aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Platforms
  • Solutions
  • Technology

Introducing AI-Powered Insights In Threat Intelligence

  • aster.cloud
  • April 30, 2023
  • 6 minute read

Our new Security AI WorkKbench, announced today at RSA Conference in San Francisco, uses the recent advancement in Large Language Models (LLMs) to address three of the biggest challenges in cybersecurity: threat overload, toilsome tools, and the talent gap. Threat intelligence is an area that suffers from all three problems, and LLMs have the capability to transform how it is operationalized to help secure businesses.

At Google Cloud, our threat intelligence offerings are grounded in three core principles:


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

  1. Trusted: Our customers can trust Mandiant Threat Intelligence to have industry-leading breadth, depth, and timeliness to deliver information that matters.
  2. Relevant: We personalize the threat landscape so it’s relevant for each customer, enabling them to prioritize threats that are likely to affect them.
  3. Actionable: Our threat intelligence is more actionable because we automate the end-to-end pipeline from raw data to security controls.

Deliver the most trusted threat intel

AI is as valuable as the data it operates on. Using LLMs to summarize irrelevant, open-source intelligence provides no more value to a customer than a manual review of that data. Doing so can even add more noise to an already-overwhelming flood of information.

That’s why the combination of Mandiant’s frontline intelligence, garnered from a team of expert researchers and over 1,000 breaches each year, and Google’s exceptional visibility on internet-wide threats, provides a powerful foundation for our AI solutions. We have been applying many natural language processing (NLP) and machine learning (ML) approaches to convert raw threat data into actionable intel for years. Recent developments in LLMs allow us to significantly improve our already market-leading intel operations. Some of the areas we are working on include:

  • Increasing the breadth of our coverage by implementing more effective tracking of digital threats across languages and modalities. Global threat actors use many methods to hide their tracks across forums, messaging services, and the deep/dark web. LLM-based approaches, which are particularly good at handling multiple modalities and languages across discussion forums, messaging services, and websites hidden from traditional search engines, help our analysts peer through this obfuscation at scale.
  • Providing greater depth to our threat intel by combining visibility across data sources. LLMs can eliminate data silos that previously prevented broad analysis by identifying relevant information across multiple sources. This will allow us to combine threat information encountered during Mandiant incident response engagements, Google’s visibility into Internet-wide threats, public information, and Mandiant research to produce a more complete and contextual picture of our threat intelligence.
  • Converting raw threat data into finished threat intelligence in machine-readable and human-readable forms. LLMs enable us to take this automation to the next level where every step in the conversion from raw threat data to finished intel to new detection rules can now be automated — with expert human supervision. In many cases, this will allow customers to see late-breaking developments in near-finished form in minutes versus days or weeks, then operationalize those insights instantly.
Read More  New Relic Delivers Reimagined Observability Platform With Unified User Experience, And Simple, Predictable Pricing To Help Companies Create More Perfect Software

Personalizing the threat landscape to focus on the most relevant threats

The vast majority of the threat landscape is irrelevant to most organizations. Therefore, it’s vital for every customer to focus on the threat landscape that is relevant for them. Personalizing the threat landscape is made possible in two ways:

  1. Automatically creating a personalized threat profile
  2. Simplifying augmentation of that threat profile by giving analysts AI based natural language search

Imagine automatically deriving a personalized and detailed threat landscape for your organization that evolves as new internal and external information becomes available. With the power of LLMs, this is becoming a reality:

  • A personalized threat profile for your organization could be automatically created, and quickly queried using a simple conversational interface to ask questions such as “Why is this threat important? What impact did this actor have on my industry counterparts? How recent has this actor’s activity been? What tactics, techniques, and procedures do they use? Why is my environment uniquely at risk? What actions should I take to mitigate the risk due to this campaign, tool, or actor?”
  • Daily recommendations could be shared on what security actions to take today based on any changes over the last 24 hours. For example, if a threat actor was seen targeting your industry using a new technique that you have exposure to, you would be notified so mitigations can be quickly put in place.
  • When there’s a significant change in your threat landscape or environment, you would be automatically provided with actionable next steps.

In the past, this kind of personalization was only available to the largest and most sophisticated organizations. LLMs will enable Mandiant to make this level of personalization available to all our customers, at scale.

Read More  Apple services deliver powerful features and intelligent updates to users this autumn

LLMs can make search significantly more efficient. While there is a plethora of information available about threats, sorting through it and making those insights actionable requires a lot of work. The summarization capabilities of LLMs make obtaining a complete understanding of a threat topic an issue of the past. Figure 1 illustrates LLM-based summarization of various threat intelligence artifacts relevant to a query. Note that the flexibility of LLMs allow us to provide a summary of the finished intel reports alongside structured intelligence, and customize the scope and technical depth of the summary to different audiences.

Figure 1: LLM-based summarization capabilities in action on the Mandiant Threat Intelligence platform.

As we continue to leverage LLMs in search, we will be supporting a conversational interface to reduce the toil and lower the skills bar for exploring the threat landscape. These iterative searches will be stateful and shareable, making it easier to collaborate with other analysts.

Make threat intelligence more actionable

Traditionally, taking action on threat intelligence has been a burdensome manual task, limiting the value of the threat intelligence to any business. A recent global survey on threat intelligence showed that nearly half of respondents cited applying threat intelligence as their greatest challenge. At Mandiant, we have been focused on making it easier for customers to act on personalized threat intelligence in their security products and workflows.

One of the most powerful combinations we offer is our ability to apply our world-class threat intelligence to event data in Chronicle Security Operations, using AI-based models to curate and prioritize indicators of compromise (IOCs) that Mandiant tracks through active breach investigations. Mandiant Breach Analytics for Chronicle provides a prioritized set of undiscovered events that could be indicative of an active breach, as seen in Figure 2.

Read More  What’s New With Google’s Unified, Open And Intelligent Data Cloud

Breach Analytics for Chronicle allows customers to readily find bad actors using novel techniques and contain them before becoming the next victim. The AI based models curate and prioritize the matches to assign an Indicator Confidence Score (IC-Score), which indicates our confidence in their use in malicious activity.

Recently, we have leveraged the power of LLMs to summarize indicator/actor/malware context pulled from our vast repository of proprietary research to provide trusted threat intel to the security analysts in the SOC. This reduces toil and the reliance on expertise, eliminating the need to scour through hundreds of reports and structured data sources to understand the context of the IOC. Mandiant plans to release this feature soon.

Figure 2: LLMs providing AI summary of malware and threat actors used in a current breach

The road ahead

Taken together, applying LLMs to the trusted, relevant, and actionable pillars will help our customers reduce threat overload, eliminate manual and tiresome toil, and close the talent gap in security. We are at the beginning of a massive transformation of how threat intel delivers value to businesses of all sizes. The examples above span capabilities we will add in the short-, medium-, and long-term, and we will continue to have our product, AI research, and engineering teams collaborate to transform security for our customers.

To learn more about the use of AI in our Threat Intelligence, visit us at RSA Conference, booth N6058 or go to cloud.google.com/security/ai

By: Vijay Ganti (Head of PM Threat Intelligence, Detections & Analytics Google Cloud Security) and Scott Coull (Head of Data Science Research, Mandiant)
Originally published at: Google Cloud Blog

Source: Cyberpogo


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • AI
  • Artificial Intelligence
  • Google Cloud
  • Large Language Models
  • LLM
  • Security
  • Security AI Workbench
You May Also Like
View Post
  • Technology

IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average

  • July 29, 2026
View Post
  • Technology

3 Questions: Neural transparency and the future of AI design

  • July 17, 2026
View Post
  • Technology

IBM and Red Hat Expand Lightwell with New Offerings to Build the Trust Infrastructure for AI-Era Open Source

  • July 8, 2026
View Post
  • Technology

The AI investment surge hasn’t produced the expected results yet. That could change in 2026

  • June 26, 2026
zedreviews-valerion
View Post
  • Gears
  • Technology

Father’s Day Outdoors – Build Dad the Ultimate Backyard Watch Party

  • June 20, 2026
zedreviews-fathers-day-50830
View Post
  • Gears
  • Technology
  • Tools

Father’s Day Outdoors, Round Two – Gear for the Action, the Tailgate, and Beating the Heat

  • June 20, 2026
zedreviews-fathers-day-2147684744
View Post
  • Gears
  • Technology
  • Tools

The Ultimate Father’s Day Gift Guide – Home Entertainment Upgrades Dad Actually Wants

  • June 20, 2026
zedreviews-fathers-day-21306
View Post
  • Gears
  • Technology

A Father’s Day Gift Guide for Every Dad – Timepieces and Travel Gear

  • June 20, 2026

Stay Connected!
LATEST
  • 1
    IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average
    • July 29, 2026
  • 2
    Accelerating the frontiers of scientific discovery: Google’s $40M commitment to the Genesis Mission
    • July 26, 2026
  • 3
    3 Questions: Neural transparency and the future of AI design
    • July 17, 2026
  • 4
    Intel Invests €5 Billion to Expand Manufacturing in Europe
    • July 13, 2026
  • 5
    IBM and Red Hat Expand Lightwell with New Offerings to Build the Trust Infrastructure for AI-Era Open Source
    • July 8, 2026
  • 6
    When I Was Young
    • July 4, 2026
  • 7
    The Fastest AI Fried Chicken In The World
    • June 29, 2026
  • 8
    Zed Approves | How to Stay Cool in Extreme Heat
    • June 29, 2026
  • 9
    The AI investment surge hasn’t produced the expected results yet. That could change in 2026
    • June 26, 2026
  • 10
    Zed Approves | It’s Prime Day 2026! Time to Upgrade Your World Cup Viewing Setup and Beat the Heat
    • June 25, 2026
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • 1
    Zed Approves | The Best Prime Day PC Deals: Top Gaming Rigs, Workstations, and Everyday Laptops
    • June 24, 2026
  • neon-cart 2
    Zed Approves: How to Gear Up for GTA 6 This Amazon Prime Day (2026 Quick Guide)
    • June 22, 2026
  • zedreviews-valerion 3
    Father’s Day Outdoors – Build Dad the Ultimate Backyard Watch Party
    • June 20, 2026
  • zedreviews-fathers-day-50830 4
    Father’s Day Outdoors, Round Two – Gear for the Action, the Tailgate, and Beating the Heat
    • June 20, 2026
  • zedreviews-fathers-day-2147684744 5
    The Ultimate Father’s Day Gift Guide – Home Entertainment Upgrades Dad Actually Wants
    • June 20, 2026
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.