Threat intelligence · Google
Google Mandiant
Frontline threat-intelligence and incident-response practice, now part of Google Cloud, built on data from its own breach investigations.
Mandiant is a threat-intelligence and incident-response company acquired by Google in 2022 and now operated within Google Cloud Security. Its intelligence product line draws on evidence gathered directly from Mandiant's own incident-response and managed-defense engagements, tracking named threat-actor groups (APT/FIN designations), malware families, and vulnerabilities exploited in the wild, feeding that into Google's broader threat-intelligence offering alongside VirusTotal and Google-native signals. Beyond intelligence feeds and reports, Mandiant continues to sell hands-on services: incident response for active breaches, Managed Defense for ongoing 24/7 detection and response, and red-team or adversary-emulation consulting. It is positioned less as a self-serve analytics product and more as expert-driven intelligence and response delivered by Mandiant's own analysts and consultants, sold through Google Cloud.
At a glance
| Vendor | |
|---|---|
| Pricing model | Quote only |
| Free tier | No |
| Deployment | Cloud |
| Open source | No |
| Best for | Enterprises needing frontline breach intelligence and hands-on incident response, not just a data feed. |
Pricing
No public pricing; threat-intelligence subscriptions and incident-response/Managed Defense engagements are quoted through Google Cloud sales.
Pricing has not been verified yet — see the vendor's site.
Features
- Threat-actor (APT/FIN) tracking from frontline IR engagements
- Managed Defense 24/7 detection and response
- Incident response and breach investigation services
- Red team and adversary emulation consulting
- Vulnerability and exploitation-in-the-wild intelligence
- Integration with Google Threat Intelligence and VirusTotal data
- Analyst-authored threat intelligence reports
Profile last reviewed September 21, 2026