Google Named Leader in Forrester Wave for External Threat Intelligence

Google has been named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. The announcement centers on Google Threat Intelligence, which combines Mandiant frontline incident response, VirusTotal crowdsourced visibility, and Google-scale infrastructure with deep and dark web monitoring. Forrester gave Google the highest possible score of 5.0 across nine criteria spanning Current Offering and Strategy, including Deep and Dark Web Monitoring, Intelligence Collection Sources, Analyst Tradecraft and Services, Attribution and Frameworks Used, Analyst Experience, Partner Ecosystem, Roadmap, Community, and Intelligence Dissemination.

A key differentiator Forrester highlighted is that Google is the only vendor in the evaluation that is also a frontier AI model developer and a significant player in quantum computing. This means Google Threat Intelligence has direct access to a leading frontier model rather than an off-the-shelf wrapper. The AI agents are fine-tuned and stress-tested continuously using proprietary Gemini best practices, removing usage limits and latency typical of third-party layers. According to the report, Google’s recent Gemini advancements accelerated the success of many of its AI-enabled functionalities. In addition to finished intelligence reports, defenders can use the agent to create custom analysis derived from frontline observations, tailored to their local threat profile and environment.

The agentic platform autonomously conducts campaign attribution and complex agentic malware analysis, backed by codified Mandiant tradecraft, dynamic visual workflows, and real-time telemetry that programmatically hardens tool routing and execution. The foundation is built by hundreds of researchers across the Google Threat Intelligence Group (GTIG) in over 30 countries speaking 30 languages. Evidence-based attribution maps directly to MITRE ATT&CK, enabling practitioners through interactive graphs and Gemini-enabled agentic threat intelligence. These capabilities feed newest threat discoveries into detection workflows, raising alert quality and removing guesswork from rule creation across the security stack. SOC teams and threat hunters can author resilient rules against novel variants, link suspicious events to known actor playbooks, and triage critical alerts with certainty.

Within the Google Security Operations ecosystem, customers can directly leverage Google Threat Intelligence enrichments with agents: the Triage and Investigation agent autonomously investigates alerts and prioritizes threats; the Detection Engineering agent automatically finds and fills coverage gaps; the Threat Hunting agent proactively searches for novel attack patterns. Forrester noted that Google maintains an open, partner-centric approach that avoids lock-in to the Google SecOps ecosystem and benefits from a strong community presence across the broader Google Cloud Security ecosystem. Google received a 5/5 score in the partner ecosystem criterion.

The company reports measurable customer impact: customers identify 139% more threats proactively and make their CTI teams 46% more efficient, accelerated by AI-driven summarization and context. This helps eliminate manual guesswork, act on validated frontline intelligence, and focus on high-value investigations. By accelerating detection engineering and proactive exposure management, Google Threat Intelligence identifies malicious infrastructure before adversaries can use it in campaigns, reducing threat dwell time and risk. The announcement includes a standard Forrester disclaimer that Forrester does not endorse any company, product, brand, or service, and that opinions reflect judgment at the time and are subject to change.

Google named a Leader in the External Threat Intelligence Service Forrester Wave™

View Original