What happened
Google SecOps announced (~Aug 9, 2026) Public Preview of the Threat Hunt Agent (THA) for Enterprise Plus customers — a Gemini-native agent that autonomously generates hunt queries (YARA-L 2.0), collects evidence, and runs proactive threat-hunting workflows across historical telemetry, turning multi-day analyst work into hours.
Why it matters
Extends Google's Agentic SOC push beyond triage/investigation copilots into autonomous proactive threat hunting, a workflow historically reserved for scarce senior analysts, changing SOC staffing/coverage economics.
Applicability
Google SecOps Enterprise Plus customers running Chronicle SIEM should pilot THA now; other SOC platform vendors should benchmark against this capability.