Security Command Center 會分析各種記錄,找出影響網路資源的潛在威脅。如需這些威脅的建議回應,請參閱「回應網路威脅發現結果」。
Event Threat Detection 提供下列以記錄為基礎的偵測功能:
Active Scan: Log4j Vulnerable to RCECloud IDS: THREAT_IDENTIFIERCommand and Control: DNS TunnelingDefense Evasion: VPC Route Masquerade AttemptImpact: VPC Firewall High Priority BlockImpact: VPC Firewall Mass Rule DeletionInitial Access: Log4j Compromise AttemptLog4j Malware: Bad DomainLog4j Malware: Bad IPMalware: bad domainMalware: bad IPMalware: Cryptomining Bad DomainMalware: Cryptomining Bad IP後續步驟
- 瞭解 Event Threat Detection。
- 瞭解如何回應網路威脅調查結果。
- 請參閱威脅發現項目索引。