Security Command Center 会分析各种日志,以发现影响 Google Workspace 资源的潜在威胁。如需了解针对这些威胁的建议响应措施,请参阅对 Google Workspace 威胁发现结果做出响应。
Event Threat Detection 支持以下基于日志的检测:
Persistence: Strong Authentication Disabled
Initial Access: Account Disabled Hijacked
Initial Access: Disabled Password Leak
Initial Access: Government Based Attack
Initial Access: Suspicious Login Blocked
Persistence: SSO Enablement Toggle
Persistence: SSO Settings Changed
Persistence: Two Step Verification Disabled