Evidence-backed analysis
Google SecOps has three different agent operating models
TIN, Threat Hunt Agent, and Detection Engineering Agent differ in trigger, runtime, and write authority.
Human reviewed 2026-08-27 · ASI-1.0 ·5 evidence records
One portfolio, three boundaries
Google TIN can start automatically or manually and produces a structured alert assessment. Threat Hunt Agent is analyst initiated and read-only during a hunt. Detection Engineering Agent runs through compatible MCP clients, evaluates coverage, and drafts YARA-L rules that must be reviewed and created manually.
What actually differs?
| Agent | Trigger | Output | Write authority |
|---|
| TIN | Event driven or manual | Verdict, findings, reasoning | Read-only in the reviewed documentation |
| Threat Hunt Agent | Human initiated | Hunt case and evidence | Read-only |
| Detection Engineering Agent | Human initiated through MCP | Draft YARA-L rules | No automatic upload |
Availability conflict
The public corpus contains conflicting preview descriptions for the Detection Engineering Agent. That conflict remains open for human review, so the projection reports availability as UNKNOWN rather than selecting the more favorable source.
Procurement consequence
Buyers should not treat the Agentic SOC umbrella as one deployment model. TIN is embedded and quota constrained, Threat Hunt depends on Enterprise Plus preview access, and the Detection Engineering Agent requires an external compatible MCP client. These differences affect integration effort, control testing, and licensing.
Governed evidence
Sources supporting this analysis
VENDOR DOCUMENTATION EV-GOOGLE-TIN-CAPABILITY
It evaluates incoming alerts, executes an investigation plan, and provides a structured analysis that includes both its findings and reasoning.
Canonical source: Google →VENDOR DOCUMENTATION EV-GOOGLE-TIN-TRIGGER
You can trigger TIN automatically or manually. Each investigation typically completes in an average of 60 seconds and runs for a maximum of 20 minutes.
Canonical source: Google →VENDOR DOCUMENTATION EV-GOOGLE-HUNT-CAPABILITY
The Threat Hunt Agent is an autonomous AI capability embedded in Google Security Operations that automates proactive threat hunting across your enterprise security telemetry.
Canonical source: Google →VENDOR DOCUMENTATION EV-GOOGLE-DEA-DRAFT
This tool does not automatically upload the rule into your Google SecOps system. In order to add any rule, review the text and then manually create new rules from the tool output.
Canonical source: Google →THIRD PARTY REPORT EV-GOOGLE-DEA-CONFLICT
The latest Google SecOps Agent, the Detection Engineering Agent, is in private preview.
Canonical source: Google Cloud Community →