Skip to main content
Google Cloud Documentation
Technology areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
Cross-product tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Security Command Center
Start free
Overview Guides Reference Samples Resources
Google Cloud Documentation
  • Technology areas
    • More
    • Overview
    • Guides
    • Reference
    • Samples
    • Resources
  • Cross-product tools
    • More
  • Console
  • Security Command Center
  • Findings and issues reference
    • Vulnerability findings reference
      • Vulnerability findings index
      • Vulnerability findings by detector
      • Remediate Security Health Analytics findings
    • Compliance Manager cloud control reference
    • Threat finding reference
      • Threat findings index
      • AI
        • AI threat findings
        • Command and Control: Steganography Tool Detected
        • Credential Access: AI Agent Anomalous Access to Metadata Service
        • Credential Access: Find Google Cloud Credentials
        • Credential Access: GPG Key Reconnaissance
        • Credential Access: Search Private Keys or Passwords
        • Defense Evasion: Base64 ELF File Command Line
        • Defense Evasion: Base64 Encoded Python Script Executed
        • Defense Evasion: Base64 Encoded Shell Script Executed
        • Defense Evasion: Folder Level TokenCreator Role Granted to AI Agent
        • Defense Evasion: Launch Code Compiler Tool In Container
        • Defense Evasion: Organization Level TokenCreator Role Granted to AI Agent
        • Defense Evasion: Project Level TokenCreator Role Granted to AI Agent
        • Discovery: AI Agent Evidence of Port Scanning
        • Discovery: AI Agent Service Account Self-Investigation
        • Discovery: AI Agent Unauthorized Service Account API Call
        • Execution: Added Malicious Binary Executed
        • Execution: Added Malicious Library Loaded
        • Execution: Added Malicious Skill Executed
        • Execution: Added Malicious Skill Loaded
        • Execution: Built in Malicious Binary Executed
        • Execution: Container Escape
        • Execution: Fileless Execution in /memfd:
        • Execution: Kubernetes Attack Tool Execution
        • Execution: Local Reconnaissance Tool Execution
        • Execution: Malicious Python Executed
        • Execution: Modified Malicious Binary Executed
        • Execution: Modified Malicious Library Loaded
        • Execution: Modified Malicious Skill Executed
        • Execution: Modified Malicious Skill Loaded
        • Execution: Netcat Remote Code Execution in Container
        • Execution: Possible Arbitrary Command Execution through CUPS (CVE-2024-47177)
        • Execution: Possible Remote Command Execution Detected
        • Execution: Program Run with Disallowed HTTP Proxy Env
        • Execution: Socat Reverse Shell Detected
        • Execution: Suspicious OpenSSL Shared Object Loaded
        • Exfiltration: AI Agent Initiated BigQuery Data Exfiltration to External Table
        • Exfiltration: AI Agent Initiated BigQuery Data Extraction
        • Exfiltration: AI Agent Initiated BigQuery VPC Perimeter Violation
        • Exfiltration: AI Agent Initiated Cloud SQL Exfiltration to External Bucket
        • Exfiltration: AI Agent Initiated Cloud SQL Exfiltration to Public Bucket
        • Exfiltration: Launch Remote File Copy Tools in Container
        • Impact: Detect Malicious Cmdlines
        • Impact: Remove Bulk Data from Disk
        • Impact: Suspicious crypto mining activity using the Stratum Protocol
        • Initial Access: AI Agent Identity Excessive Permission Denied Actions
        • Initial Access: Dormant Service Account Activity in AI Service
        • Malicious Script Executed
        • Malicious URL Observed
        • Persistence: New AI API Method
        • Persistence: New Geography for AI Service
        • Persistence: Sensitive AI Permission Added to Custom Role
        • Persistence: Sensitive Role Granted by AI Agent
        • Persistence: Sensitive Role Granted to External AI Agent
        • Privilege Escalation: AI Agent Cross-Project Access Token Generation
        • Privilege Escalation: AI Agent Cross-Project OpenID Token Generation
        • Privilege Escalation: AI Agent Token Generation Using Implicit Delegation
        • Privilege Escalation: AI Agent Token Generation Using signJwt
        • Privilege Escalation: Anomalous Impersonation of Service Account for AI Admin Activity
        • Privilege Escalation: Anomalous Multistep Service Account Delegation for AI Admin Activity
        • Privilege Escalation: Anomalous Multistep Service Account Delegation for AI Data Access
        • Privilege Escalation: Anomalous Service Account Impersonator for AI Admin Activity
        • Privilege Escalation: Anomalous Service Account Impersonator for AI Data Access
        • Privilege Escalation: Attempt to Abuse Sudo For Privilege Escalation (CVE-2019-14287)
        • Privilege Escalation: Polkit Local Privilege Escalation Vulnerability (CVE-2021-4034)
        • Privilege Escalation: Sudo Potential Privilege Escalation (CVE-2021-3156)
        • Reverse Shell
        • Unexpected Child Shell
      • Amazon EC2
        • Malware: Malicious file on disk
      • Backup and DR
        • Backup and DR threat findings
        • Impact: Deleted Google Cloud Backup and DR Backup
        • Impact: Deleted Google Cloud Backup and DR Vault
        • Impact: Deleted Google Cloud Backup and DR host
        • Impact: Deleted Google Cloud Backup and DR plan association
        • Impact: Google Cloud Backup and DR delete policy
        • Impact: Google Cloud Backup and DR delete profile
        • Impact: Google Cloud Backup and DR delete storage pool
        • Impact: Google Cloud Backup and DR delete template
        • Impact: Google Cloud Backup and DR expire all images
        • Impact: Google Cloud Backup and DR expire image
        • Impact: Google Cloud Backup and DR reduced backup expiration
        • Impact: Google Cloud Backup and DR reduced backup frequency
        • Impact: Google Cloud Backup and DR remove appliance
        • Impact: Google Cloud Backup and DR remove plan
      • BigQuery
        • BigQuery threat findings
        • Exfiltration: BigQuery Data Exfiltration
        • Exfiltration: BigQuery Data Extraction
        • Exfiltration: BigQuery Data to Google Drive
        • Exfiltration: Move to Public BigQuery resource
      • Cloud Run
        • Cloud Run threat findings
        • Command and Control: Steganography Tool Detected
        • Credential Access: Find {{gcp_name_abbr}} Credentials
        • Credential Access: GPG Key Reconnaissance
        • Credential Access: Search Private Keys or Passwords
        • Defense Evasion: Base64 ELF File Command Line
        • Defense Evasion: Base64 Encoded Bash Script Executed
        • Defense Evasion: Base64 Encoded Python Script Executed
        • Defense Evasion: Launch Code Compiler Tool In Container
        • Execution: Added Malicious Binary Executed
        • Execution: Added Malicious Library Loaded
        • Execution: Added Malicious Skill Executed
        • Execution: Added Malicious Skill Loaded
        • Execution: Built in Malicious Binary Executed
        • Execution: Built in Malicious Skill Executed
        • Execution: Container Escape
        • Execution: Cryptomining Docker Image
        • Execution: Fileless Execution in /memfd:
        • Execution: Kubernetes Attack Tool Execution
        • Execution: Local Reconnaissance Tool Execution
        • Execution: Malicious Python executed
        • Execution: Modified Malicious Binary Executed