בדף הזה מוסבר איך לעיין בתוצאות של Event Threat Detection במסוף Google Cloud , ומוצגות דוגמאות לתוצאות של Event Threat Detection.
Event Threat Detection הוא שירות מובנה שעוקב אחרי מקורות הנתונים של יומני Cloud Logging בארגון או בפרויקטים שלכם ומזהה איומים כמעט בזמן אמת. אם מפעילים את Security Command Center ברמת הארגון, אפשר גם לעקוב אחרי זרמי הרישום ביומן של Google Workspace באמצעות התכונה Event Threat Detection. מידע נוסף זמין במאמר סקירה כללית על Event Threat Detection.
הפעלה או השבתה של Event Threat Detection
כברירת מחדל, התכונה Event Threat Detection (זיהוי איומים באירועים) מופעלת. מידע כללי על הפעלה או השבתה של שירות מובנה או המודולים שלו זמין במאמר הגדרת שירותים של Security Command Center.
בדיקת הממצאים
כדי לראות את הממצאים של Event Threat Detection, צריך להפעיל את השירות בהגדרות Services ב-Security Command Center. אחרי שמפעילים את Event Threat Detection, הוא סורק יומנים ספציפיים כדי ליצור ממצאים. חלק מהיומנים ש-Event Threat Detection יכול לסרוק מושבתים כברירת מחדל, ולכן יכול להיות שתצטרכו להפעיל אותם.
מידע נוסף על כללי הזיהוי המובנים שבהם נעשה שימוש ב-Event Threat Detection ועל היומנים שנסרקים על ידי Event Threat Detection זמין בנושאים הבאים:
אפשר לראות את הממצאים של Event Threat Detection ב-Security Command Center. אם הגדרתם ייצוא רציף לכתיבת יומנים, תוכלו גם לראות את הממצאים ב-Cloud Logging. ייצוא רציף ל-Cloud Logging זמין רק כשמפעילים את Security Command Center ברמת הארגון. כדי ליצור ממצא ולאמת את ההגדרה, אפשר להפעיל בכוונה גלאי ולבדוק את Event Threat Detection.
ההפעלה של Event Threat Detection מתבצעת תוך שניות. בדרך כלל, זמן האחזור של הזיהוי הוא פחות מ-15 דקות מהרגע שבו נכתב יומן ועד שהממצא זמין ב-Security Command Center. מידע נוסף על זמן האחזור זמין במאמר סקירה כללית של זמן האחזור ב-Security Command Center.
בדיקת הממצאים ב-Security Command Center
אפשר להעניק את תפקידי ה-IAM של Security Command Center ברמת הארגון, התיקייה או הפרויקט. היכולת שלכם להציג, לערוך, ליצור או לעדכן ממצאים, נכסים ומקורות אבטחה תלויה ברמת הגישה שניתנה לכם. מידע נוסף על תפקידים ב-Security Command Center זמין במאמר בקרת גישה.
כדי לעיין בממצאים במסוף Google Cloud :
במסוף Google Cloud , עוברים לדף Findings של Security Command Center.
אם צריך, בוחרים את Google Cloud הפרויקט או הארגון.
בקטע Quick filters, בקטע המשנה Source display name, בוחרים אחת מהאפשרויות הבאות או את שתיהן:
- Event Threat Detection: כדי לסנן ממצאים שנוצרו על ידי גלאים מובנים של Event Threat Detection
- מודולים מותאמים אישית של Event Threat Detection: כדי לסנן ממצאים שנוצרו על ידי מודולים מותאמים אישית של Event Threat Detection
הטבלה מאוכלסת בממצאים של Event Threat Detection.
כדי לראות את הפרטים של ממצא ספציפי, לוחצים על שם הממצא בקטע
Category. חלונית פרטי הממצא מתרחבת ומוצג בה מידע, כולל:- מתי האירוע התרחש
- המקור של נתוני הממצאים
- רמת החומרה של הזיהוי, לדוגמה גבוהה
- הפעולות שבוצעו, כמו הוספת תפקיד בניהול זהויות והרשאות גישה (IAM) למשתמש ב-Gmail
- המשתמש שביצע את הפעולה, מופיע לצד כתובת אימייל ראשית
כדי להציג את כל הממצאים שנוצרו כתוצאה מהפעולות של אותו משתמש:
- בחלונית הפרטים של הממצא, מעתיקים את כתובת האימייל שלצד כתובת אימייל ראשית.
- סוגרים את החלונית.
בעורך השאילתות, מזינים את השאילתה הבאה:
access.principal_email="USER_EMAIL"מחליפים את USER_EMAIL בכתובת האימייל שהעתקתם קודם.
ב-Security Command Center מוצגים כל הממצאים שמשויכים לפעולות שבוצעו על ידי המשתמש שציינתם.
צפייה בממצאים ב-Cloud Logging
אם מגדירים ייצוא רציף לכתיבת יומנים, אפשר לראות את הממצאים של Event Threat Detection ב-Cloud Logging. התכונה הזו זמינה רק אם מפעילים את רמת הפרימיום של Security Command Center ברמת הארגון.
כדי לראות את הממצאים של Event Threat Detection ב-Cloud Logging:
נכנסים אל Logs Explorer במסוף Google Cloud .
בוחרים את Google Cloud הפרויקט או משאב אחר Google Cloud שבו מאוחסנים היומנים של Event Threat Detection.
משתמשים בחלונית Query כדי ליצור את השאילתה באחת מהדרכים הבאות:
- ברשימה All resources (כל המשאבים), מבצעים את הפעולות הבאות:
- בוחרים באפשרות גלאי איומים כדי להציג רשימה של כל הגלאים.
- כדי לראות את הממצאים מכל הגלאים, בוחרים באפשרות all detector_name. כדי לראות את הממצאים של גלאי ספציפי, בוחרים את השם שלו.
- לוחצים על אישור. הטבלה Query results מתעדכנת עם היומנים שבחרתם.
מזינים את השאילתה הבאה בעורך השאילתות ולוחצים על Run query:
resource.type="threat_detector"
הטבלה Query results מתעדכנת עם היומנים שבחרתם.
- ברשימה All resources (כל המשאבים), מבצעים את הפעולות הבאות:
כדי לראות יומן, בוחרים שורה בטבלה ולוחצים על הרחבת שדות מקוננים.
אתם יכולים ליצור שאילתות מתקדמות ביומן כדי לציין קבוצה של רשומות ביומן מכל מספר של יומנים.
דוגמאות לפורמטים של ממצאים
בקטע הזה מופיעים קישורים לדוגמאות של פלט JSON לתוצאות של Event Threat Detection. הפלט הזה מוצג כשמייצאים ממצאים באמצעותGoogle Cloud המסוף או כשמציגים רשימה של ממצאים באמצעות Security Command Center API או Google Cloud CLI.
בדף הזה מופיעות דוגמאות לסוגים שונים של ממצאים. כל דוגמה כוללת רק את השדות שהכי רלוונטיים לסוג הממצאים הזה.
רשימה מלאה של השדות שזמינים בממצא מופיעה במאמרי העזרה של ה-API של Security Command Center, במאמר על המשאב Finding.
כדי לראות דוגמאות לממצאים, אפשר ללחוץ על אחד מהקישורים הבאים.
| ממצא איום | דוגמה ל-JSON |
|---|---|
Active Scan: Log4j Vulnerable to RCE |
דוגמה לקובץ JSON |
Brute force SSH |
דוגמה לקובץ JSON |
Cloud IDS: THREAT_IDENTIFIER |
דוגמה לקובץ JSON |
Defense Evasion: Breakglass Workload Deployment Created |
דוגמה לקובץ JSON |
Defense Evasion: Breakglass Workload Deployment Updated |
דוגמה לקובץ JSON |
Defense Evasion: Folder Level TokenCreator Role Granted to AI Agent |
דוגמה לקובץ JSON |
Defense Evasion: Modify VPC Service Control |
דוגמה לקובץ JSON |
Defense Evasion: Organization Level TokenCreator Role Granted to AI Agent |
דוגמה לקובץ JSON |
Defense Evasion: Project Level TokenCreator Role Granted to AI Agent |
דוגמה לקובץ JSON |
Discovery: AI Agent Service Account Self-Investigation |
דוגמה לקובץ JSON |
Discovery: AI Agent Unauthorized Service Account API Call |
דוגמה לקובץ JSON |
Discovery: Can get sensitive Kubernetes object check |
דוגמה לקובץ JSON |
Discovery: Service Account Self-Investigation |
דוגמה לקובץ JSON |
Evasion: Access from Anonymizing Proxy |
דוגמה לקובץ JSON |
Execution: Cryptomining Docker Image |
דוגמה לקובץ JSON |
Exfiltration: AI Agent Initiated BigQuery Data Exfiltration to External Table |
דוגמה לקובץ JSON |
Exfiltration: AI Agent Initiated BigQuery Data Extraction |
דוגמה לקובץ JSON |
Exfiltration: AI Agent Initiated BigQuery VPC Perimeter Violation |
דוגמה לקובץ JSON |
Exfiltration: AI Agent Initiated CloudSQL Exfiltration to External Bucket |
דוגמה לקובץ JSON |
Exfiltration: AI Agent Initiated CloudSQL Exfiltration to Public Bucket |
דוגמה לקובץ JSON |
Exfiltration: BigQuery Data Exfiltration |
דוגמה לקובץ JSON |
Exfiltration: BigQuery Data Extraction |
דוגמה לקובץ JSON |
Exfiltration: BigQuery Data to Google Drive |
דוגמה לקובץ JSON |
Exfiltration: Cloud SQL Data Exfiltration |
דוגמה לקובץ JSON |
Exfiltration: Cloud SQL Over-Privileged Grant |
דוגמה לקובץ JSON |
Exfiltration: Cloud SQL Restore Backup to External Organization |
דוגמה לקובץ JSON |
Impact: Cryptomining Commands |
דוגמה לקובץ JSON |
Impact: Deleted Google Cloud Backup and DR Backup |
דוגמה לקובץ JSON |
Impact: Deleted Google Cloud Backup and DR host |
דוגמה לקובץ JSON |
Impact: Deleted Google Cloud Backup and DR plan association |
דוגמה לקובץ JSON |
Impact: Deleted Google Cloud Backup and DR Vault |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR delete policy |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR delete profile |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR delete storage pool |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR delete template |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR expire all images |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR expire image |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR reduced backup expiration |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR reduced backup frequency |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR remove appliance |
דוגמה לקובץ JSON |
Impact: Google Cloud Backup and DR remove plan |
דוגמה לקובץ JSON |
Initial Access: Account Disabled Hijacked |
דוגמה לקובץ JSON |
Initial Access: AI Agent Identity Excessive Permission Denied Actions |
דוגמה לקובץ JSON |
Initial Access: Database Superuser Writes to User Tables |
דוגמה לקובץ JSON |
Initial Access: Disabled Password Leak |
דוגמה לקובץ JSON |
Initial Access: Dormant Service Account Action |
דוגמה לקובץ JSON |
Initial Access: Dormant Service Account Activity in AI Service |
דוגמה לקובץ JSON |
Initial Access: Dormant Service Account Key Created |
דוגמה לקובץ JSON |
Initial Access: Excessive Permission Denied Actions |
דוגמה לקובץ JSON |
Initial Access: Government Based Attack |
דוגמה לקובץ JSON |
Initial Access: Leaked Service Account Key Used |
דוגמה לקובץ JSON |
Initial Access: Log4j Compromise Attempt |
דוגמה לקובץ JSON |
Initial Access: Suspicious Login Blocked |
דוגמה לקובץ JSON |
Lateral Movement: Modified Boot Disk Attached to Instance |
דוגמה לקובץ JSON |
Malware: bad domain |
דוגמה לקובץ JSON |
Malware: bad IP |
דוגמה לקובץ JSON |
Malware: Cryptomining Bad Domain |
דוגמה לקובץ JSON |
Malware: Cryptomining Bad IP |
דוגמה לקובץ JSON |
Persistence: GCE Admin Added SSH Key |
דוגמה לקובץ JSON |
Persistence: GCE Admin Added Startup Script |
דוגמה לקובץ JSON |
Persistence: IAM Anomalous Grant |
דוגמה לקובץ JSON |
Persistence: New AI API Method |
דוגמה לקובץ JSON |
Persistence: New API Method |
דוגמה לקובץ JSON |
Persistence: New Geography |
דוגמה לקובץ JSON |
Persistence: New Geography for AI Service |
דוגמה לקובץ JSON |
Persistence: New User Agent |
דוגמה לקובץ JSON |
Persistence: Sensitive AI Permission Added to Custom Role |
דוגמה לקובץ JSON |
Persistence: Sensitive Role Granted by AI Agent |
דוגמה לקובץ JSON |
Persistence: Sensitive Role Granted to External AI Agent |
דוגמה לקובץ JSON |
Persistence: SSO Enablement Toggle |
דוגמה לקובץ JSON |
Persistence: SSO Settings Changed |
דוגמה לקובץ JSON |
Persistence: Strong Authentication Disabled |
דוגמה לקובץ JSON |
Persistence: Two Step Verification Disabled |
דוגמה לקובץ JSON |
Privilege Escalation: AI Agent Cross-Project Access Token Generation |
דוגמה לקובץ JSON |
Privilege Escalation: AI Agent Cross-Project OpenID Token Generation |
דוגמה לקובץ JSON |
Privilege Escalation: AI Agent Token Generation Using Implicit Delegation |
דוגמה לקובץ JSON |
Privilege Escalation: AI Agent Token Generation Using signJwt |
דוגמה לקובץ JSON |
Privilege Escalation: AlloyDB Database Superuser Writes to User Tables |
דוגמה לקובץ JSON |
Privilege Escalation: AlloyDB Over-Privileged Grant |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Impersonation of Service Account for Admin Activity |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Impersonation of Service Account for AI Admin Activity |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Multistep Service Account Delegation for Admin Activity |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Multistep Service Account Delegation for AI Admin Activity |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Multistep Service Account Delegation for AI Data Access |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Multistep Service Account Delegation for Data Access |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Service Account Impersonator for Admin Activity |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Service Account Impersonator for AI Admin Activity |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Service Account Impersonator for AI Data Access |
דוגמה לקובץ JSON |
Privilege Escalation: Anomalous Service Account Impersonator for Data Access |
דוגמה לקובץ JSON |
Privilege Escalation: Changes to sensitive Kubernetes RBAC objects |
דוגמה לקובץ JSON |
Privilege Escalation: Create Kubernetes CSR for master cert |
דוגמה לקובץ JSON |
Privilege Escalation: Creation of sensitive Kubernetes bindings |
דוגמה לקובץ JSON |
Privilege Escalation: Default Compute Engine Service Account SetIAMPolicy |
דוגמה לקובץ JSON |
Privilege Escalation: Dormant Service Account Granted Sensitive Role |
דוגמה לקובץ JSON |
Privilege Escalation: External Member Added To Privileged Group |
דוגמה לקובץ JSON |
Privilege Escalation: Get Kubernetes CSR with compromised bootstrap credentials |
דוגמה לקובץ JSON |
Privilege Escalation: Impersonation Role Granted For Dormant Service Account |
דוגמה לקובץ JSON |
Privilege Escalation: Launch of privileged Kubernetes container |
דוגמה לקובץ JSON |
Privilege Escalation: Privileged Group Opened To Public |
דוגמה לקובץ JSON |
Privilege Escalation: Sensitive Role Granted To Hybrid Group |
דוגמה לקובץ JSON |