You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
August 13, 2026
AI Protection supports data residency in the Kingdom of Saudi Arabia (KSA) for all Security Command Center service tiers.
For more information, see Planning for data residency.
August 10, 2026
The integration of Security Command Center with Application Design Center for application lifecycle security assessments is generally available (GA). Design-time findings are sent to Security Command Center on demand during deployment. This feature lets you filter findings by App Hub application at the app-enabled folder and project levels.
For more information, see Application lifecycle security assessments.
Vulnerability Assessment for Google Cloud is available in General Availability.
August 04, 2026
Security Command Center released new Malicious Skill runtime threat detectors for Google Kubernetes Engine (GKE), Cloud Run, and Agent Platform. These detectors identify when a malicious skill (an AI agent capability) is executed or loaded. A malicious skill is any malicious binary that has been tagged as an LLM skill by Google's threat intelligence.
For more information, see the following:
August 03, 2026
The Assured Open Source Software Premium tier supports JavaScript (NPM) packages for Node.js environments.
For more information, see Download NPM packages using direct repository access and List of supported NPM packages for the Assured Open Source Software premium tier.
For the Security Command Center Standard tier, AI Protection is supported for both projects and organizations.
Project-level activations for the Standard tier include access to the AI security dashboard, basic inventory view (excluding Gemini models), and baseline security findings.
Some features of AI Protection are only available for the Premium and Enterprise tiers or for organization-level activations. For more information, see Configure AI Protection.
July 31, 2026
Organizations that are enrolled in the data residency Preview program can update their organization's data residency and data encryption configuration. For more information, see Modify data residency or data encryption configuration.
Agent Platform Vulnerability Assessment (Preview) scans for plaintext secrets, such as credentials, access tokens, and API keys, in customer-deployed Gemini Enterprise Agent Platform containers. For more information, see Agent Platform Vulnerability Assessment.
July 28, 2026
Version 1.2.0 of the Google SCC ITSM app and version 1.3.0 of the Google SCC SIR app have been released.
To reflect this update, the ServiceNow integration guide is updated with the following changes:
- Added support for ServiceNow Yokohama, Zurich, and Australia versions.
Added the following features:
- Mute and unmute findings
- Create mute rules
- Create Configuration Item (CI) lookup rules
- View the action log
Updated setup instructions for Java KeyStore certificates.
Added additional troubleshooting steps for maximum execution time exceeded errors, data collection issues, and ECC Queue timeout errors.
For more information, see Sending Security Command Center data to ServiceNow.
July 27, 2026
For the Security Command Center Premium tier, you can enable AI Protection at the project level.
Project-level activations include access to the AI security dashboard, AI threat detection, and AI vulnerability and misconfiguration findings.
Some features of AI Protection are only available for organization-level activations. For more information, see Configure AI Protection.
For the Security Command Center Premium tier, you can enable AI Protection at the project level.
Project-level activations include access to the AI security dashboard, AI threat detection, and AI vulnerability and misconfiguration findings.
For more information, see Configure AI Protection.
July 17, 2026
Key insights from Security Command Center are available on the Security & compliance page in Cloud Hub. This feature is available in General Availability.
July 13, 2026
You can integrate Security Command Center with Jira to review findings in your Jira project. For more information, see Integrate Jira with Security Command Center.
July 09, 2026
You can modify the data residency and data encryption configuration on the Premium and Standard tiers after you activate Security Command Center for your organization. For more information, see Modify data residency or data encryption configuration.
June 25, 2026
The Assured Open Source Software premium tier includes an updated list of curated binaries for the Go, Java, and Python languages.
For more information, see List of supported Java and Python packages for the Assured OSS premium tier and List of supported Go packages for the Assured OSS premium tier.
June 18, 2026
Security Command Center External Exposure is available in Preview for the Security Command Center Premium tier. The service helps you manage and reduce your external attack surface through automated asset discovery, Google Cloud network exposure path validation, and active exploitability testing.
For more information, see Detect exposed resources.
June 05, 2026
AI Protection supports data residency in the European Union (EU) for the Security Command Center Premium tier.
For more information, see Planning for data residency.
The following Security Command Center finding category names from AI Protection have new names that clarify that AI Protection detects Gemini foundation models:
VERTEX_AI_MODEL_DETECTEDchanges toGEMINI_MODEL_DETECTED.VERTEX_AI_MODEL_NOT_PROTECTED_BY_MODEL_ARMORchanges toGEMINI_MODEL_NOT_PROTECTED_BY_MODEL_ARMOR.
For more information about AI Protection findings, see AI Protection overview.
May 28, 2026
Risk Engine detects toxic combinations that are related to Managed Service for Apache Spark (formerly known as Dataproc), including Lightning Engine.
Risk reports are updated to include more content in the Risk Engine introduction and the System attack exposure pages. For more information about what's included in risk reports, see Risk reports overview.
May 21, 2026
The following Compliance Manager frameworks were updated:
- CIS Critical Security Controls v8 (version 8.0)
- CIS GCP Foundations Benchmark v3.0 (version 7.0)
- CSA Cloud Controls Matrix v4.0.11 (version 7.0)
- ISO 27001:2022 (version 9.0)
- NIST 800-53 Revision 5 (version 9.0)
- NIST Cybersecurity Framework 1.1 (version 8.0)
- PCI DSS v4.0.1 (version 6.0)
- Qatar National Information Assurance Standard v2.1 (version 6.0)
- SOC 2017 (version 7.0)
The Security Command Center Enterprise service tier is deprecated. It will be shut down on May 21, 2027. By default, your organization will automatically move to the Premium service tier on that date.
Artifact guard is available in Preview to the Security Command Center Enterprise and Premium tiers. Artifact guard is a service that helps you prevent the deployment of vulnerable packages throughout the software development lifecycle.
Risk Engine detects toxic combinations that are related to Cloud Build resources.
May 19, 2026
Vulnerability Assessment for Google Cloud supports scanning XFS and NTFS disk partition types.
May 15, 2026
Vulnerability Assessment for Google Cloud supports scanning GKE clusters that have Image streaming enabled.
May 11, 2026
Compliance Manager can be enabled for a single project. For more information, see Enable Compliance Manager.
New Standard tier activations at the organization level support the enhanced Standard tier features. New Standard tier activations at the project level continue to support Standard-legacy tier features. For more information, see Standard tier enhanced and automatically activated for some customers.
April 22, 2026
When Security Command Center is activated at the project level only, you can enable Vulnerability Assessment for Google Cloud on the single project.
Security Command Center has new predefined rules and controls:
Additional predefined security graph rules to support Agent Runtime
Additional support in existing correlated threats rules for Agent Runtime
Additional runtime detectors in Agent Platform Threat Detection
Additional Event Threat Detection rules to support AI agents
Security Command Center findings that are related to AI security risks are available in the Security tab of the Gemini Enterprise Agent Platform. The feature helps provide comprehensive visibility into findings, active threats, and attack path simulations. This feature requires Security Command Center Premium or Enterprise.
For more information, see View security findings.
April 17, 2026
Through the Application Design Center, Security Command Center helps you perform proactive security assessments (Preview) throughout your application development lifecycle. This integration shows both design-time and runtime findings in Security Command Center. For more information, see Application lifecycle security assessments.
Data Security Posture Management has new controls in Preview. The controls help you secure Cloud Storage objects and include the following:
- Govern the minimum retention period for Cloud Storage objects
- Require Customer-Managed Encryption for Cloud Storage objects
- Restrict Public Access to Cloud Storage objects
For more information, see Advanced data governance and security cloud controls.
April 16, 2026
AI Protection supports agentic workloads in Preview, including Gemini Enterprise Agent Platform and Model Context Protocol (MCP) servers. This update includes the following:
- Agent Platform Vulnerability Assessment: Identifies software vulnerabilities (CVEs) in agentic workloads that are deployed with Gemini Enterprise Agent Platform. Findings are surfaced for vulnerabilities of HIGH or CRITICAL severity that are detected in your custom dependencies.
- Expanded detection and controls: Includes new threat detection findings and recommended security controls for AI agents and MCP servers.
- Enhanced inventory and filtering: Provides an updated AI security dashboard view and new filtering options for agentic resources in the console.
April 15, 2026
When you activate Security Command Center Standard or Premium tier for a project, several services are automatically enabled and service-specific service agents are provisioned with the required IAM roles and permissions.
For more information, see Activate for a project when Security Command Center is not active in the organization.
April 14, 2026
Cloud Run Threat Detection monitors Cloud Run worker pools. For a list of resources that Cloud Run Threat Detection monitors, see Supported resources.
April 09, 2026
Key insights from Security Command Center are available on the Security & compliance page in Cloud Hub. This feature is available in Preview.
April 02, 2026
Security Command Center Risk Engine supports Managed Service for Apache Spark resources in attack paths and Managed Service for Apache Spark clusters and jobs in high-value resource sets.
March 31, 2026
Risk Engine supports
aiplatform.googleapis.com/ReasoningEngine
in both attack paths and high value
resource
sets.
March 27, 2026
Risk Engine has launched enhanced heuristics to help identify default high-value resources.
If you are using the default high-value resource set, you might observe changes in the exposure scores of their findings, resources, and issues. For information about these changes, see Default high-value resource set.
March 25, 2026
The following Compliance Manager frameworks were updated:
- CIS GKE 1.7 (version 3.0)
- CIS Critical Security Controls v8 (version 6.0)
- CSA Cloud Controls Matrix v4.0.11 (version 5.0)
- ISO 27001:2022 (version 7.0)
- Qutar National Information Assurance Standard v2.1 (version 4.0)
- NIST 800-53 Revision 5 (version 7.0)
- NIST Cybersecurity Framework 1.1 (version 6.0)
- PCI DSS v4.0.1 (version 4.0)
- Security Essentials (version 12.0)
- SOC 2017 (version 5.0)
March 16, 2026
The names of Event Threat Detection rules pertaining to AI control plane have changed.
The Cloud Run Threat Detection rule
Privilege Escalation: Fileless Execution in /dev/shm has been shut
down.
March 09, 2026
In March 2026, Risk Engine will launch enhanced heuristics to more accurately identify default high-value resources.
No action is required. As a result of this enhancement, customers using the default high-value resource set may observe changes in the exposure scores of their findings, resources, and issues. Customers using custom resource value configurations are not affected.
March 05, 2026
AI Protection is generally available (GA) in the Security Command Center Premium tier at the organization level.
For regional availability, see Locations for AI Protection.
February 26, 2026
Security Command Center lets you filter findings, issues, and compliance information to view only the resources that are registered to an App Hub application. For information, see Integration with App Hub.
February 11, 2026
The Security Command Center Standard tier, available at no charge, has a new set of capabilities and is activated automatically for some organizations. For information about these changes, see Standard tier enhanced and automatically activated for some customers.
January 30, 2026
The prompt injection and jailbreak detection
filter for the Mumbai (asia-south1) and Singapore (asia-southeast1) regions
is upgraded to improve detection accuracy and reduce the rate of false positives.
December 16, 2025
The following Container Threat Detection detectors have been released to General Availability:
Command and Control: Piped Encoded Code Execution DetectedCommand and Control: Piped Encoded Download
December 15, 2025
You can configure Model Armor floor settings for Google-managed Model Context Protocol (MCP) servers to define baseline safety and security filters. This feature is in Preview.
You can also configure Cloud Logging for sanitization operations. The Model Armor floor settings perform these operations on traffic to and from Google-managed MCP servers and Gemini Enterprise Agent Platform models.
December 12, 2025
Multiple pages in Security Command Center Standard have been improved:
- The Risk overview page is enhanced to provide separate views for misconfiguration, vulnerabilities and identity-related findings.
- The Findings page includes predefined filter views for vulnerabilities and identity findings.
- The left navigation has been updated.
AI Protection is generally available (GA) in the Security Command Center Enterprise tier and is available as a Preview in the Security Command Center Premium tier.
December 11, 2025
Security Command Center Risk Engine supports Cloud Build Attack Paths with Cloud Build Resources supported in the high-value resource set.
December 10, 2025
You can configure Model Armor to enhance the security of your agentic AI applications that interact with Google Cloud Model Context Protocol (MCP) servers. This feature is in Preview. For configuration details, see Model Armor integration with Google Cloud MCP servers.
December 05, 2025
Security Command Center Risk Engine
uses the storage.restrictAuthTypes
organization policy constraint to determine whether Cloud Storage buckets are
reachable using signed URLs.
December 04, 2025
The monitoring dashboard is available in General Availability.
December 03, 2025
November 20, 2025
The following updates simplify Security Command Center Standard and Premium tier activation for organizations:
- You need fewer Identity and Access Management (IAM) roles to activate Security Command Center.
- A variety of services are automatically enabled during activation. Service-specific service agents are automatically enabled with the IAM roles and permissions that are required for these services to function.
See the following for detailed information about activating a specific tier:
November 17, 2025
The following AI Protection features are available:
- AI Security dashboard: The dashboard has an updated AI Inventory section, which includes an overview of AI agents.
- Assets page: You can filter for AI resources, including AI agents that are deployed to Agent Runtime.
AI Protection is available in Preview to the Security Command Center Enterprise tier.
Agent Engine Threat Detection, a built-in service of Security Command Center, is available in Preview to the Security Command Center Enterprise and Premium tiers. This service helps you detect and investigate potential attacks on AI agents that are deployed to Agent Runtime Runtime.
November 14, 2025
Data Security Posture Management (DSPM) supports the Security Command Center Premium tier at the organization level.
November 11, 2025
Several features and updates have been made available to Security Command Center in a federated identity environment:
- Exporting findings to a CSV file.
- Exporting findings to Cloud Storage.
The following features aren't supported by identity federation but are being moved to other sections in the documentation:
- Sending feedback in Security Command Center
- Managing Google SecOps settings.
November 10, 2025
Model Armor is available in the following regions:
europe-west1(Belgium)europe-west2(London)europe-west3(Frankfurt)asia-south1(Mumbai)
For more information, see Locations for the Model Armor API.
Data Security Posture Management (DSPM) has been released to General Availability for the Security Command Center Enterprise tier.
November 07, 2025
You can use customer-managed encryption keys (CMEK) organization policies with Security Command Center. For more information, see Use CMEK organization policies with Security Command Center.
The monitoring and auditing capabilities for Compliance Manager have been released to General Availability.
November 06, 2025
Security Command Center Risk Engine supports Cloud Run attack paths for the following high-value resources:
run.googleapis.com/Jobrun.googleapis.com/Service
November 03, 2025
Compliance Manager supports the Security Command Center Premium tier at the organization level.
October 30, 2025
In addition to the Enterprise service tier, Issues are available on the Security Command Center Premium service tier at the organization level. This update includes capabilities such as Toxic Combinations, Chokepoints, and Graph Search (Preview). The console navigation has been updated to reflect an Issues page for Premium tier users.
October 21, 2025
The release note for Security Command Center and attack path simulations, published on October 16, 2025, was updated to clarify that attack path simulations use Compute Engine and Google Kubernetes Engine OS and software vulnerability findings to detect toxic combinations and chokepoints.
October 20, 2025
Container image vulnerability findings has been released to General Availability.
October 17, 2025
Customers with an organization-level activation of Security Command Center Premium have an organization-level discovery subscription at no charge from Sensitive Data Protection. For more information, see Sensitive data discovery in Security Command Center Premium.
October 16, 2025
Security Command Center and attack path simulations use Compute Engine and Google Kubernetes Engine operating system and software vulnerabilities to detect toxic combinations and chokepoints.
UPDATE: Attack path simulations analyze OS and software vulnerability findings for Compute Engine and Google Kubernetes Engine resources to detect toxic combinations and chokepoints.
October 15, 2025
The following features in Compliance Manager are available in General Availability:
- Applying and updating built-in frameworks and cloud controls
- Creating, applying, and editing custom frameworks and cloud controls
- Support for VPC Service Control perimeters
- Audit logging
- Client libraries
- REST APIs
October 10, 2025
Correlated Threats is available in Preview. This feature combines related threat findings together by using the security graph, helping you to prioritize and respond to active threats.
October 09, 2025
Data Security Posture Management (available in Preview) lets you deploy frameworks with advanced data security cloud controls to app-enabled folders. For more information, see Deploy advanced data security cloud controls.
October 07, 2025
Google Cloud console pages for all Security Command Center tiers have been enhanced.
The following changes were made to all service tiers—Standard, Premium, and Enterprise:
- You can refresh findings in the Finding query results panel.
- The JSON tab on the detail pane of the Findings page displays the raw findings JSON object, making it compatible with APIs.
- Autocompletion of a query in the Findings page query editor is improved.
- The Findings > Quick filters panel shows default values if there is an error fetching results.
- The Findings > Quick filters panel shows separate State and Mute filter sections.
The following changes were made to the Enterprise service tier:
- Added support for the Vulnerabilities page.
- Added support for security marks.
- Added support for the Threats dashboard on the Risk overview page.
- The finding detail panel on the Issues page is updated. Open the panel using the View details button when viewing a toxic combination issue type.
- Additional query operators and query functions are available.
- The opt-out banner is no longer available.
September 27, 2025
Model Armor limits the maximum input size for files and text to 4 MB, automatically skipping any content that exceeds this threshold.
September 23, 2025
The upgraded model for the prompt injection and jailbreak detection filter is available in EU multi-region. This model has improved detection rates across several attack vectors, including the following:
- Do Anything Now prompts
- System instruction manipulation
- Unauthorized action execution
- Sensitive information retrieval
Bulk export findings to BigQuery is available in General Availability. Bulk exports are supported for organizations, projects, and folders.
September 22, 2025
Graph search lets you explore the security graph using custom queries. This product is available in Preview in the Security Command Center Enterprise tier.
September 16, 2025
Model Armor is integrated with Google Agentspace to provide greater insights and enhanced security of your agent interactions by default. For more information, see Integration with Google Agentspace.
September 15, 2025
The Findings page in Security Command Center has been improved.
With Security Command Center Premium and Enterprise, the page includes the following predefined filter views that return a specific category of findings.
- Premium service tier: All Findings, Vulnerabilities, Identity, and Threats.
- Enterprise service tier: All Findings, Vulnerabilities, Identity, Data, and Code.
With Security Command Center Enterprise, the page includes a selector to filter by cloud provider: Google Cloud, Amazon Web Service (AWS), and Microsoft Azure.
For more information, see Review and manage findings.
September 12, 2025
Security Command Center has improved the automatic selection of resources when running attack path simulations using the default high-value resource set.
Risk Engine uses heuristics to identify resources used for non-production purposes. To help ensure that you have information about the most important assets, Risk Engine calculates the attack exposure score for all other resources in the default high-value resource set before calculating the attack exposure score for these non-production resources.
To customize the high-value resource set, see Define and manage your high-value resource set. For information about Risk Engine, see Attack exposure scores and attack paths.
Security Command Center changed how Google Cloud subnets are handled when running attack path simulations. The result is that attack paths are more accurate in relation to networking. Certain customers with specific Google Cloud subnet configurations, for example, when a VPC connector accesses a subnetwork, may see significant changes to toxic combinations, chokepoints, and attack exposure scores.
September 11, 2025
Assured Open Source Software (Assured OSS) now supports Go packages. For more information, see Download Go packages using direct repository access.
September 10, 2025
Cloud Run Threat Detection is available in General Availability.
September 08, 2025
The Model Armor monitoring dashboard provides a centralized view to track interactions and violations within your projects. This feature is available in Preview. For more information, see View the monitoring dashboard.
Multiple pages in Security Command Center Premium have been improved:
- The Risk overview page is enhanced to provide a view of threats, vulnerabilities, and misconfigurations.
- The Findings page includes predefined filter views for vulnerabilities and identity findings.
- Information previously on the Threats page is available in the Threats dashboard on the Risk overview page.
- Information previously on the Vulnerabilities page is now available on the Vulnerabilities dashboard on the Risk overview page.
September 02, 2025
Vulnerability assessment for Google Cloud supports scanning disks configured with customer-managed encryption keys (CMEK) for projects that are outside of VPC Service Controls perimeters. For more information about how to scan disks configured with CMEK, see Run Vulnerability Scans for CMEK disks.
August 27, 2025
Compliance Manager (available in Preview) now lets you remove resources from deployed frameworks.
August 20, 2025
Issues, chokepoints (for Google Cloud), and predefined security graph rules have been released to General Availability.
August 15, 2025
AI Protection helps you manage the security posture of your AI workloads by detecting threats and helping you to mitigate risks to your AI asset inventory. This product is available in Preview to the Security Command Center Enterprise tier.
August 14, 2025
You can use customer-managed encryption keys (CMEKs) to protect data at rest in Security Command Center. This feature is available in General Availability. For more information, see Enable CMEK for Security Command Center.
August 12, 2025
Data Security Posture Management (DSPM) lets you define, deploy, monitor, and audit data security postures for your Google Cloud environment. This product is available in Preview to the Security Command Center Enterprise tier.
August 07, 2025
The following Container Threat Detection detectors have been released to General Availability:
Execution: Possible Arbitrary Command Execution through CUPS (CVE-2024-47177)Execution: Socat Reverse Shell DetectedPrivilege Escalation: Abuse of Sudo For Privilege Escalation (CVE-2019-14287)Privilege Escalation: Polkit Local Privilege Escalation Vulnerability (CVE-2021-4034)Privilege Escalation: Sudo Potential Privilege Escalation (CVE-2021-3156)
Risk reports generated and downloaded from Security Command Center include a system attack exposure page that shows the organization's exposure risk over time and lists the projects and resources that have the highest risk.
August 04, 2025
Model Armor supports the asia-southeast1 location. For information
about supported locations, see
Locations for the Model Armor API.
August 01, 2025
Compliance Manager helps ensure that your Google Cloud infrastructure, workloads, and data meet the security and regulatory requirements of your organization. This product is available in Preview to the Security Command Center Enterprise tier.
July 29, 2025
Model Armor and Gemini Enterprise Agent Platform integration
Model Armor integrates with Gemini Enterprise Agent Platform, providing a default security configuration for all new prediction endpoints. This feature is in Preview. For more information, see Integration with Gemini Enterprise Agent Platform.
You can send a bulk export of Security Command Center findings to a BigQuery dataset. This feature is available in Preview. For more information, see Bulk export findings to BigQuery.
You can use Terraform to manage Model Armor floor settings and templates. This helps reduce manual overhead with Model Armor deployments. For more information, see Terraform resources for Security Command Center.
July 28, 2025
Model Armor filter updates
- The prompt injection and jailbreak detection filter now supports 10,000 tokens.
- For the Sensitive Data Protection filter,
SKIP_DETECTIONis returned if the prompt or response exceeds the token limit. - For all other filters, if the prompt or response exceeds the token limit,
MATCH_FOUNDis returned if malicious content is found, andSKIP_DETECTIONis returned if no malicious content is found.
July 25, 2025
Cloud Infrastructure Entitlement Management (CIEM) has launched support for log ingestion from Microsoft Azure management groups. This capability lets users set up log ingestion and then consume findings at an Azure management group level, rather than at the subscription level. For more information, see Configure Microsoft Azure log ingestion for management groups. This capability is available in Preview.
A new risk scoring algorithm is launched. As a result, you might see slight changes in attack exposure scores for resources and findings. The new algorithm better reflects attacker behavior and gives a fairer representation of the relative risk level of your organization. We will monitor the results of this change and might perform further adjustments, if necessary.
July 24, 2025
For the Enterprise service tier, Security Command Center offers data residency support in the European Union, Saudi Arabia, and United States. This feature is in General Availability.
July 22, 2025
The Setup guide in Security Command Center Enterprise, used to monitor the activation progress and configure services, is now in General Availability.
The Impair Defenses: Two Step Verification Disabled finding type of
Event Threat Detection was renamed to Persistence: Two Step Verification Disabled. For a
complete list of Event Threat Detection finding types, see
Event Threat Detection overview.
July 21, 2025
The Aggregations panel on the Findings page in Security Command Center Enterprise has been enhanced and is now called Quick Filters. For information about filtering results on the Findings page, see Review and manage findings.
July 17, 2025
The following Container Threat Detection detectors for file monitoring are in Preview:
Collection: Pam.d ModificationCredential Access: Access Sensitive Files on NodesDefense Evasion: Disable or modify Linux audit systemDefense Evasion: Root Certificate InstalledExecution: Suspicious Cron ModificationPersistence: Modify ld.so.preload
The following Security Command Center Enterprise pages in the Google Cloud console now fully replace equivalent pages that you accessed previously in the Google Security Operations console.
- Risk Overview
- Issues
- Assets (previously called Resources)
- Findings
Left navigation links in the Google SecOps console open the related Google Cloud console page. See the earlier release announcement about these pages.
July 14, 2025
In the Google Kubernetes Engine (GKE) security posture dashboard, the software vulnerabilities pane is available in Preview, not General Availability.
July 11, 2025
Notebook Security Scanner is a built-in package vulnerability detection service of Security Command Center. This feature is available in Preview to the Security Command Center Premium or Enterprise tier.
You can enable and use Notebook Security Scanner to detect vulnerabilities in
Python packages that are used in Colab Enterprise notebooks (files with
the ipynb filename extension) and resolve those package vulnerability
findings.
July 10, 2025
In the Google Cloud console, the Google Kubernetes Engine (GKE) security posture dashboard shows the top software vulnerabilities that affect your GKE workloads. This feature is in General Availability.
July 01, 2025
Security Command Center now supports the detection of Chokepoints for the following cloud service provider platforms:
- Amazon Web Services (AWS)
- Microsoft Azure
Support for Chokepoints with Microsoft Azure and AWS is in Preview.
June 30, 2025
You can download risk reports as PDFs. Risk reports help you understand the results of the attack path simulations (virtual red teaming) that Security Command Center runs. This feature is in Preview and is available for customers on the Enterprise or Premium service tiers. For more information, see Risk reports overview.
The following Virtual Machine Threat Detection detectors are in General Availability.
Defense Evasion: Unexpected ftrace handlerDefense Evasion: Unexpected interrupt handlerDefense Evasion: Unexpected kernel modulesDefense Evasion: Unexpected kernel read-only data modificationDefense Evasion: Unexpected kprobe handlerDefense Evasion: Unexpected processes in runqueueDefense Evasion: Unexpected system call handler
The Defense Evasion: Unexpected kernel code modification detector of Virtual Machine Threat Detection is shut down. For more information, see Detector shutdowns.
June 27, 2025
The following Event Threat Detection detectors have been released to GA.
Exfiltration: Cloud SQL Data ExfiltrationCredential Access: CloudDB Failed login from Anonymizing Proxy IPInitial Access: CloudDB Successful login from Anonymizing Proxy IP
June 20, 2025
The display name for the following Event Threat Detection rules have changed. Please update any artifacts that use these values, such as finding filters, finding queries, or mute rules.
| Previous display name | New display name |
|---|---|
Defensive Evasion: Static Pod Created
| Defense Evasion: Static Pod Created |
Data Destruction: Deleted Google Cloud Backup and DR Backup |
Impact: Deleted Google Cloud Backup and DR Backup |
Inhibit System Recovery: Deleted Google Cloud Backup and DR host |
Impact: Deleted Google Cloud Backup and DR host |
Inhibit System Recovery: Deleted Google Cloud Backup and DR plan association |
Impact: Deleted Google Cloud Backup and DR plan association |
Inhibit System Recovery: Deleted Google Cloud Backup and DR Vault |
Impact: Deleted Google Cloud Backup and DR Vault |
Inhibit System Recovery: Google Cloud Backup and DR delete policy |
Impact: Google Cloud Backup and DR delete policy |
Inhibit System Recovery: Google Cloud Backup and DR delete profile |
Impact: Google Cloud Backup and DR delete profile |
Inhibit System Recovery: Google Cloud Backup and DR delete storage pool |
Impact: Google Cloud Backup and DR delete storage pool |
Inhibit System Recovery: Google Cloud Backup and DR delete template |
Impact: Google Cloud Backup and DR delete template |
Data Destruction: Google Cloud Backup and DR expire image |
Impact: Google Cloud Backup and DR expire image |
Data Destruction: Google Cloud Backup and DR remove appliance |
Impact: Google Cloud Backup and DR remove appliance |
Inhibit System Recovery: Google Cloud Backup and DR remove plan |
Impact: Google Cloud Backup and DR remove plan |
Impair Defenses: Strong Authentication Disabled |
Persistence: Strong Authentication Disabled |
Credential Access: External Member Added To Privileged Group |
Privilege Escalation: External Member Added To Privileged Group |
Persistence: Impersonation Role Granted For Dormant Service Account |
Privilege Escalation: Impersonation Role Granted For Dormant Service Account |
Credential Access: Privileged Group Opened To Public |
Privilege Escalation: Privileged Group Opened To Public |
Credential Access: Sensitive Role Granted To Hybrid Group |
Privilege Escalation: Sensitive Role Granted To Hybrid Group |
Risk Engine includes the aiplatform.googleapis.com/Model resource type in the default high-value resource set. For more information, see the list of default resource types.
June 19, 2025
CVEs with no known exploitation activity are not considered in attack path simulations
Vulnerability findings in Security Command Center are enriched by Mandiant Threat Intelligence. A CVE with wide exploitation activity is more likely to be used in an attack path compared to a CVE with only anticipated exploitation activity. Vulnerabilities with no known exploitation activity are not considered in attack path simulations. For more information, see Incorporation of CVE data.
The prompt injection and jailbreak detection filter in Model Armor flags more threats across various attack vectors, and offers an improved detection rate for high-confidence malicious prompts. This filter is available in us-east1.
June 18, 2025
The Set security marks option in the new Security Command Center Enterprise Findings and Assets pages is temporarily unavailable. You can opt-out of the new Security Command Center Enterprise experience to manage security marks using the Cloud console. Or, you can manage security marks using the Security Command Center API.
June 13, 2025
The following Event Threat Detection detectors for Vertex AI have been released to Preview:
Persistence: New Geography for AI ServicePrivilege Escalation: Anomalous Multistep Service Account Delegation for AI Admin ActivityPrivilege Escalation: Anomalous Multistep Service Account Delegation for AI Data AccessPrivilege Escalation: Anomalous Service Account Impersonator for AI Admin ActivityPrivilege Escalation: Anomalous Service Account Impersonator for AI Data AccessPrivilege Escalation: Anomalous Impersonation of Service Account for AI Admin ActivityPersistence: New AI API MethodInitial Access: Dormant Service Account Activity in AI Service
June 08, 2025
Multi-language support for Model Armor filters
The Responsible AI and prompt injection and jailbreak detection filters are tested in English, Spanish, French, Italian, Portuguese, German, Chinese (Mandarin), Japanese, and Korean. These filters can work in other languages, but the quality of results might vary.
For more information, see Languages supported.
Model Armor supports screening text in the following document types for malicious content.
- DOCX, DOCM, DOTX, DOTM documents
- PPTX, PPTM, POTX, POT presentations
- XLSX, XLSM, XLTX, XLTM spreadsheets
June 06, 2025
The Security Risk Overview dashboard for Compute Engine is in General Availability. In addition, it provides a Top CVE findings table that lists the most severe CVEs that affect your Compute Engine instances.
June 05, 2025
Muted findings are no longer considered in the Security Command Center Risk Engine. As a result, they no longer get attack exposure scores.
Vulnerability Assessment for Google Cloud supports scanning on Google Kubernetes Engine (GKE) nodes and containers. This feature has been released to Preview.
June 04, 2025
Security Command Center Premium customers can now access toxic combinations, which are in General Availability, and chokepoints, which are in Preview. These are available at the organization level. For more information, see Toxic combinations and chokepoints overview.
June 03, 2025
The following Container Threat Detection detectors for Google Kubernetes Engine have been released to General Availability:
Credential Access: Find Google Cloud CredentialsCredential Access: GPG Key ReconnaissanceDefense Evasion: Base64 ELF File Command LineDefense Evasion: Base64 Encoded Python Script ExecutedDefense Evasion: Base64 Encoded Shell Script ExecutedExecution: Fileless Execution in /memfd:Execution: Suspicious OpenSSL Shared Object LoadedPrivilege Escalation: Fileless Execution in /dev/shm
May 29, 2025
Domain tagging for toxic combinations and chokepoints has been improved to be more precise. The following filters are available for issues:
- CVE Vulnerabilities
- Identity
- Data
- AI Security
May 28, 2025
Model Armor enhancements
- Model Armor supports multi-regional endpoints. For more information, see Locations for the Model Armor API.
- All Model Armor filters support up to 2,000 tokens.
May 27, 2025
Enhanced data residency support in the European Union and United States is in General Availability.
May 23, 2025
Starting May 26, 2025, the findings retention period for new activations of Security Command Center will change from 13 months to 90 days.
The retention period for findings for existing customers prior to May 26, 2025, remains unchanged.
For more information on retention periods, see Data retention.
May 22, 2025
The Google Kubernetes Engine (GKE) security posture dashboard shows the top threats, but not the top software vulnerabilities, detected by Security Command Center.
In the Google Cloud console, the Google Kubernetes Engine (GKE) security posture dashboard shows the top threats and software vulnerabilities that affect your GKE workloads. This feature is in General Availability.
May 15, 2025
The GA release of enhanced data residency support in the European Union and United States is temporarily delayed.
When you enable Security Command Center for the first time in an organization, and you enable data residency in the European Union or United States, data residency controls are enforced at rest, in use, and in transit. This feature is in General Availability.
For details, see Planning for data residency and Security Command Center regional endpoints.
Risk Engine supports the Artifact Registry service. This support lets Risk Engine consider images that are hosted in Artifact Registry when calculating attack paths. For more information, see Resources that receive attack exposure scores.
To support this change, Risk Engine includes the artifactregistry.googleapis.com/Repository resource type in the default high-value resource set. For more information, see the list of default resource types.
May 09, 2025
A Security Risk Overview dashboard for Compute Engine is available in the Google Cloud console. The dashboard, available in Preview, shows the top Security Command Center findings that affect your Compute Engine resources.
May 08, 2025
Security Command Center Enterprise uses predefined security graph rules to identify issues. This feature is in Preview.
For more information, see Predefined security graph rules.
The following Security Command Center Enterprise pages that you previously accessed through the Google Security Operations console are now under Security Command Center in the Google Cloud console:
- Risk Overview
- Issues
- Assets (previously called resources)
- Findings
The Security Command Center Enterprise left navigation also includes links to pages in the Google Security Operations console. For information about this navigation and accessing Google Security Operations pages, see Security Command Center Enterprise console.
May 05, 2025
Web Security Scanner, a built-in service of Security Command Center, released new detectors. The following detectors, which are available with the Enterprise and Premium tiers of Security Command Center, detect misconfigurations in web applications:
HSTS_MISCONFIGURATIONCSP_MISSINGCSP_MISCONFIGURATIONCOOP_MISSINGCLICKJACKING_PROTECTION_MISSING
For more information, see Web Security Scanner misconfiguration findings.
April 29, 2025
Vulnerability Assessment for Google Cloud has been released to Preview. This feature helps to discover critical and high severity software vulnerabilities in your Compute Engine VM instances without installing agents.
Vulnerability Assessment for Google Cloud is on by default. Customers might see an increase in findings due to vulnerabilities in existing virtual machines that weren't previously detected.
April 28, 2025
Security Command Center provides increased support for Microsoft Azure data.
- Security Command Center can collect Microsoft Azure resource and configuration data.
- Risk Engine can discover toxic combinations, attack paths, and issues in your Microsoft Azure environment.
- The Sensitive Data Protection discovery service can profile your Azure Blob Storage data and identify vulnerabilities and misconfigurations that can expose sensitive data.
- Cloud Infrastructure Entitlement Management (CIEM) can analyze and generate misconfiguration findings for Azure role-assignments that grant principals excessive privileges beyond what they use. This capability is available in Preview.
Toxic Combinations for Amazon Web Services (AWS) has been released to General Availability.
April 21, 2025
The Execution: Ingress Nightmare Vulnerability Execution detector of Container Threat Detection is in Preview.
April 18, 2025
The ability of Event Threat Detection to analyze foundational log sources is generally available (GA).
April 17, 2025
The discovery findings that Sensitive Data Protection generates in Security Command Center include recommended next steps. This improvement applies to the finding categories listed in Publish data profiles to Security Command Center.
April 09, 2025
IAM recommender findings are now available with project-level activations of Security Command Center.
Model Armor and GKE integration
Model Armor now enforces security policies uniformly on generative AI inference traffic using a traffic extension. This applies to all application load balancers, including Google Kubernetes Engine Inference Gateway. This feature is in Preview. For more information, see Integration with Google Kubernetes Engine.
April 07, 2025
Cloud Run Threat Detection is available in Preview.
April 02, 2025
When activating Security Command Center Enterprise, you can monitor the provisioning status and progress of initial scans. This capability is in Preview.
March 21, 2025
Model Armor filter update
The prompt injection and jailbreak detection filter in Model Armor is upgraded with increased efficacy and higher model quality scores.
March 20, 2025
The Risk section of the SecOps console has been updated for Security Command Center Enterprise, introducing the following features in Preview:
- Issues are the most important security risks Security Command Center Enterprise has found in your cloud environments. Sourced from Security Command Center's virtual red teaming and security graph, issues give you all the details you need to understand, triage, and remediate a risk. Explore attack path diagrams, attack exposure scores, exposed resources, related findings, and whether multiple issues exist on a primary resource, all from the one place.
- Security graph is a graph database that has cloud resources like assets, identities, apps, and data assigned to its nodes, while the edges of the graph determine the risk relationship between those resources following detection rules. When a relationship risk is discovered, the security graph generates an issue.
- Chokepoints are critical severity issues that focus on common resources or resource groups where multiple attack paths converge. Because of this focus on a common point, resolving a chokepoint can resolve other issues too, like toxic combinations.
The Risk Overview dashboard has also been updated, and a new Issues page added to the Risk section. You can navigate through different security domains in the Risk section using the tabs near the top of the page, such as All risk, Vulnerabilities, and Code.
March 18, 2025
Cloud Infrastructure Entitlement Management (CIEM) has launched support for the following:
- Log ingestion from Amazon SQS queues.
- An alternate
CIEM onlyfeed to reduce costs.
For more information, see Configure AWS log ingestion for CIEM.
This feature is available in General Availability to the Security Command Center Enterprise tier.
March 14, 2025
The Execution: Malicious Python Executed detector in Container Threat Detection released to General Availability.
The following Event Threat Detection rules for Google Kubernetes Engine have been released to General Availability:
GKE_NODEPORT_SERVICE_CREATEDGKE_SENSITIVE_NAMESPACE_WORKLOAD_TRIGGEREDGKE_STATIC_POD_CREATEDGKE_TOR_PROXY_IP_REQUESTGKE_WEBHOOK_CONFIG_CREATEDYL2_GKE_ANONYMOUS_USERS_GRANTED_ACCESSYL2_GKE_APPROVE_CSR_FORBIDDENYL2_GKE_CRB_CLUSTERROLE_AGGREGATION_CONTROLLERYL2_GKE_MANUALLY_DELETED_CSRYL2_GKE_POD_MASQUERADINGYL2_GKE_REVERSE_SHELL_PODYL2_GKE_SERVICE_ACCOUNT_CREATION_SENSITIVE_NAMESPACEYL2_GKE_SUSPICIOUS_CRYPTOMINING_POD
March 13, 2025
Security Command Center has released the Artifact Registry vulnerability assessment detection service, which includes the CONTAINER_IMAGE_VULNERABILITY detector. This detector generates vulnerability findings for container images that are stored and scanned in Artifact Registry. The detector generates findings for vulnerable container images deployed to the following assets:
- Google Kubernetes Engine cluster
- Cloud Run revision
- Cloud Run job
- App Engine
This feature is available in Preview to all Security Command Center tiers.
March 10, 2025
The following detectors have been added to Container Threat Detection.
- Execution: Program Run with Disallowed HTTP Proxy Env
- Exfiltration: Launch Remote File Copy Tools in Container
For more information, see Container Threat Detection detectors.
March 06, 2025
The AWS connector has changed to enable additional use cases and requires the collection of AWS organization and organizational unit (OU) data. This change may require you to take additional action. For details about the change, see the AWS connector changelog.
March 03, 2025
You can use Virtual Machine Threat Detection to scan your Amazon Elastic Compute Cloud (EC2) VM disks for malware. To enable this feature, see Enable VM Threat Detection for AWS. This feature is in Preview.
February 28, 2025
Event Threat Detection, a built-in service of Security Command Center, has released new detectors. The following detectors, which are available in Preview with the Enterprise and Premium tiers of Security Command Center, allow users to manage threats to their Google Cloud Backup and Disaster Recovery assets in Security Command Center:
BACKUP_DELETE_VAULTBACKUP_DELETE_VAULT_BACKUPBACKUP_DELETE_BACKUP_PLAN_ASSOCIATION
In addition, we updated the existing BACKUP_REMOVE_PLAN detector to support findings on Google Cloud Backup and Disaster Recovery assets that are managed in the Google Cloud console. This detector will dynamically generate finding descriptions based on the finding source.
February 25, 2025
You can now use Organization Policy Service custom constraints to provide more granular control over specific fields for some Security Command Center resources. For more information, see Configure custom organization policies. This feature is in General Availability.
February 17, 2025
Findings from Sensitive Data Protection include the INFO_TYPES and RELATED_RESOURCES fields when available. These fields appear in the sourceProperties field of the finding in Security Command Center. The affected finding categories are DATA_RISK, DATA_SENSITIVITY, PUBLIC_SENSITIVE_DATA, SECRETS_IN_STORAGE, and SENSITIVE_DATA_CMEK_DISABLED.
February 14, 2025
The attack path simulations feature can now automatically set the resource value of a Vertex AI dataset based on the sensitivity of the data that the dataset contains. For information about how to enable the automatic assignment of resource values based on data sensitivity, see Create a resource value configuration.
February 13, 2025
Security Command Center now supports integration with Snyk. This feature is in Preview.
February 12, 2025
Cloud Infrastructure Entitlement Management (CIEM) has launched support for the following:
- AWS Managed Microsoft AD and on-premises Active Directory identities. This feature alerts you to potential misconfigurations in your on-premises Active Directory or AWS-managed Active Directory identities.
- Account-level findings in AWS. This lets you set up AWS audit logs for individual AWS accounts—instead of mandating logs across the entire AWS organization—and helps reduce your total cost of operations for CIEM in Security Command Center Enterprise.
February 03, 2025
Protect your AI applications using Model Armor
Model Armor is a Google Cloud service that enables you to apply content safety and content security controls to LLM prompts and responses to mitigate risks such as sensitive data leakage, prompt injection, and offensive content. For more information, see Model Armor overview.
January 24, 2025
Risk Engine, which generates attack exposure scores and attack paths for your high-value resources, now supports the spanner.googleapis.com/Instance resource type.
For more information, see Resource types supported in high-value resource sets.
January 17, 2025
Security Command Center now displays the number of resources scanned for a specific security compliance standard. This information appears as a column in the table on the Compliance detail page of the Google Cloud console for a given compliance standard.
To view the number of resources scanned against a security compliance standard, see Assess compliance against a specific standard.
January 16, 2025
A new Risk Overview page is the default view for Security Command Center Enterprise customers. It serves as your first contact security dashboard for the highest priority risks in your cloud environments. From here you can quickly assess toxic combinations, threats, compliance issues, and high impact vulnerabilities.
The Postures section in the SecOps console has been renamed to Risk, and moved to the top of the navigation for Security Command Center Enterprise customers. You can find the Vulnerabilities and Data Security dashboards here, along with the Findings and Resources pages.
January 13, 2025
A new error code, AWS_ACTIVE_COLLECTOR_ACCOUNTS_NOT_FOUND, is available in the AWS connector in Security Command Center. Additional guidance is available to help troubleshoot the 'AWS_FAILED_TO_ASSUME_DELEGATED_ROLE' error.
December 18, 2024
Install new version of the Security Command Center Enterprise use case
The installation and configuration of a new version of the SCC Enterprise - Cloud Orchestration & Remediation use case in the Security Operations console is required for the toxic combination functionality of Security Command Center Enterprise. The new use case, identified by date December 18, 2024, introduces updates to security posture findings playbooks and other enhancements to support the management of toxic combination findings and cases in the Security Operations console.
For installation instructions, see Update Enterprise use case, December 2024.
Security Health Analytics now supports new resource types for creating custom modules. For a full list of supported resource types, see Supported resource types.
Vulnerability Assessment for AWS now supports scanning container images in Elastic Container Registry (ECR). It can detect operating system misconfigurations and issues with installed packages.
December 17, 2024
For Security Command Center Enterprise customers, the Sensitive Data Protection discovery service is now automatically enabled during the Enterprise activation process. For more information, see Enable sensitive data discovery in the Enterprise tier.
December 16, 2024
Security Command Center can now produce Cloud Infrastructure Entitlement Management (CIEM) misconfiguration findings for federated identities that are connected to your AWS environment through the AWS IAM Identity Center.
Detector for Container Threat Detection released to General Availability
Container Threat Detection, a built-in service available in Security Command Center Premium and Enterprise, has launched three new detectors to General Availability:
- Execution: Container Escape: Detects when a process inside a container tries to break out of its isolation and interact with the host system or other containers.
- Execution: Kubernetes Attack Tool Execution: Detects when a Kubernetes attack tool is run inside a container, indicating a potential attempt to exploit vulnerabilities in the Kubernetes environment.
- Execution: Local Reconnaissance Tool Execution: Detects when a local reconnaissance tool is executed within a container, suggesting that an attacker is gathering information about the container environment, such as network configurations, active processes, or mounted file systems.
For more information, see Container Threat Detection detectors.
December 10, 2024
AI summaries of attack paths are disabled in Security Command Center
Effective December 13, 2024, the preview of Gemini AI-generated summaries of Security Command Center attack paths is discontinued. The summaries are no longer available in the Google Cloud console.
For more information, see Gemini features in Security Command Center.
December 09, 2024
When activating the Security Command Center Enterprise tier, you now have the option to connect Security Command Center to an existing Google Security Operations instance or provision a new instance. For more information, see Activate the Security Command Center Enterprise tier.
November 21, 2024
As of November 13, 2024, Security Command Center can produce Cloud Entitlement Infrastructure Management (CIEM) findings for the following identity and access issues in AWS environments:
- Users, groups, or assumed IAM roles that are inactive and have one or more permissions.
- Overly permissive trust policies that are enforced on an AWS IAM role.
- Identities that can move laterally through impersonation.
The Sensitive Data Protection discovery service is now included in Security Command Center Enterprise. To enable discovery, see Enable sensitive data discovery in the Enterprise tier.
The Sensitive Data Protection discovery service remains available to Security Command Center Premium and Standard customers as a separately priced feature.
November 15, 2024
Manage security postures using the Google Cloud console is generally available.
You can now create, deploy, update, and delete security postures using the Google Cloud console. For more information, see Manage a security posture.
November 14, 2024
The application steps to activate the Security Command Center Enterprise tier have been streamlined. For information, see Activate the Security Command Center Enterprise tier.
The Defense Evasion: Rootkit detector of Virtual Machine Threat Detection is in General Availability. For more information, see Virtual Machine Threat Detection overview.
You can now view the configurations that determine the resource values of your high-value resource set. For more information, see View the configurations that match a high-value resource.
November 11, 2024
As of December 9, 2024, if you activate Security Command Center within an organization for the first time, then you must use only version 2 of the Security Command Center API in that organization. Earlier versions are not supported.
If you activated Security Command Center at the project level prior to December 9, 2024, then any projects you activate in the same organization will support all available versions of the Security Command Center API.
To migrate to the v2 API from an earlier version, see Migrate to v2 of the Security Command Center API.
The Vulnerability management dashboard was enhanced to include information about containers with exploitable vulnerabilities. This feature is in Preview.
Starting October 24, 2024, the IAM Recommender service is enabled by default when activating Security Command Center. You manage the IAM Recommender service under the Security Command Center Settings page > Integrated services tab. For more information, see Add integrated Google Cloud services to Security Command Center.
November 08, 2024
To help you detect potentially malicious anomalies in your network, Event Threat Detection now supports the ability to analyze foundational log sources, which produce Bad IP findings without enabling VPC Flow Logs. This feature is in Preview.
- If you activated Security Command Center Premium or Enterprise in a project or organization before October 18, 2024, then you have access to this feature in that project or organization.
- If you activated Security Command Center Premium or Enterprise at the project level before October 18, 2024, and you activate additional projects in the same organization, then the additional projects will have access to this feature.
- If you activated Security Command Center Premium or Enterprise in a project or organization on or after October 18, 2024, and you want to enable this feature, then contact Google Cloud Customer Care.
November 07, 2024
The v2 Security Command Center API is generally available (GA).
To migrate from an earlier version, see Migrate to v2 of the Security Command Center API.
October 25, 2024
Event Threat Detection's Outgoing DoS finding has been shut down and is no longer available.
October 18, 2024
The VMTD disabled finding category from Virtual Machine Threat Detection is no longer available. For more information about the finding categories that this built-in service provides, see Virtual Machine Threat Detection overview.
October 16, 2024
Toxic combination findings are generally available. This includes the following updates:
- Support for toxic combination findings on AWS resources. This feature is available in Preview.
- Addition of a new Toxic Combination Cases TTR and Trend widget on the Posture overview page of the Google Security Operations console. The widget details the trends for open and closed toxic combination cases for a specific time range.
October 11, 2024
Working with findings and resources in the Security Operations console
The ability to work with findings and resources using the Security Operations console is now in General Availability. This feature is available only to Security Command Center Enterprise customers.
The following capabilities were added since the Preview release of this feature:
- You can export findings to a CSV file.
- Additional query operators in the Add filters menu in the Query editor on the Findings page are now available.
- The autocomplete menu suggests possible values when your write queries in the Query editor. During Preview, the autocomplete menu suggested only filter names and functions.
- You can hide or display panels on the Findings page.
- Your sort and column settings are retained within the current session.
October 09, 2024
Install new version of the Security Command Center Enterprise use case
The installation and configuration of a new version of the SCC Enterprise - Cloud Orchestration & Remediation use case in the Security Operations console is required for the toxic combination functionality of Security Command Center Enterprise. The new use case, identified by date October 9, 2024, introduces a new widget, an updated ingestion logic, and other enhancements to support the management of toxic combination findings and cases in the Security Operations console.
For installation instructions, see Update Enterprise use case, October 2024.
October 08, 2024
Vulnerability management dashboard released to Preview
The new Vulnerability management dashboard lets you investigate CVE vulnerabilities identified in your Google Cloud and AWS environments.
This feature is available in Preview.
October 04, 2024
Manage security postures using the Google Cloud console
You can now create, deploy, update, and delete security postures using the Google Cloud console. This feature is available in Preview.
For more information, see Manage a security posture.
October 03, 2024
GKE Security Posture vulnerability findings now support attack exposure scores
GKE runtime OS vulnerability findings detected by GKE Security Posture in Google Cloud are now scored by attack path simulations. Use these attack exposure scores on vulnerabilities to help secure the resources that are the most valuable to your business and to address the most significant vulnerabilities in your GKE clusters. For more information, see Attack exposure scores.
October 01, 2024
Data residency for Security Command Center is now available in the Kingdom of Saudi Arabia.
September 25, 2024
YARA rule names that appear in Virtual Machine Threat Detection findings will be renamed
On or after October 28, 2024, YARA rule names that appear in Malware: Malicious file on disk (YARA) findings from Virtual Machine Threat Detection will be renamed. This update will resolve naming inconsistencies in the YARA rules. The new naming convention will contain the prefix, designation, type, name, and iteration of the YARA rule. The following are examples of the new names:
Ext_FE_Hunting_Linux_CYCLOPSBLINK_FEBetaM_APT_Controller_REDFLARE_1M_Backdoor_REDSONJA_4M_Cryptomine_XMRIG_1
September 18, 2024
Assign high-value resources based on Sensitive Data Protection insights for Amazon S3 buckets
The attack path simulations feature can now automatically set the resource value of an Amazon S3 bucket based on the sensitivity of the data that the bucket contains.
For information about how to enable the automatic assignment of resource values based on data sensitivity, see Create a resource value configuration.
For information about how to configure Sensitive Data Protection to send data sensitivity classifications to Security Command Center, see Publish data profiles to Security Command Center.
September 11, 2024
Validate updates to integrations in the Security Command Center Enterprise use case
Updates to the threat response playbook blocks and use case flows are available in the SCC Enterprise - Cloud Orchestration & Remediation use case for Security Command Center Enterprise. To get these changes, upgrade the integrations to the latest versions.
For more information, see Validate integration versions in the use case.
September 09, 2024
New configuration options for Vulnerability Assessment for AWS
When configuring Vulnerability Assessment for AWS, you can customize the scan settings by defining the scan interval, specific regions, specific tags, and specific instance IDs. You can also include SC1 or ST1 instances in the scan. For more information, see Enable and use Vulnerability Assessment for AWS.
September 04, 2024
Install new version of the Security Command Center Enterprise use case
The installation and configuration of a new version of the SCC Enterprise - Cloud Orchestration & Remediation use case in the Security Operations console is required for the toxic combination functionality of Security Command Center Enterprise. The new use case, identified by date, September 4, 2024, introduces updated widgets, new playbooks, optimized data synchronization jobs, updated ingestion logic, and other enhancements to support the management of toxic combination findings and cases in the Security Operations console.
For installation instructions, see Update Enterprise use case, September 2024.
August 29, 2024
Dynamic mute rules are generally available
Security Command Center now supports dynamic mute rules, which allow you to mute future and existing findings temporarily until a specified date or indefinitely until a finding no longer matches the configuration. We are adding these rules as an alternative to the original static mute rules that only mute future findings indefinitely.
We recommend using dynamic mute rules exclusively in your mute rule configurations. For instructions on how to migrate your existing mute rules to dynamic mute rules, see Migrate from static to dynamic mute rules.
For a comparison of static and dynamic mute rules, see Types of mute rules.
August 27, 2024
Documentation is available for the Security Posture REST API.
August 15, 2024
Install new version of the Security Command Center Enterprise use case
The installation and configuration of a new version of the SCC Enterprise - Cloud Orchestration & Remediation use case in the Security Operations console is required for the toxic combination functionality of Security Command Center Enterprise. The new use case, identified by the date August 15, 2024, provides updates to the security operations features of the Enterprise tier of Security Command Center.
For installation instructions, see Update Enterprise use case, August 2024.
August 12, 2024
EC2 Vulnerability Assessment findings now support attack exposure scores
Software vulnerability findings detected by EC2 Vulnerability Assessment for Amazon Web Services are now scored with attack path simulations. Use these attack exposure scores on vulnerabilities to proactively secure the resources that are the most valuable to your business. For more information, see Attack exposure scores.
Cloud Infrastructure Entitlement Management (CIEM) is generally available
CIEM helps you adhere to the principle of least privilege by providing a comprehensive look at the security of your identity and access configuration. It provides insight into details such as what permissions are associated with a given identity, what roles are not optimal (highly permissive), and what steps you can take to remediate potential misconfigurations.
For more information about CIEM, see Overview of Cloud Infrastructure Entitlement Management.
July 29, 2024
Preview of curated detections for Microsoft Azure data
New curated detections in the Cloud Threats category that identify suspicious patterns in Microsoft Azure data are currently available in Preview.
For more information, see curated detections for Microsoft Azure data in the Security Command Center documentation.
Assign high-value resources based on Sensitive Data Protection insights for Cloud Storage
The attack path simulations feature can now automatically set the resource value of a Cloud Storage resource based on the sensitivity of the data that the bucket contains.
For information about how to enable the automatic assignment of resource values based on data sensitivity, see Create a resource value configuration.
For information about how to configure Sensitive Data Protection to send data sensitivity classifications to Security Command Center, see Publish data profiles to Security Command Center.
Detector for Container Threat Detection released to General Availability
Container Threat Detection, a built-in service available in Security Command Center Premium and Enterprise, has launched a new detector, Unexpected Child Shell, in General Availability.
The detector monitors all process executions and generates a finding if a process that does not normally invoke shells spawns a shell process.
For more information, see Container Threat Detection detectors.
July 01, 2024
Working with findings and resources in the Security Operations console
Security Command Center Enterprise customers can now work with findings and affected resources using the Security Operations console. For example, you can do the following in the Security Operations console:
- Filter for findings and resources based on different attributes.
- Fine-tune your queries.
- View the details of specific findings and resources.
- View high-value resources and their attack exposure scores.
- View the changes to a resource.
This feature is available in Preview.
For more information, see the following:
June 25, 2024
Introducing the Security Command Center Risk Engine
Security Command Center introduces Risk Engine as the name of the functionality that provides attack path simulations, attack exposure scores, attack path visualizations, and toxic combination findings.
For more information, see Assess risk with Risk Engine.
Toxic combination findings release to Preview
In the Enterprise tier of Security Command Center, the Risk Engine generates a finding when it detects a toxic combination during attack path simulations. A toxic combination is a group of security issues that, when they occur together in a particular pattern, create a path to one or more of your high-value resources.
The toxic combinations features introduces a new finding class, Toxic combination, and adds new fields in the Finding object to hold information about toxic combinations.
For more information, see Overview of toxic combinations.
UPDATE: The Preview release of the toxic combination feature is being rolled out to customers in stages. You might not receive toxic combination findings or see the new features in the Security Operations console for up to two weeks.
The release note for the toxic combination feature published on June 25, 2024 was updated to explain the staged release of the feature.
Install new version of the Security Command Center Enterprise use case
The installation and configuration of a new version of the SCC Enterprise - Cloud Orchestration & Remediation use case in the Security Operations console is required for the toxic combination functionality of Security Command Center Enterprise. The new use case, identified by date, June 25, 2024, introduces new widgets, new playbooks, and other enhancements to support the management of toxic combination findings and cases in the Security Operations console.
For installation instructions, see Update Enterprise use case, June 2024.
June 17, 2024
The Security Command Center Assets page will require new permissions
On or after July 11, 2024, a new Identity and Access Management (IAM) permission will be required to view the Assets page in Google Cloud console. If you use custom roles to control access to Google Cloud resources, you will need to add this new permission to your custom roles before that date to continue using the Assets page.
For more information, see Assets page.
June 13, 2024
Preview of Cloud Infrastructure Entitlement Management capabilities
Cloud Infrastructure Entitlement Management (CIEM) for Amazon Web Services (AWS) and other identity providers on Google Cloud, such as Entra ID (Azure AD) and Okta, is now in preview.
CIEM helps you adhere to the principle of least privilege by providing a comprehensive look at the security of your identity and access configuration. CIEM provides insight into details such as what permissions are associated with a given identity, what roles are not optimal (highly permissive), and what steps you can take to remediate potential misconfigurations.
For more information, see Overview of Cloud Infrastructure Entitlement Management.
June 03, 2024
Vulnerability Assessment for AWS service released to General Availability
The Vulnerability Assessment for AWS service, a built-in service of the Enterprise tier of Security Command Center, is released to General Availability.
The Vulnerability Assessment for AWS service creates a disk snapshot to assess Amazon Web Service EC2 machines for software vulnerabilities.
For more information, see Overview of Vulnerability Assessment for AWS.
May 31, 2024
VM Threat Detection's malware detector released to General Availability
Virtual Machine Threat Detection, a built-in service of Security Command Center, launched the Malware: Malicious file on disk (YARA) detector to GA. This detector generates a finding if an executable file in a virtual machine matches known malware signatures.
May 30, 2024
Mute state of findings display in alerts, cases, and tickets
The mute state of a finding is now reflected in its corresponding alert, case, and tickets in the Security Operations console of Security Command Center Enterprise. Previously, muted findings displayed only their Active status. For more information, see Finding status in Cases overview.
Finding severities update in cases automatically
In the Security Operations console of Security Command Center Enterprise, the severity of each finding is displayed in its corresponding case in the Finding summary widget. If the severity of a finding changes, the case is updated automatically. For more information, see Finding severity versus case priority.
May 22, 2024
New curated detections for existing AWS rule sets
Enhanced the existing curated detections for AWS rule sets in the Cloud Threats category to add 40 new detections. These new rules, added to existing rule sets, expand the coverage and are designed to identify tactics and techniques commonly employed by malicious actors that use popular open source offensive security tools against AWS resources.
For more information, see curated detections for AWS rule sets in the Google Security Operations documentation.
May 14, 2024
Rapid Vulnerability Detection preview shuts down on July 14, 2024
The Preview release of the Rapid Vulnerability Detection service is discontinued and the service will be shut down on July 14, 2024.
No action is required.
On July 14, 2024, the status of any findings produced by the Rapid Vulnerability Detection service will be automatically set to Inactive and will be retained for a period defined by the Security Command Center data retention policy.
May 06, 2024
Assign high-value resources based on Sensitive Data Protection insights for Cloud SQL
The attack path simulations feature can now automatically set the resource value of a Cloud SQL resource based on the sensitivity of the data that the instance contains.
For information about how to enable the automatic assignment of resource values based on data sensitivity, see Create a resource value configuration.
For information about how to configure Sensitive Data Protection to send data sensitivity classifications to Security Command Center, see Publish data profiles to Security Command Center.
May 01, 2024
AI summaries of finding are disabled in Security Command Center
Effective May 1, 2024, the preview of Gemini AI-generated summaries of Security Command Center findings is discontinued. The summaries are no longer available in the Google Cloud console.
For more information, see Gemini features in Security Command Center.
April 15, 2024
Security Health Analytics use of security marks for asset allowlists deprecated
Starting April 15, 2025, Security Health Analytics will no longer use security marks to allowlist assets for Security Health Analytics detectors.
After that date, you can still apply security marks to assets, but they will no longer affect the way that Security Health Analytics processes assets.
For more information about security marks for assets, see Add assets to allowlists.
Historical snapshots to be disabled in Security Command Center API
Starting July 15, 2024, Security Command Center will discontinue historical snapshot capabilities in the Security Command Center API, which were used to query for findings at a particular point in time. Specifically, readTime and compareDuration will be removed from list and group API calls for findings. Also, start_time will be removed from SetFindingState, SetFindingWorkflowState and UpdateSecurityMarks.
For more information about the Security Command Center API, see Overview.
Data retention period to be reduced for Standard tier findings
For existing Standard tier users, on July 14, 2024, the data retention period for findings will be reduced from 13 months to 35 days. For new users activating the Standard tier after April 15, 2024, the data retention period for findings is 35 days.
The retention period for findings in the Premium tier and Enterprise tier remains 13 months.
For more information, see Data retention.
April 02, 2024
Enterprise tier released to General Availability
The Enterprise tier, which transforms Security Command Center into a cloud-native application protection platform (CNAPP) that combines cloud security and enterprise security operations with multicloud support, is released to General Availability.
The following features and capabilities of the Enterprise tier are new to Security Command Center:
- Multicloud support: You can now connect Security Command Center to Amazon Web Services for the following capabilities:
- Detect threats and vulnerabilities
- Assess the risk exposure of your high-value AWS resources
- Assess compliance with security standards
- A new Security Operations console for global security operations tasks
- SIEM and SOAR capabilities for security operations
- Security investigation and event management (SIEM) capabilities:
- Ingest and normalize logs from Google Cloud, AWS, Security Command Center findings, and resource metadata from multiple sources
- Detect the most important cloud threats with curated threat detection
- Search across consolidated SIEM data
- Security operations and response (SOAR) capabilities:
- Manage detections, investigations, and responses with cases
- Automate response workflows with playbooks
- Focus on posture and threat findings with dedicated views in the Security Operations console
- Integrate with IT service management products, such as Jira and ServiceNow, for posture management
- Search across consolidated SOAR data
- Security investigation and event management (SIEM) capabilities:
- The following attack exposure scoring features are in General Availability:
- Vulnerability and misconfiguration detections
- Security Health Analytics includes the following enhancements:
- New misconfiguration detectors for AWS resources
- Detectors are mapped to new security standards
- You can now manage the remediation of critical and high severity vulnerability and misconfiguration findings using cases that are automatically opened for you.
- Security Health Analytics includes the following enhancements:
- Threat detection and investigation
- Detect threats in your AWS deployments
- Investigate and respond to incidents with SIEM-like capabilities across 90 days of cloud logs
- Manage the investigation of and response to threats by using cases
- Define response workflows and automated actions in response to threats by using playbooks
- Mandiant Attack Surface Management integration
- Mandiant Attack Surface Management scans your external attack surfaces to identify vulnerability and misconfiguration findings
- Sensitive Data Protection integration
- The Risk overview page of Security Command Center in the Google Cloud console now shows data security findings from the Sensitive Data Protection discovery service
- Findings from Sensitive Data Protection that indicate the sensitivity and data risk levels of your data can inform the automated assignment of resource values for the attack path simulation feature
- Gemini artificial intelligence features
- Natural language search for threat findings
- AI investigation widget for cases
- Compliance, security standards
- Support for AWS security standards
- Validate infrastructure as code (IaC) against organization policies and Security Health Analytics detectors. The IaC validation feature lets you determine whether your new or modified resource definitions violate the existing policies that are applied to your Google Cloud resources.
- Integration with Assured Open Source Software The paid tier of Assured OSS is included with your Enterprise tier license, so that you can enhance your code security by using the open source software packages that Google uses for its own developer workflows.
With the Enterprise tier, severity levels of certain findings are now variable
In the Enterprise tier of Security Command Center, the default severity level of an active vulnerability or misconfiguration finding can change if the finding's attack exposure score changes. If you are a user of the Premium tier and you upgrade to the Enterprise tier, check any automated or manual procedures that rely on the value of the severity property to ensure that they can support a variable severity value.
For more information, see Severities that vary based on attack exposure score.
April 01, 2024
The following Security Health Analytics misconfiguration detectors have changed to check for overly restrictive flag values that might prevent error messages from being written to the logs:
SQL_LOG_ERROR_VERBOSITYSQL_LOG_MIN_ERROR_STATEMENT_SEVERITY
For the flag values that the detectors check for, see:
March 26, 2024
GKE security posture recommendations released to Preview
Recommendations from GKE security posture are now available as findings in all tiers of Security Command Center as a Preview release.
GKE security posture publishes workload configuration auditing results as Misconfiguration class findings and vulnerability assessment results as Vulnerability class findings in Security Command Center.
For more information, see GKE security posture dashboard.
March 21, 2024
Security Command Center detectors are now mapped to the following additional compliance frameworks:
- CIS Critical Security Controls v8
- Cloud Controls Matrix v 4
- HIPAA
- ISO 27001 (2022)
- NIST 800-53 (rev 5)
- NIST Cybersecurity Framework (v 1.0)
- PCI-DSS 4.0
- SOC 2 (2017)
March 20, 2024
New misconfiguration detectors for AlloyDB for PostgreSQL clusters released to General Availability.
Security Health Analytics, a built-in service of Security Command Center, released new detectors to General Availability. The following detectors, which are available only with the Premium tier of Security Command Center, detect misconfigurations in AlloyDB for PostgreSQL clusters and instances:
- ALLOYDB_AUTO_BACKUP_DISABLED: Automated backups are not enabled in AlloyDB for PostgreSQL cluster.
- ALLOYDB_LOG_ERROR_VERBOSITY: Instance database flag
log_error_verbosityfor AlloyDB for PostgreSQL instance is not set todefaultor another less restrictive value. - ALLOYDB_LOG_MIN_ERROR_STATEMENT_SEVERITY: Instance database flag
log_min_error_statementfor AlloyDB for PostgreSQL instance is not set to ERROR or lower. - ALLOYDB_LOG_MIN_MESSAGES: Instance database flag
log_min_messagesfor AlloyDB for PostgreSQL instance is not set to at minimumwarning.
For more information, see SQL vulnerability findings.
February 29, 2024
Security Command Center API v2 released to Preview
The Security Command Center API v2, which enables data residency control and includes the /locations/LOCATION field in resource names, is released to Preview.
For more information, see the REST reference Security Command Center API Overview.
Data residency for Security Command Center release to Preview
Security Command Center data residency control is released to Preview. Security Command Center supports the following data locations:
- European Union (
eu) - United States (
us) - Global (
global)
For more information, see Data residency.
February 28, 2024
Virtual Machine Threat Detection, a built-in service of Security Command Center Premium, has launched a new detector, Defense Evasion: Rootkit, in Preview.
The detector monitors virtual machines and generates a finding if a combination of signals matching a known kernel-mode rootkit is present.
For more information, see Virtual Machine Threat Detection overview.
February 20, 2024
Manual control of finding state deprecated for vulnerabilities and misconfigurations
Starting October 21, 2024, you will no longer be able to manually update the state of vulnerability or misconfiguration findings that are issued by Security Health Analytics or VM Manager. Security Command Center will return an error message on manual attempts to change the values of the state. Security Command Center will also begin preventing the manual creation of findings under the exact same name as a source that is automatically managed by Security Command Center in order to prevent the creation of findings that can never be resolved.
For more information, see Finding states.
Pane on Overview page that supports postures for Vertex AI released to Preview
A pane on the Overview page lets you monitor for vulnerabilities that were found by the Security Health Analytics custom modules that apply to Vertex AI, and lets you view any drift from the Vertex AI organization policies that are defined in a posture.
For more information, see Monitor posture drift.
February 14, 2024
Support for VPC Service Controls released to General Availability
You can now protect Security Command Center using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.
February 11, 2024
Exports of compliance reports will require new permissions
On or after March 15, 2024, a new Identity and Access Management (IAM) permission will be required to export a compliance report from the Google Cloud console. If you use custom roles to control access to Google Cloud resources, you will need to add this new permission to your custom roles before that date to continue exporting compliance reports.
For more information, see Export a compliance report.
February 06, 2024
High-value resources now include attack exposure scores
The calculation of attack exposure scores for high-value resources by the Security Command Center Attack Path Simulations feature is released to Preview. Use attack exposure scores on resources to proactively secure the resources that are the most valuable to your business. For more information, see Attack exposure scores.
Mandiant analyst CVE ratings added to vulnerability findings
The addition of CVE information, including ratings of the vulnerability by Mandiant Threat Intelligence analysts, to the details of Security Command Center vulnerability findings is released to Preview. You can now prioritize vulnerabilities based on the exploitability and impact ratings from Mandiant. For more information, see Prioritize vulnerability findings to reduce risk.
New security posture service released to General Availability
The new security posture service is released to General Availability. This service lets you create and deploy postures so that you can define the policies for your Google Cloud organization and monitor for drift.
For more information, see Security posture overview.
Attack exposure scores informed by Mandiant Threat Intelligence
The inclusion of CVE exploitability ratings in the calculation of attack exposure scores for vulnerability findings is released to Preview. The ratings, which are provided by Mandiant Threat Intelligence analysts, enables Security Command Center attack path simulations to provide more accurate scores for prioritizing vulnerability findings. For more information, see Incorporation of CVE data.
Prioritize high-value resources automatically by data sensitivity
The optional integration of the Sensitive Data Protection discovery feature with the Security Command Center attack path simulation feature is released to Preview. If you use Sensitive Data Protection discovery, you can choose to have the priority value of supported high-value resources set automatically based on whether they contain medium-sensitivity or high-sensitivity data. For more information, see Set resource priority values automatically by data sensitivity.
Improvements to compliance standards support now available
Improvements to the Security Command Center Compliance page in the Google Cloud console are released to General Availability. Your state of compliance with all supported standards is now presented more clearly and a new Compliance details page makes it easier to see failing controls. For more information, see Assess and report compliance.
January 31, 2024
Virtual Machine Threat Detection, a built-in service of Security Command Center, launched the Malware: Malicious file on disk (YARA) detector to Preview. This detector generates a finding if an executable file in a virtual machine matches known malware signatures.
January 26, 2024
Security Command Center Management API released to General Availability
The Security Command Center Management API, which provides API support for managing settings and custom modules, is released to General Availability.
For more information, see Security Center Management API.
January 24, 2024
New Container Threat Detection service account deferred
The new service account for Container Threat Detection that was included with new activations of Security Command Center after December 7, 2023 was temporarily removed from new activations on Dec 19, 2023 due to issues with older GKE clusters.
If you activated Security Command Center during this time period, all issues have been resolved and there is no impact to your experience.
New activations of Security Command Center will use the service account that was used prior to December 7, 2023 with the Container Threat Detection service until further notice.
For more information about the new service account, see Required IAM permissions.
January 10, 2024
Issue that caused finding severities to change unexpectedly is resolved
Between December 11, 2023 and January 10, 2024, an issue might have changed the severities of some findings unexpectedly. As of today, the issue has been fixed for all customers. Any finding severities that were changed have been returned to their original state.
December 15, 2023
The custom modules feature for Event Threat Detection is now in General Availability. This feature lets you create custom Event Threat Detection detectors that meet the unique needs of your organization.
In addition, the Unexpected Cloud API Call module type is now available. This module type lets you create a custom module that detects when a specified principal calls a specified method against a specified resource.
For more information, see Overview of custom modules for Event Threat Detection.
December 13, 2023
Custom roles will require new permissions for custom modules
On or after January 22, 2024, new Identity and Access Management (IAM) permissions will be required to work with custom modules for both Event Threat Detection and Security Health Analytics. If you use custom roles to control access to Google Cloud resources, you will need to add these new permissions to your custom roles before that date to continue working with custom modules.
For more information, see the following:
December 11, 2023
New Container Threat Detection service account with new activations
For activations of Security Command Center after December 7, 2023, Container Threat Detection uses a new service account for Identity and Access Management (IAM) permissions.
During the activation process, new users grant permissions to two service accounts: one for Security Command Center and one for Container Threat Detection. The new service account speeds the first-time enablement of Container Threat Detection.
If you activated Security Command Center prior to December 7, 2023, Container Threat Detection remains unchanged and continues to use its original service account.
For more information, see Service agent roles.
December 07, 2023
New goal-based query presets for identity and access misconfigurations
New goal-based query presets on the Security Command Center Vulnerabilities page are released to Preview.
The query presets support cloud infrastructure entitlement management (CIEM) by filtering vulnerability finding categories to those that are related to principal accounts that are misconfigured or that have excessive permissions to Google Cloud resources.
For more information, see Goal-based query presets.
December 04, 2023
Policy Controller integration released to General Availability
The integration of Policy Controller for Kubernetes clusters with Security Command Center is released to General Availability. Violation alerts from Policy Controller appear in Security Command Center as misconfiguration findings.
For more information, see Policy Controller.
November 10, 2023
Policy Controller integration now in Preview
The integration of Policy Controller for Kubernetes clusters with Security Command Center is released to Preview. Violation alerts from Policy Controller now appear in Security Command Center as misconfiguration findings.
For more information, see Policy Controller.
November 08, 2023
Support for VPC Service Controls released to Preview
You can now protect Security Command Center using VPC Service Controls perimeters. For more information, see VPC Service Controls supported products.
October 19, 2023
Backup and DR Service threat detectors available in Security Command Center Premium
Event Threat Detection, a built-in service of Security Command Center, released new rules for the Google Cloud Backup and DR service to Preview. Security Command Center can now detect the following:
- Backup and DR actions that inhibit system recovery
- Backup and DR actions that result in data destruction
For more information, see:
- Backup and DR in Event Threat Detection rules
- What is Backup and DR Service?
October 18, 2023
Container Threat Detection, a built-in service of Security Command Center Premium, has launched a new detector, Unexpected Child Shell, in Preview.
The detector monitors all process executions and generates a finding if a process that does not normally invoke shells spawns a shell process.
For more information, see Container Threat Detection detectors.
October 09, 2023
Cloud IDS threat detections available in Security Command Center
Threats that are detected by Cloud IDS, a Google Cloud intrusion detection service, are now included in the findings that are issued by the Event Threat Detection service of Security Command Center. This feature is available in Preview.
For more information, see:
- Cloud IDS in Event Threat Detection rules
- Cloud IDS overview
September 29, 2023
containsOnly() function released to General Availability.
You can now use the containsOnly() function to query findings with an array-type attribute or subfield that only contains values that match the specified filter, and no other values.
For more information, see The containsOnly function.
September 20, 2023
Attack path simulations support additional resources
The attack path simulation feature that generates attack exposure scores and attack paths for your high-value resources now supports the following additional Google Cloud resources:
aiplatform.googleapis.com/Datasetaiplatform.googleapis.com/Featurestoreaiplatform.googleapis.com/MetadataStoreaiplatform.googleapis.com/Modelaiplatform.googleapis.com/TrainingPipelinecontainer.googleapis.com/Cluster
For more information, see Resource types supported in high-value resource sets.
September 19, 2023
Vulnerabilities per resource type graphic released to General Availability
The Security Command Center Overview page in the Cloud console now shows a Vulnerabilities per resource type graphic, which replaces the Active vulnerabilities over time by severity graphic. The Vulnerabilities per resource type graphic shows the resources in your organization (for example, Cloud Storage buckets, Compute Engine instances, and firewalls), how many active vulnerabilities exist for each resource, and the severity of those vulnerabilities.
September 15, 2023
Event Threat Detection, a built-in service of Security Command Center, released a new rule, Initial Access: Leaked Service Account Key Used, to General Availability.
For more information, see Event Threat Detection rules.
September 11, 2023
Security Command Center now supports CIS Google Cloud Computing Foundations Benchmark v2.0.0.
The support for v2.0.0 includes the following new vulnerability detector:
Load balancer logging disabled
For more information, see the following:
August 21, 2023
inIpRange() function released to General Availability
You can now specify a range of IP addresses by using the inIpRange() function in query statements to filter findings that contain IPv4 or IPv6 addresses within the specified range.
For more information, see The inIpRange function.
August 16, 2023
New assets experience released to General Availability
The Security Command Center Assets page in the Cloud console is now powered by Cloud Asset Inventory. The new Assets page provides expanded asset visibility and includes a new asset query feature.
This release is part of the planned deprecation of the Security Command Center Assets API scheduled for on or after June 20, 2024.
For more information, see Assets page.
August 03, 2023
AI-generated summaries of the simulated attack paths for Security Command Center findings are released to Preview. When you view the attack path for a finding, you can now read explanations that are generated dynamically by artificial intelligence (AI).
For more information, see AI-generated summaries.
Attack exposure scores and attack paths released to General Availability
The attack path simulation feature that generates attack exposure scores and attack paths for findings that expose your high-value resources is now released to General Availability.
For information about the feature, see Attack exposure scores and attack paths.
July 31, 2023
The Security Health Analytics detector NETWORK_POLICY_DISABLED now recognizes network policies that are implemented by using GKE Dataplane V2.
For more information, see the following:
July 26, 2023
The custom modules feature for Event Threat Detection is now in Preview. Custom modules allow you to define custom detectors for Event Threat Detection.
For more information, see Overview of custom modules for Event Threat Detection.
July 14, 2023
AI-generated summaries of Security Command Center findings are released to Preview. When you view finding details, you can now read explanations that are generated dynamically by artificial intelligence (AI).
For more information, see AI-generated summaries.
July 13, 2023
Recommendations from the IAM recommender are now available as findings in Security Command Center in a Preview release.
The following IAM recommender recommendations are now published as Vulnerability class findings in Security Command Center:
- IAM role has excessive permissions
- Service agent role replaced with basic role
- Service agent granted basic role
- Unused IAM role
For more information, see Security sources > IAM recommender.
June 28, 2023
As of June 20, 2023, Security Command Center Asset API endpoints and dependent functionality are deprecated and will be removed from the product for all users on or after June 20, 2024. Use Cloud Asset Inventory and its API instead.
After June 20, 2023, the asset functionality is not included with new activations of Security Command Center.
If you activated Security Command Center before June 20, 2023, but have not used the asset functionality in the 90 days prior to June 20, 2023, the asset functionality is removed.
If you activated Security Command Center before June 20, 2023, and have used the asset functionality in the 90 days prior to June 20, 2023, the asset functionality remains available for you until June 20, 2024 or later.
The deprecation applies to the following Security Command Center interfaces:
- Security Command Center Asset API endpoints
- Except for
gcloud scc assets update-marks, which is not deprecated, theassetssubgroup of thegcloud sccCLI command - The Assets page and related functionality in the Google Cloud Console
June 22, 2023
Only the Security Center Service Agent (roles/securitycenter.serviceAgent) role is required by the Security Command Center service account. Previously, the service account also required the roles/serviceusage.serviceUsageAdmin and roles/cloudfunctions.serviceAgent roles to work properly.
June 21, 2023
Event Threat Detection, a built-in service of Security Command Center, released the following new rules to General Availability.
Initial Access: Dormant Service Account ActionPrivilege Escalation: Dormant Service Account Granted Sensitive RolePersistence: Impersonation Role Granted For Dormant Service AccountInitial Access: Dormant Service Account Key Created
For more information, see Event Threat Detection rules.