Cybereason and Google Cloud announced a strategic partnership in October 2021 to develop an extended detection and response (XDR) solution. The launch concept paired Cybereason’s MalOp engine with Google Cloud and Chronicle analytics to help correlate security signals across an organization. Cybereason later said development had moved from Chronicle to its own data lake, so the Chronicle-powered description is best understood as the product’s historical launch framing—not confirmation of a current, distinct Chronicle offer.
What the partnership announced
In October 2021, Cybereason and Google Cloud said they would work together on XDR. The stated aim was to combine Cybereason’s analysis of malicious operations, or MalOps, with Google Cloud infrastructure and Chronicle security analytics. Cybereason’s announcement described the collaboration, while IDC’s October 13, 2021 summary characterized it as combining MalOp detection and visualization with Google Cloud and Chronicle analytics.
The idea behind XDR is to bring security data from multiple parts of an IT environment into a more unified investigation and response workflow. Cybereason described coverage spanning endpoints, networks, identities, cloud environments, and application workspaces. The company said its MalOp engine was intended to connect activity across affected devices, users, and systems. These are vendor-described capabilities; the cited announcements do not establish independently tested outcomes.
How the proposed XDR approach was described
Rather than treating endpoint alerts in isolation, the product was presented as correlating signals from several sources to give defenders broader context when investigating a suspected incident. Chronicle was part of the original joint-development framing for collecting and analyzing telemetry. Cybereason’s product description also reported that its MalOp engine analyzed more than 23 trillion security events per week. That is a company-published scale claim, not an independently verified comparative benchmark.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
Cybereason’s historical product overview, Introducing Cybereason XDR Powered by Google Chronicle, explains that launch-era positioning. The announcement describes intended functionality; it should not be read as proof that every listed data source was available to every customer or that particular detection results were independently validated.
Timeline: announcement, Marketplace availability, and product evolution
| Date | What was stated |
|---|---|
| October 2021 | Cybereason and Google Cloud announced a strategic collaboration to develop a joint XDR solution using Cybereason’s MalOp approach alongside Google Cloud and Chronicle analytics. |
| December 15, 2021 | Cybereason announced that its XDR and EDR solutions were available through Google Cloud Marketplace. This is a dated availability announcement, not confirmation of present-day sales, pricing, or terms. See the Marketplace announcement. |
| March 28, 2022 | Cybereason Japan announced planned availability in Japan for summer 2022 and said XDR development had moved from Chronicle to Cybereason’s own data lake while the Google alliance continued. The release describes a plan for Japan, not proof of current regional availability. Read the Japan release. |
What changed after the Chronicle launch framing
Cybereason’s later product materials describe XDR as a Google Cloud Platform-based platform but also state that development moved from Chronicle to a Cybereason data lake. Its current product-page description carries that qualification. In other words, the Google relationship continued, but the available materials do not support describing the later architecture as still being powered by Chronicle in the same way as the 2021 launch concept.
The sources do not establish whether a Chronicle-branded variant remains a separate product that customers can order, or whether it has feature parity with the later data-lake description. They also do not provide current licensing, pricing, or geographic availability for such a variant.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What enterprise buyers should verify
Organizations evaluating the offering should confirm the current product configuration directly with Cybereason or an authorized provider. In particular, ask which data lake and analytics components are used in the offered deployment, what telemetry sources and integrations are supported, and what response workflows are included. Request current documentation for licensing, regions, Marketplace status, and any required Google Cloud services before comparing procurement options.
Cybereason describes reseller and incident-response partner activity on its partner page. That category-level information does not establish that a particular provider currently sells or implements this XDR product; verify a provider’s status and scope before relying on it.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

