Google SecOps Enhances Investigation and Case Management (Preview)
Google SecOps has launched a public preview of a revamped Investigation Management experience, designed to handle higher investigation volumes and support new investigation types like retrohunt and threat hunting. This update allows users to track UDM events and detections alongside alerts within cases, offering customizable views and integrated search workflows for improved navigation. The preview is currently limited to single-SIEM deployments and requires manual migration of existing configurations.
Features (1) ›
- Google SecOps [Spotlight Feature] Investigation and case management experience
[Spotlight Feature] Investigation and case management experience This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview . This preview is currently supported only fo
https://docs.cloud.google.com/release-notes#July_26_2026
Related releases
- Config Connector 1.154.1 Adds New Alpha Resources and Field Support Google Cloud release notes ·
- Security Command Center: Data Residency & Agent Vulnerability Scanning Preview Google Cloud release notes ·
- Cloud SQL for PostgreSQL: Private Service Connect changes August 2026 Google Cloud release notes ·
- Cloud SQL for SQL Server: Private Service Connect connection behavior changes Google Cloud release notes ·
- Cloud SQL for MySQL: Private Service Connect and QueryData Updates Google Cloud release notes ·
- Cloud SQL for PostgreSQL: Faster CMEK Re-encryption Google Cloud release notes ·