אינדקס של ממצאי פגיעויות

במסמך הזה מוסבר איך למצוא ממצאים של נקודות חולשה שזמינים ב-Security Command Center. כדי לקבל פרטים נוספים, אפשר להשתמש במסנן כדי לחפש קטגוריות של ממצאי פגיעות, משאבי ענן בפיקוח או שירותי זיהוי.

שם קטגוריית משאב שירות זיהוי
API key APIs unrestricted API Security Health Analytics
API key apps unrestricted API Security Health Analytics
API key exists API Security Health Analytics
API key not rotated API Security Health Analytics
Cloud Asset API disabled מאגר משאבי ענן Security Health Analytics
Public Compute image Compute Engine Security Health Analytics
Confidential Computing disabled Compute Engine Security Health Analytics
Compute project wide SSH keys allowed Compute Engine Security Health Analytics
Compute Secure Boot disabled Compute Engine Security Health Analytics
Compute serial ports enabled Compute Engine Security Health Analytics
Default service account used Compute Engine Security Health Analytics
Disk CMEK disabled Compute Engine Security Health Analytics
Disk CSEK disabled Compute Engine Security Health Analytics
Full API access Compute Engine Security Health Analytics
HTTP load balancer Compute Engine Security Health Analytics
Instance OS Login disabled Compute Engine Security Health Analytics
IP forwarding enabled Compute Engine Security Health Analytics
OS login disabled Compute Engine Security Health Analytics
Public IP address Compute Engine Security Health Analytics
Shielded VM disabled Compute Engine Security Health Analytics
Weak SSL policy Compute Engine Security Health Analytics
Alpha cluster enabled Google Kubernetes Engine Security Health Analytics
Auto repair disabled Google Kubernetes Engine Security Health Analytics
Auto upgrade disabled Google Kubernetes Engine Security Health Analytics
Binary authorization disabled Google Kubernetes Engine Security Health Analytics
Cluster logging disabled Google Kubernetes Engine Security Health Analytics
Cluster monitoring disabled Google Kubernetes Engine Security Health Analytics
Cluster private Google access disabled Google Kubernetes Engine Security Health Analytics
Cluster secrets encryption disabled Google Kubernetes Engine Security Health Analytics
Cluster shielded nodes disabled Google Kubernetes Engine Security Health Analytics
COS not used Google Kubernetes Engine Security Health Analytics
Integrity monitoring disabled Google Kubernetes Engine Security Health Analytics
Intranode visibility disabled Google Kubernetes Engine Security Health Analytics
IP alias disabled Google Kubernetes Engine Security Health Analytics
Legacy authorization enabled Google Kubernetes Engine Security Health Analytics
Legacy metadata enabled Google Kubernetes Engine Security Health Analytics
Master authorized networks disabled Google Kubernetes Engine Security Health Analytics
Network policy disabled Google Kubernetes Engine Security Health Analytics
Nodepool boot CMEK disabled Google Kubernetes Engine Security Health Analytics
Nodepool secure boot disabled Google Kubernetes Engine Security Health Analytics
Over privileged account Google Kubernetes Engine Security Health Analytics
Over privileged scopes Google Kubernetes Engine Security Health Analytics
Pod security policy disabled Google Kubernetes Engine Security Health Analytics
Private cluster disabled Google Kubernetes Engine Security Health Analytics
Release channel disabled Google Kubernetes Engine Security Health Analytics
Web UI enabled Google Kubernetes Engine Security Health Analytics
Workload Identity disabled Google Kubernetes Engine Security Health Analytics
Dataproc CMEK disabled Managed Service for Apache Spark Security Health Analytics
Dataproc image outdated Managed Service for Apache Spark Security Health Analytics
BigQuery table CMEK disabled BigQuery Security Health Analytics
Dataset CMEK disabled BigQuery Security Health Analytics
Public dataset BigQuery Security Health Analytics
DNSSEC disabled Cloud DNS Security Health Analytics
RSASHA1 for signing Cloud DNS Security Health Analytics
Egress deny rule not set חומת אש Security Health Analytics
Firewall rule logging disabled חומת אש Security Health Analytics
Open Cassandra port חומת אש Security Health Analytics
Open ciscosecure websm port חומת אש Security Health Analytics
Open directory services port חומת אש Security Health Analytics
Open DNS port חומת אש Security Health Analytics
Open elasticsearch port חומת אש Security Health Analytics
Open firewall חומת אש Security Health Analytics
Open FTP port חומת אש Security Health Analytics
Open HTTP port חומת אש Security Health Analytics
Open LDAP port חומת אש Security Health Analytics
Open Memcached port חומת אש Security Health Analytics
Open MongoDB port חומת אש Security Health Analytics
Open MySQL port חומת אש Security Health Analytics
Open NetBIOS port חומת אש Security Health Analytics
Open OracleDB port חומת אש Security Health Analytics
Open pop3 port חומת אש Security Health Analytics
Open PostgreSQL port חומת אש Security Health Analytics
Open RDP port חומת אש Security Health Analytics
Open Redis port חומת אש Security Health Analytics
Open SMTP port חומת אש Security Health Analytics
Open SSH port חומת אש Security Health Analytics
Open Telnet port חומת אש Security Health Analytics
Access Transparency disabled IAM Security Health Analytics
Admin service account IAM Security Health Analytics
Essential Contacts Not Configured IAM Security Health Analytics
KMS role separation IAM Security Health Analytics
Non org IAM member IAM Security Health Analytics
Open group IAM member IAM Security Health Analytics
Over privileged service account user IAM Security Health Analytics
Primitive roles used IAM Security Health Analytics
Redis role used on org IAM Security Health Analytics
Service account role separation IAM Security Health Analytics
Service account key not rotated IAM Security Health Analytics
User managed service account key IAM Security Health Analytics
KMS key not rotated Cloud KMS Security Health Analytics
KMS project has owner Cloud KMS Security Health Analytics
KMS public key Cloud KMS Security Health Analytics
Too many KMS users Cloud KMS Security Health Analytics
Audit logging disabled רישום ביומן Security Health Analytics
Bucket logging disabled רישום ביומן Security Health Analytics
Locked retention policy not set רישום ביומן Security Health Analytics
Log not exported רישום ביומן Security Health Analytics
Object versioning disabled רישום ביומן Security Health Analytics
Audit config not monitored מעקב Security Health Analytics
Bucket IAM not monitored מעקב Security Health Analytics
Custom role not monitored מעקב Security Health Analytics
Firewall not monitored מעקב Security Health Analytics
Network not monitored מעקב Security Health Analytics
Owner not monitored מעקב Security Health Analytics
Route not monitored מעקב Security Health Analytics
MFA not enforced אימות Security Health Analytics
Default network רשת Security Health Analytics
DNS logging disabled רשת Security Health Analytics
Legacy network רשת Security Health Analytics
Load balancer logging disabled רשת Security Health Analytics
Org policy Confidential VM policy מדיניות הארגון Security Health Analytics
Org policy location restriction מדיניות הארגון Security Health Analytics
Pubsub CMEK disabled Pub/Sub Security Health Analytics
AlloyDB auto backup disabled AlloyDB Security Health Analytics
AlloyDB backups disabled AlloyDB Security Health Analytics
AlloyDB CMEK disabled AlloyDB Security Health Analytics
AlloyDB log min error statement severity AlloyDB Security Health Analytics
AlloyDB log min messages AlloyDB Security Health Analytics
AlloyDB log error verbosity AlloyDB Security Health Analytics
AlloyDB public IP AlloyDB Security Health Analytics
AlloyDB SSL not enforced AlloyDB Security Health Analytics
Auto backup disabled Cloud SQL Security Health Analytics
Public SQL instance Cloud SQL Security Health Analytics
SSL not enforced Cloud SQL Security Health Analytics
SQL CMEK disabled Cloud SQL Security Health Analytics
SQL contained database authentication Cloud SQL Security Health Analytics
SQL cross DB ownership chaining Cloud SQL Security Health Analytics
SQL external scripts enabled Cloud SQL Security Health Analytics
SQL local infile Cloud SQL Security Health Analytics
SQL log checkpoints disabled Cloud SQL Security Health Analytics
SQL log connections disabled Cloud SQL Security Health Analytics
SQL log disconnections disabled Cloud SQL Security Health Analytics
SQL log duration disabled Cloud SQL Security Health Analytics
SQL log error verbosity Cloud SQL Security Health Analytics
SQL log lock waits disabled Cloud SQL Security Health Analytics
SQL log min duration statement enabled Cloud SQL Security Health Analytics
SQL log min error statement Cloud SQL Security Health Analytics
SQL log min error statement severity Cloud SQL Security Health Analytics
SQL log min messages Cloud SQL Security Health Analytics
SQL log executor stats enabled Cloud SQL Security Health Analytics
SQL log hostname enabled Cloud SQL Security Health Analytics
SQL log parser stats enabled Cloud SQL Security Health Analytics
SQL log planner stats enabled Cloud SQL Security Health Analytics
SQL log statement Cloud SQL Security Health Analytics
SQL log statement stats enabled Cloud SQL Security Health Analytics
SQL log temp files Cloud SQL Security Health Analytics
SQL no root password Cloud SQL Security Health Analytics
SQL public IP Cloud SQL Security Health Analytics
SQL remote access enabled Cloud SQL Security Health Analytics
SQL skip show database disabled Cloud SQL Security Health Analytics
SQL trace flag 3625 Cloud SQL Security Health Analytics
SQL user connections configured Cloud SQL Security Health Analytics
SQL user options configured Cloud SQL Security Health Analytics
SQL weak root password Cloud SQL Security Health Analytics
Bucket CMEK disabled Cloud Storage Security Health Analytics
Bucket policy only disabled Cloud Storage Security Health Analytics
Public bucket ACL Cloud Storage Security Health Analytics
Public log bucket Cloud Storage Security Health Analytics
Flow logs disabled רשת משנה Security Health Analytics
Flow logs settings not recommended רשת משנה Security Health Analytics
Private Google access disabled רשת משנה Security Health Analytics
AWS findings AWS Security Health Analytics
Accessible Git repository אפליקציית אינטרנט Web Security Scanner
Accessible SVN repository אפליקציית אינטרנט Web Security Scanner
Accessible ENV File אפליקציית אינטרנט Web Security Scanner
Cacheable password input אפליקציית אינטרנט Web Security Scanner
Clear text password אפליקציית אינטרנט Web Security Scanner
Insecure allow origin ends with validation אפליקציית אינטרנט Web Security Scanner
Insecure allow origin starts with validation אפליקציית אינטרנט Web Security Scanner
Invalid content type אפליקציית אינטרנט Web Security Scanner
Invalid header אפליקציית אינטרנט Web Security Scanner
Mismatching security header values אפליקציית אינטרנט Web Security Scanner
Misspelled security header name אפליקציית אינטרנט Web Security Scanner
Mixed content אפליקציית אינטרנט Web Security Scanner
Outdated library אפליקציית אינטרנט Web Security Scanner
Server side request forgery אפליקציית אינטרנט Web Security Scanner
Session ID leak אפליקציית אינטרנט Web Security Scanner
SQL injection אפליקציית אינטרנט Web Security Scanner
Struts insecure deserialization אפליקציית אינטרנט Web Security Scanner
XSS אפליקציית אינטרנט Web Security Scanner
XSS angular callback אפליקציית אינטרנט Web Security Scanner
XSS error אפליקציית אינטרנט Web Security Scanner
XXE reflected file leakage אפליקציית אינטרנט Web Security Scanner
Prototype pollution אפליקציית אינטרנט Web Security Scanner
Hsts Misconfiguration אפליקציית אינטרנט Web Security Scanner
Content Security Policy Header Missing אפליקציית אינטרנט Web Security Scanner
Content Security Policy Header Misconfigured אפליקציית אינטרנט Web Security Scanner
Cross-Origin-Opener-Policy Header Missing אפליקציית אינטרנט Web Security Scanner
Clickjacking Protection Missing אפליקציית אינטרנט Web Security Scanner
IAM role has excessive permissions IAM שירות ההמלצות של IAM
Service agent role replaced with basic role IAM שירות ההמלצות של IAM
Service agent granted basic role IAM שירות ההמלצות של IAM
Unused IAM role IAM שירות ההמלצות של IAM
Assumed identity has excessive permissions IAM Cloud Infrastructure Entitlement Management
Group has excessive permissions IAM Cloud Infrastructure Entitlement Management
User has excessive permissions IAM Cloud Infrastructure Entitlement Management
User is inactive IAM Cloud Infrastructure Entitlement Management
Group is inactive IAM Cloud Infrastructure Entitlement Management
Assumed identity is inactive IAM Cloud Infrastructure Entitlement Management
Overly permissive trust policy enforced on assumed identity IAM Cloud Infrastructure Entitlement Management
Assumed identity has lateral movement risk IAM Cloud Infrastructure Entitlement Management
Floor settings violation הגנה מוגברת על המודל הגנה מוגברת על המודל
SHA Canned Module Drifted מצב אבטחה מצב אבטחה
SHA Custom Module Drifted מצב אבטחה מצב אבטחה
SHA Custom Module Deleted מצב אבטחה מצב אבטחה
Org Policy Canned Constraint Drifted מצב אבטחה מצב אבטחה
Org Policy Canned Constraint Deleted מצב אבטחה מצב אבטחה
Org Policy Custom Constraint Drifted מצב אבטחה מצב אבטחה
Org Policy Custom Constraint Deleted מצב אבטחה מצב אבטחה
Disable VPC External IPv6 מצב אבטחה מצב אבטחה
Disable VPC Internal IPv6 מצב אבטחה מצב אבטחה
Require OS Login מצב אבטחה מצב אבטחה
Restrict Authorized Networks מצב אבטחה מצב אבטחה
Require VPC Connector מצב אבטחה מצב אבטחה
Disabled Serial Port Access מצב אבטחה מצב אבטחה
Skip Default Network Creation מצב אבטחה מצב אבטחה
Allowed Ingress מצב אבטחה מצב אבטחה
Uniform Bucket Level Access מצב אבטחה מצב אבטחה
Allowed VPC Egress מצב אבטחה מצב אבטחה
OS vulnerability Compute Engine VM Manager
Container image vulnerability Artifact Registry הערכת נקודות חולשה ב-Artifact Registry
Software vulnerability Agent Platform הגנה מבוססת-AI
Public sensitive data נכס נתונים Sensitive Data Protection
Secrets in environment variables מחשוב ללא שרת (serverless) Sensitive Data Protection
Secrets in storage נכס נתונים Sensitive Data Protection
Gemini model not protected by Model Armor הגנה מוגברת על המודל הגנה מוגברת על המודל
Gemini model detected הגנה מוגברת על המודל הגנה מוגברת על המודל

המאמרים הבאים