Security Command Center 会分析各种日志,以发现影响网络资源的潜在威胁。如需了解针对这些威胁的建议响应措施,请参阅应对网络威胁发现结果。
Event Threat Detection 提供以下基于日志的检测功能:
Active Scan: Log4j Vulnerable to RCECloud IDS: THREAT_IDENTIFIERCommand and Control: DNS TunnelingDefense Evasion: VPC Route Masquerade AttemptImpact: VPC Firewall High Priority BlockImpact: VPC Firewall Mass Rule DeletionInitial Access: Log4j Compromise AttemptLog4j Malware: Bad DomainLog4j Malware: Bad IPMalware: bad domainMalware: bad IPMalware: Cryptomining Bad DomainMalware: Cryptomining Bad IP后续步骤
- 了解 Event Threat Detection。
- 了解如何应对网络威胁发现结果。
- 查看威胁发现结果索引。