Mandiant, VirusTotal, and other sources, then organizes it by campaign relevance.

Chris Corde, Senior Director of Product Management at Google Cloud, told MSSP Alert that the platform’s value starts with how it transforms frontline threat intelligence into something analysts can act on immediately.

“Unlike traditional threat intelligence feeds that can inundate security teams with irrelevant information, Emerging Threats Center operationalizes curated, frontline threat intelligence from Mandiant. It provides a single view of relevant risk and immediate contextualization to a customer’s specific environment, helping analysts proactively hunt for time-sensitive threats and get definitive answers on how they are affected.”

For MSSPs, this means far less manual correlation work. Analysts can review matching IOCs across a year of telemetry and any hits from Google-curated detection rules, all aligned to specific campaigns their clients might encounter.

Automating Detection Engineering With Analysts' Control

The detection engine behind the Center is powered by Gemini models that test existing rules against synthetic events crafted to mimic adversary behavior. When the system sees a detection gap, it drafts a new rule and provides a summary for an analyst to review.

Corde said this marks a meaningful departure from how most teams build detections today. “Automated rule creation with Gemini, which fuels the Emerging Threats Center, differentiates with a deep understanding of attacker behavior from real attacks and transforms manual processes into an automated outcome. It enables a technological shift from detecting single indicators to systematically detecting underlying adversary behaviors.”

The goal isn’t to replace analysts. It’s to give them something production-ready sooner. Corde emphasized that control stays with the SOC. “Despite the high level of automation, the process maintains a human-in-the-loop validation, where security analysts retain control by vetting and verifying new rules before deployment.”

For MSSPs, this supervised automation can help scale detection engineering across multiple customer environments. Instead of spending days writing and testing rules, teams can move straight to review and deployment.

Clearer Answers During Major Threat Events

During active campaigns, the Center highlights two things: Whether a client has any IOC or detection matches tied to the campaign, and whether the relevant detections are active moving forward.

That gives MSSPs a concrete way to communicate exposure and readiness to customers. It supports proactive hunting by surfacing time-sensitive activity without forcing analysts to jump between intel reports and customer data.

For service providers, the value lies in speed, consistency, and clearer communication. The Emerging Threats Center offers a repeatable way to interpret threat campaigns and roll updated protections across accounts. It reduces the manual interpretation work that often slows down response, and it gives MSSPs a stronger framework to explain both risk and defensive posture to their customers.

Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds