Mandiant Hunt is listed in Google Cloud’s security catalog for expert-led threat hunting that takes place directly in Google Security Operations.
What Is Mandiant Hunt?
Google Cloud lists Mandiant Hunt in its official security catalog under Security operations with the description of uncovering hidden attacks with elite threat hunters by your side. The catalog names identifying detection and visibility gaps, reducing attacker dwell time, and hunting on 12 months of hot data directly within Google SecOps as its characteristics.
The catalog entry points to a product page currently titled Mandiant Threat Defense. There, Google Cloud describes comprehensive active threat detection across the full security stack, efficient prioritization of critical security cases, expert-led rapid response, and AI-assisted threat hunting — delivered natively in Google Security Operations and supported by a designated Mandiant expert.
Core Features
- Intelligence-led hunting: Based on up-to-the-minute intelligence from Mandiant incident response engagements and vast telemetry from Google Threat Intelligence
- Human-led hunting: Mandiant experts have exposed a wide range of threat actors, from insiders to financially motivated to state-sponsored
- AI assistance: Security models trained on Google Threat Intelligence and observed attacker behavior automatically create and execute threat hunts
- Prioritization: A proprietary case prioritization model supports efficient investigation and response for high severity cases
- Response: Expert-led investigations and scaled SOAR playbooks, with Gemini for enhanced remediation recommendations
Typical Use Cases
Uncover Hidden Attacks
Continuous threat hunting on 12 months of hot data directly within Google SecOps.
Close Detection Gaps
Mandiant experts provide targeted tuning recommendations, working side by side with your security team or MSSP.
Handover to Incident Response
When an incident is confirmed, the investigation escalates seamlessly to Mandiant Incident Response.
Benefits
- Native to Google SecOps: No separate tool stack required for hunting and investigation
- Human plus AI: Expert knowledge complemented by security models trained on attacker behavior
- Traceable results: Investigation results mapped to MITRE ATT&CK
- Reporting for decision makers: Native Google SecOps dashboards for executive-level reporting
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Mandiant Hunt: assessing the right scope of service, preparing your Google SecOps environment, and implementing tuning and remediation recommendations.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Mandiant Hunt?
Mandiant Hunt is listed in Google Cloud's official security catalog with the description of uncovering hidden attacks with elite threat hunters by your side. Google Cloud lists identifying detection and visibility gaps, reducing attacker dwell time, and hunting on 12 months of hot data directly within Google SecOps as its characteristics.
Where does the catalog entry for Mandiant Hunt point?
The security catalog entry links to the product page at cloud.google.com/security/products/mandiant-managed-threat-hunting. That page is currently titled Mandiant Threat Defense and describes comprehensive active threat detection, threat hunting, and rapid response by Mandiant experts, delivered natively in Google Security Operations.
How do the threat hunters work?
Google Cloud describes the approach as intelligence-led, human-led, and AI-assisted. Hunting is defined by up-to-the-minute intelligence from Mandiant incident response engagements and telemetry from Google Threat Intelligence. Mandiant experts also leverage security models trained on Google Threat Intelligence and attacker behavior observed in incident response engagements to automatically create and execute threat hunts.
How are results presented?
According to Google Cloud, investigation results are mapped to MITRE ATT&CK. Executive-level security reporting is available through native dashboards in Google SecOps.
What happens when an incident is confirmed?
Google Cloud states that investigations escalate seamlessly to Mandiant Incident Response for rapid incident resolution.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
