Google Threat Intelligence has moved its agentic AI capabilities from public preview to general availability for Enterprise and Enterprise+ customers. The release is designed to help security teams automate complex cyber defense workflows and use specialized threat intelligence more efficiently.
The platform supports a range of security functions, including threat hunting, incident response and daily alert triage. Analysts can use natural-language queries to generate threat reports, search for indicators of compromise and investigate suspicious files, domains and software vulnerabilities.
Agentic AI systems can perform multistep tasks rather than simply returning a single response to a prompt. In a cybersecurity setting, this can allow the system to gather relevant threat data, conduct analyses and organize findings into an actionable result.
Google Threat Intelligence also includes a Prompt Library containing predefined workflows developed for common investigative tasks. Security teams can use these prompts to repeat complex processes consistently without rebuilding each investigation from the beginning.
The structured workflows can support activities such as tracing how malware has evolved over time and comparing the tactics, techniques and procedures used by different threat actors. This approach is intended to make expert-level analysis more accessible to teams with limited time or specialized personnel.
A dedicated Malware Analysis Agent can automatically activate when deeper inspection is required. It analyzes suspicious files within a secure cloud sandbox and can extract information such as command-and-control infrastructure and encryption keys.
Command-and-control infrastructure refers to the servers and communication systems attackers use to manage compromised devices. Identifying these systems can help defenders block malicious traffic, investigate related activity and understand how a cyberattack operates.
The Malware Analysis Agent is designed to support files targeting multiple operating systems. Automating this process could reduce the manual work required to reverse-engineer malware and allow analysts to focus on remediation and broader incident response.
Google is also emphasizing transparency in the platform’s AI-generated findings. According to the company, the system provides visibility into how it develops its conclusions and includes inline citations connected to underlying threat intelligence data.
These citations are intended to help analysts verify findings rather than relying on unsupported AI output. Greater source transparency can be particularly important in cybersecurity, where inaccurate conclusions may lead teams to overlook a genuine threat or spend resources investigating a false positive.
The general availability release could help organizations scale advanced threat analysis across security operations centers. By combining natural-language interaction with automated investigative workflows, Google Threat Intelligence aims to help defenders respond more quickly to emerging malware, vulnerabilities and threat actors.