Security Command Center 会分析各种日志,以发现影响数据库的潜在威胁。Event Threat Detection 支持以下基于日志的检测:
Credential Access: CloudDB Failed login from Anonymizing Proxy IPExfiltration: Cloud SQL Data ExfiltrationExfiltration: Cloud SQL Over-Privileged GrantExfiltration: Cloud SQL Restore Backup to External OrganizationInitial Access: CloudDB Successful login from Anonymizing Proxy IPInitial Access: Database Superuser Writes to User TablesPrivilege Escalation: AlloyDB Database Superuser Writes to User TablesPrivilege Escalation: AlloyDB Over-Privileged Grant后续步骤
- 了解 Event Threat Detection。
- 查看威胁发现结果索引。