Security Command Center 會對 Compute Engine 資源執行無代理程式和以記錄為基礎的監控作業。如需這些威脅的建議回應,請參閱「回應 Compute Engine 威脅發現」。
免代理程式監控發現項目類型
透過 Virtual Machine Threat Detection,您可以進行下列無代理程式監控偵測:
Defense Evasion: RootkitDefense Evasion: Unexpected ftrace handlerDefense Evasion: Unexpected interrupt handlerDefense Evasion: Unexpected kernel modulesDefense Evasion: Unexpected kernel read-only data modificationDefense Evasion: Unexpected kprobe handlerDefense Evasion: Unexpected processes in runqueueDefense Evasion: Unexpected system call handlerExecution: cryptocurrency mining combined detectionExecution: Cryptocurrency Mining Hash MatchExecution: Cryptocurrency Mining YARA RuleMalware: Malicious file on diskMalware: Malicious file on disk (YARA)記錄發現項目類型
Event Threat Detection 提供下列記錄檔偵測功能:
Brute force SSHImpact: Managed Instance Group Autoscaling Set To MaximumLateral Movement: Modified Boot Disk Attached to InstanceLateral Movement: OS Patch Execution From Service AccountPersistence: GCE Admin Added SSH KeyPersistence: GCE Admin Added Startup ScriptPersistence: Global Startup Script AddedPrivilege Escalation: Global Shutdown Script Added您可以使用敏感動作服務,進行下列以記錄為準的偵測:
Impact: GPU Instance CreatedImpact: Many Instances CreatedImpact: Many Instances Deleted後續步驟
- 瞭解虛擬機器威脅偵測。
- 瞭解 Event Threat Detection。
- 瞭解敏感操作服務。
- 瞭解如何回應 Compute Engine 威脅。
- 請參閱威脅發現項目索引。