Published: 27/08/26

One Year On: How SEP2 Maximised Google Threat Intelligence

One year ago, SEP2 officially announced our strategic partnership with Google Cloud to embed Google Threat Intelligence (GTI) directly into our cyber security operations.

Since we made that announcement, our goal has been to integrate the combined telemetry of Google, Mandiant’s frontline intelligence, and VirusTotal’s massive malware corpus into our 24/7/365 UK-based Security Operations Centre (SOC).

Twelve months later, this partnership has transformed from a milestone announcement into a core driver of proactive defence for our customers. Here is a look at what we’ve achieved, how our SOC has evolved, and how we are delivering tangible protection to organisations across diverse industries and complex tech stacks.

Growing Impact: Adoption & Proof of Value

Over the past year, uptake for GTI-powered services has accelerated rapidly:

  • 9 Enterprise Clients have upgraded to Wingman MDR Enhanced, leveraging deep GTI telemetry inside our managed detection and response ecosystem.
  • 5 Major Organisations received direct engineering support from SEP2 consultants to deploy and configure Google Threat Intelligence natively within their internal IT estates.
  • Dedicated Proof of Values (POVs) have been successfully deployed throughout 2026 for prospective enterprise clients looking to evaluate dedicated Wingman Threat Intelligence workflows.

Real-World Defense: Stopping Breaches Before They Start

The threat landscape in 2026 requires catching early-stage reconnaissance before it escalates into active intrusion. Our Digital Threat Monitoring, powered by GTI, has provided critical early warning indicators across the deep and dark web.

Dark Web Credential Exfiltrations

Nearly every organisation (all but one) operating on Wingman MDR Enhanced had employee credentials surfaced on dark web forums or illicit leak sites during the past 12 months.

These detections ranged from targeted “sale-of-access” listings to massive third-party SaaS data dumps containing corporate email addresses.

Real-World Case Study: Dark Web Credential Interdiction

  • The Incident: Corporate Entra ID credentials were discovered for sale on a dark web forum after an employee used their corporate identity to register for an external, compromised third-party SaaS tool.
  • The Risk: The stolen credentials provided direct access to corporate Microsoft Entra ID logins and linked financial services portals used by the organisation to conduct business.
  • The Impact: Because GTI flagged the listing on the dark web immediately, SEP2’s SOC collaborated with the customer to verify the validity of the finding. Following on from this, as the password was compliant with the corporate password policy, the SOC initiated a credential reset for the user and performed a reactive threat hunt to ensure there had been no illicit access attempts to the account..
  • The Outcome: The threat was contained before attackers could execute cloud-native identity session hijacking or pivot into critical financial platforms, preventing an active breach.

High-Targeted Sector Dynamics: What Our SOC is Seeing

Threat actors continue to shift tactics away from generic, mass-Phishing campaigns toward targeted edge exploitation and interactive social engineering.

According to frontline threat metrics from the latest Mandiant M-Trends reporting alongside SEP2 SOC telemetry, actor activity remains heavily concentrated across specific sectors while maintaining a broad reach across the entire market.

Industry Vertical Targeting Frequency Common Attack Vectors Observed
Legal & Professional Services 8.9% Third-party SaaS token theft, Edge VPN exploitation, Dark Web access sales
Manufacturing 8.0% Supply chain compromises, Network perimeter abuse, Ransomware hand-offs
Education 6.5% Credential harvesting, Session hijacking, ClickFix social engineering
All Other Sectors 78.0% Diverse spread including High-Tech, Financial, and Healthcare targets

Active Campaigns & Geopolitical Disruption

Operating across diverse geographies, our SOC monitors a wide array of threat clusters. In recent weeks, SEP2 analysts directly intercepted and contained Russian-nexus disruption campaigns specifically targeting UK infrastructure and enterprise organisations.

Having access to Mandiant frontline insights allows our analysts to perform accurate attribution on common and state-aligned threats. Understanding the specific threat actor’s motivations and typical TTPs allows both our SOC team and our clients to clearly assess residual risk and execute targeted remediation steps rather than relying on generic playbooks.

Elevating SOC Velocity with GenAI & VirusTotal

Integrating the full VirusTotal corpus has fundamentally altered how our analysts triage, enrich, and sandbox incoming alerts.

By having immediate access to VirusTotal’s contextual data, file reputation engines, and automated detonation pipelines, our SOC has established a solid baseline of telemetry that cuts through investigative noise.

Powered by Wingman AI (Casey)

Following our GTI partnership, we launched our Agentic SOC powered by Wingman AI, featuring our autonomous AI Investigation Agent, Casey.

Casey natively ingests Google Threat Intelligence feeds and is trained on Mandiant’s security incident data lakes. When an alert fires:

  1. Autonomous Enrichment: Casey uses GTI to instantly correlate indicators of compromise (IOCs), historical threat actor infrastructure, and sandbox behaviors.
  2. Contextual Risk Scoring: Instead of treating alerts in isolation, the agent evaluates the threat against the organisation’s specific technological attack surface.
  3. Detection Library Engineering: Every incident handled by our team feeds back into our continuous detection library. We maintain a baseline set of evergreen rules applied to all clients, supported by risk-informed custom rules designed for specific industry risks.

Looking Ahead: Expanding Your Defense Posture

The attack surface is rapidly evolving. Threat actors are blending perimeter edge targeting, hyper-personalised vishing, cloud-native identity hijacking, and ClickFix techniques into complex, multi-stage campaigns.

Whether you are looking to enhance your MDR capabilities through Wingman MDR or want to deploy Google Threat Intelligence / Google Security Operations Enterprise+ inside your own estate, SEP2 is ready to guide your journey.

Want to learn more about how Google Threat Intelligence and SEP2’s Wingman MDR can protect your organisation? Contact the SEP2 Cyber Security Team today.

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.