flâneur

Overview of Event Threat Detection | Security Command Center | Google Cloud

cloud.google.com · 8,036 words · saved by 1 readers

Event Threat Detection is a built-in service for the Security Command Center Premium tier that continuously monitors your organization or projects and identifies threats within your systems in near-real time. Event Threat Detection is regularly updated with new detectors to identify emerging threats at cloud scale. Event Threat Detection monitors the Cloud Logging stream for your organization or projects. If you activate Security Command Center Premium tier at the organization level, Event Threat Detection consumes logs for your projects as they are created and Event Threat Detection can monitor Google Workspace Logs. Cloud Logging contains log entries of API calls and other actions that create, read, or modify the configuration or metadata of your resources. Google Workspace logs track user sign-ins to your domain and provide a record of actions performed on your Google Workspace Admin Console. Log entries contain status and event information that Event Threat Detection uses to quickl

Active Scan: Log4j Vulnerable to RCE Unavailable Cloud DNS logs Log4j vulnerability scanners initiated and identified DNS queries for unobfuscated domains. This vulnerability can lead to remote code execution (RCE). Findings are classified as High severity by default. Impact: Deleted Google Cloud Backup and DR host BACKUP_HOSTS_DELETE_HOST Cloud Audit Logs: Backup and DR Service Admin Activity audit logs A host was deleted from the Backup and DR management console. Applications that are associated with the deleted host might not be protected. Findings are classified as Low severity by…

related reading