Security Command Center 会对 Cloud Run 资源执行运行时和控制平面监控。如需了解针对这些威胁的建议响应措施,请参阅对 Cloud Run 威胁发现结果作出响应。
运行时发现类型
Cloud Run Threat Detection 提供以下运行时检测:
Execution: Added Malicious Binary Executed
Execution: Added Malicious Library Loaded
Execution: Built in Malicious Binary Executed
Execution: Container Escape
Execution: Kubernetes Attack Tool Execution
Execution: Local Reconnaissance Tool Execution
Execution: Malicious Python executed
Execution: Modified Malicious Binary Executed
Execution: Modified Malicious Library Loaded
Malicious Script Executed
Malicious URL Observed
Reverse Shell
Unexpected Child Shell
控制平面发现结果类型
Event Threat Detection 可提供以下控制平面检测:
Execution: Cryptomining Docker Image
Impact: Cryptomining Commands
Privilege Escalation: Default Compute Engine Service Account SetIAMPolicy
后续步骤
- 了解 Cloud Run Threat Detection。
- 了解 Event Threat Detection。
- 了解如何应对 Cloud Run 威胁发现结果。
- 查看威胁发现结果索引。