Threat detection
Google Cloud provides several types of threat detection via SCC Premium:
- Event Threat Detection
- Container Threat Detection
- VM Threat Detection
- Anomaly Detection
Let us start with ETD.
Event Threat Detection
Event Threat Detection (ETD) is a built-in feature of the SCC Premium tier that watches your Google Cloud environment in real time and detects threats within your systems. New detectors are added to ETD regularly to discover emerging threats at cloud scale.
ETD produces security findings by matching events in your Cloud Logging and Google Workspace log streams to known indicators of compromise (IoCs). IoCs, developed by internal Google security sources, identify potential vulnerabilities and attacks. ETD also detects threats by identifying known adversarial tactics, techniques, and procedures in your logging stream, and by detecting deviations from the historically observed behavior of your Google Cloud organization.
Here are...