Security Command Center 会对 Compute Engine 资源进行无代理监控和基于日志的监控。如需了解针对这些威胁的建议响应措施,请参阅应对 Compute Engine 威胁发现结果。
无代理监控发现结果类型
Virtual Machine Threat Detection 提供以下无代理监控检测:
Defense Evasion: RootkitDefense Evasion: Unexpected ftrace handlerDefense Evasion: Unexpected interrupt handlerDefense Evasion: Unexpected kernel modulesDefense Evasion: Unexpected kernel read-only data modificationDefense Evasion: Unexpected kprobe handlerDefense Evasion: Unexpected processes in runqueueDefense Evasion: Unexpected system call handlerExecution: cryptocurrency mining combined detectionExecution: Cryptocurrency Mining Hash MatchExecution: Cryptocurrency Mining YARA RuleMalware: Malicious file on diskMalware: Malicious file on disk (YARA)基于日志的发现结果类型
Event Threat Detection 支持以下基于日志的检测:
Brute force SSHImpact: Managed Instance Group Autoscaling Set To MaximumLateral Movement: Modified Boot Disk Attached to InstanceLateral Movement: OS Patch Execution From Service AccountPersistence: GCE Admin Added SSH KeyPersistence: GCE Admin Added Startup ScriptPersistence: Global Startup Script AddedPrivilege Escalation: Global Shutdown Script AddedSensitive Actions Service 支持以下基于日志的检测:
Impact: GPU Instance CreatedImpact: Many Instances CreatedImpact: Many Instances Deleted后续步骤
- 了解 Virtual Machine Threat Detection。
- 了解 Event Threat Detection。
- 了解 Sensitive Actions Service。
- 了解如何应对 Compute Engine 威胁。
- 请参阅威胁发现结果索引。