Contain threats with the SecOps Response Agent

Supported in:

This guide explains how you can leverage the AI-powered Response Agent within Google SecOps to respond to and remediate security alerts. Use the Response Agent to:

  • Automatically generate immediate, context-aware response recommendations based on investigation verdicts.
  • Execute verified response actions directly from the agentic investigation interface.
  • Bridge the gap between threat detection and threat resolution with tiered automation controls.

When you use the Response Agent, you can reduce manual response overhead and eliminate delays between threat identification and containment. Successful use of the Response Agent leads to predictable, safety-checked threat neutralization across critical organizational assets.

Key terminology

  • Response Agent: The AI-powered assistant that suggests or executes response actions to neutralize a detected threat.
  • Containment: Short-term, immediate actions taken to stop the spread of a threat (for example, isolating a host or blocking an IP address).
  • Remediation: Long-term actions aimed at removing a threat completely and patching vulnerabilities (powered in conjunction with external tools like Wiz).
  • Manual approval: A human-in-the-loop tier where the agent presents intended actions as recommendations for your approval.
  • Autonomous execution: A tier where the agent executes actions automatically based on predefined risk thresholds (Low Risk, Medium Risk, High Risk).

Quota usage during Private Preview

  • Response Agent: During the Private Preview phase, generating response plans with the Response Agent does not consume your AI quota.
  • Using integrations: When you execute response and containment actions through installed integrations within the Response Agent, standard integration usage applies.

Before you begin

Make sure you have or do the following:

  • Permissions: Configuring agent settings and managing exclusions requires administrator permissions, managed in SIEM Settings > Gemini Investigations. Reviewing alerts and executing plans is performed by security analysts. Specific Identity and Access Management (IAM) roles may be required to modify these settings.
  • Execution pathways: Verify that your preferred execution pathway is configured:

    • Triage Agent (TIN) path: Requires Auto-Investigate Alerts in Gemini to be enabled under SIEM Settings > Gemini Investigations > Triage Agent. Response plans are generated automatically for alerts evaluated as true positives.
    • Playbooks path: Does not require TIN. You can drag the Response Agent step into a playbook to run dynamically alongside deterministic steps when an alert triggers.
  • Environment check: Ensure your response and endpoint tools (such as EDRs, firewalls, or Identity Providers) are installed and active as integrations in your Google SecOps environment under Available Tools.

How the Response Agent works

The Response Agent operates as the active response component of the Agentic SOC ecosystem. It processes enriched context and alert verdicts to synthesize safety-checked response plans. The following sections explain the underlying autonomy logic, triggering stages, and response workflow.

Tiered autonomy and risk logic

To ensure safety, the agent evaluates response actions against an Autonomous Execution Level setting (Manual Approval, Low Risk, Medium Risk, High Risk).

Risk assessment mechanism

Risk levels are calculated by evaluating the operational impact, reversibility, and scope of the proposed action itself (for example, resetting a password versus wiping a device).

Global execution modes

You can configure the agent to run in the following global modes based on your risk tolerance:

  • Manual approval: Actions require explicit approval before execution. This is the default setting.
  • Autonomous execution: Actions at or below the selected risk threshold run automatically. You can set the threshold to Low Risk, Medium Risk, or High Risk. For example, if Medium Risk is selected, the agent will execute all low and medium-risk actions automatically without asking for approval. High-risk actions will default to requiring manual approval.

Per-tool overrides

Additionally, you can configure granular overrides under Available Tools, either at the integration level or the action level:

  • Autonomous: Always runs automatically regardless of the global risk setting.
  • Default: Inherits execution behavior from the global Autonomous Execution Level.
  • Manual Approval: Always requires human approval regardless of the global risk setting.

Stage 1: Building the response plan

  1. Synthesize context: The agent reviews the case verdict, enriched entities, and environmental context to form a list of concrete recommended actions tailored to the specific scenario.
  2. AI Script & Code Generation: If AI Script & Code Generation is enabled (disabled by default) and a recommended response action does not exist in your current integrations, Gemini can dynamically write custom code to execute missing actions.

Stage 2: Viewing and executing the plan

  1. Access cases: Go to Cases and select a case tagged with Gemini.
  2. Review the plan: Review the response plan at either the case level or the alert level:
    • Case-level aggregation: On the Overview tab, review the Case Summary widget for aggregated recommendations.
    • Alert-level details: Click the Alerts & Detections tab. Select an alert, click View investigation and response plan, and then click View response plan to open the response drawer.
  3. Review actions: Inspect the recommended actions, target entity parameters, and execution risk levels.
  4. Modify plan: Select or clear individual actions, edit target parameters, or append manual response steps (such as blocking an IP address) as direct feedback for incomplete plans.
  5. Execute: Click Execute actions to run the selected plan.
  6. Audit trail: Executed actions display individual success or failure statuses directly within the workflow.

Stage 3: Wiz integration (cloud responses)

While the SecOps Response Agent focuses primarily on immediate containment actions within your environment, the integration with Wiz provides a strategic, long-term defense. It helps you fully remediate identified cloud vulnerabilities and secure your posture to prevent future attacks.

The Response Agent pulls critical risk data directly from Wiz to assist in resolving cloud infrastructure risks:

  • Related risks: Displays critical related Wiz risk issues attached to cloud entities involved in the case.
  • Next steps: For detailed actions and response steps, click View Issue in Wiz to link directly to the Wiz platform and safely complete the remediation within the Wiz environment.

Configure the Response Agent

  1. Access Settings: Go to SIEM Settings > Gemini Investigations > Context & Response.
  2. Enable or disable: In the Context & Response section, toggle Response Agent to Enabled or Disabled.
  3. Set Autonomous Execution Level: Select the maximum risk level allowed to run automatically (Manual Approval, Low Risk, Medium Risk, or High Risk).
  4. Configure AI Script & Code Generation: Optional: Toggle AI Script & Code Generation to Enabled (disabled by default) to allow Gemini to write dynamic code for unhandled actions.
  5. Manage tool overrides (Exclusions): Optional: Under Available Tools, select specific integrations or actions to override their execution mode (Autonomous, Default, or Manual Approval). This is how you manage exclusions (by turning off or restricting specific integrations or actions).

Need more help? Get answers from Community members and Google SecOps professionals.