Emerging Threats overview

Supported in:

The Emerging Threats page in Google Security Operations provides AI-powered threat intelligence that helps you understand how current and emerging threat campaigns might affect your organization. It builds on Applied Threat Intelligence (ATI) and is powered by Google Threat Intelligence (GTI) and Gemini models.

The Emerging Threats page provides a curated view of the most critical global threats from GTI that pose risks to your environment, including IoCs, detection matches, and affected entities. It uses Gemini to transform large volumes of raw intelligence feeds into actionable insights, letting you operationalize threat data directly in your investigation workflows.

For more details about the IAM permissions required to access the Emerging Threats page, see Emerging Threats: threatCollections and iocAssociations.

Key benefits

Emerging Threats strengthens your organization's visibility into active and developing threat campaigns.
It provides the following benefits:

  • Continuous threat visibility: GTI campaign data is continuously reflected in your workspace, so you are always aware of relevant threat campaigns as they develop.
  • Actionable insights: You receive enriched, contextual results rather than manually browsing threat reports.
  • Faster detection validation: Automated processes help you validate detection coverage and review campaign data with less manual effort.
  • Reduced operational overhead: Out-of-the-box detection generation reduces manual effort in parsing threat reports for detection opportunities.

Need more help? Get answers from Community members and Google SecOps professionals.