API key APIs unrestricted
|
API |
Security Health Analytics
|
API key apps unrestricted
|
API |
Security Health Analytics
|
API key exists
|
API |
Security Health Analytics
|
API key not rotated
|
API |
Security Health Analytics
|
Cloud Asset API disabled
|
Cloud Asset Inventory |
Security Health Analytics
|
Public Compute image
|
Compute Engine |
Security Health Analytics
|
Confidential Computing disabled
|
Compute Engine |
Security Health Analytics
|
Compute project wide SSH keys allowed
|
Compute Engine |
Security Health Analytics
|
Compute Secure Boot disabled
|
Compute Engine |
Security Health Analytics
|
Compute serial ports enabled
|
Compute Engine |
Security Health Analytics
|
Default service account used
|
Compute Engine |
Security Health Analytics
|
Disk CMEK disabled
|
Compute Engine |
Security Health Analytics
|
Disk CSEK disabled
|
Compute Engine |
Security Health Analytics
|
Full API access
|
Compute Engine |
Security Health Analytics
|
HTTP load balancer
|
Compute Engine |
Security Health Analytics
|
Instance OS Login disabled
|
Compute Engine |
Security Health Analytics
|
IP forwarding enabled
|
Compute Engine |
Security Health Analytics
|
OS login disabled
|
Compute Engine |
Security Health Analytics
|
Public IP address
|
Compute Engine |
Security Health Analytics
|
Shielded VM disabled
|
Compute Engine |
Security Health Analytics
|
Weak SSL policy
|
Compute Engine |
Security Health Analytics
|
Alpha cluster enabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Auto repair disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Auto upgrade disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Binary authorization disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Cluster logging disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Cluster monitoring disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Cluster private Google access disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Cluster secrets encryption disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Cluster shielded nodes disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
COS not used
|
Google Kubernetes Engine |
Security Health Analytics
|
Integrity monitoring disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Intranode visibility disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
IP alias disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Legacy authorization enabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Legacy metadata enabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Master authorized networks disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Network policy disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Nodepool boot CMEK disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Nodepool secure boot disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Over privileged account
|
Google Kubernetes Engine |
Security Health Analytics
|
Over privileged scopes
|
Google Kubernetes Engine |
Security Health Analytics
|
Pod security policy disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Private cluster disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Release channel disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Web UI enabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Workload Identity disabled
|
Google Kubernetes Engine |
Security Health Analytics
|
Dataproc CMEK disabled
|
Managed Service for Apache Spark |
Security Health Analytics
|
Dataproc image outdated
|
Managed Service for Apache Spark |
Security Health Analytics
|
BigQuery table CMEK disabled
|
BigQuery |
Security Health Analytics
|
Dataset CMEK disabled
|
BigQuery |
Security Health Analytics
|
Public dataset
|
BigQuery |
Security Health Analytics
|
DNSSEC disabled
|
Cloud DNS |
Security Health Analytics
|
RSASHA1 for signing
|
Cloud DNS |
Security Health Analytics
|
Egress deny rule not set
|
防火墙 |
Security Health Analytics
|
Firewall rule logging disabled
|
防火墙 |
Security Health Analytics
|
Open Cassandra port
|
防火墙 |
Security Health Analytics
|
Open ciscosecure websm port
|
防火墙 |
Security Health Analytics
|
Open directory services port
|
防火墙 |
Security Health Analytics
|
Open DNS port
|
防火墙 |
Security Health Analytics
|
Open elasticsearch port
|
防火墙 |
Security Health Analytics
|
Open firewall
|
防火墙 |
Security Health Analytics
|
Open FTP port
|
防火墙 |
Security Health Analytics
|
Open HTTP port
|
防火墙 |
Security Health Analytics
|
Open LDAP port
|
防火墙 |
Security Health Analytics
|
Open Memcached port
|
防火墙 |
Security Health Analytics
|
Open MongoDB port
|
防火墙 |
Security Health Analytics
|
Open MySQL port
|
防火墙 |
Security Health Analytics
|
Open NetBIOS port
|
防火墙 |
Security Health Analytics
|
Open OracleDB port
|
防火墙 |
Security Health Analytics
|
Open pop3 port
|
防火墙 |
Security Health Analytics
|
Open PostgreSQL port
|
防火墙 |
Security Health Analytics
|
Open RDP port
|
防火墙 |
Security Health Analytics
|
Open Redis port
|
防火墙 |
Security Health Analytics
|
Open SMTP port
|
防火墙 |
Security Health Analytics
|
Open SSH port
|
防火墙 |
Security Health Analytics
|
Open Telnet port
|
防火墙 |
Security Health Analytics
|
Access Transparency disabled
|
IAM |
Security Health Analytics
|
Admin service account
|
IAM |
Security Health Analytics
|
Essential Contacts Not Configured
|
IAM |
Security Health Analytics
|
KMS role separation
|
IAM |
Security Health Analytics
|
Non org IAM member
|
IAM |
Security Health Analytics
|
Open group IAM member
|
IAM |
Security Health Analytics
|
Over privileged service account user
|
IAM |
Security Health Analytics
|
Primitive roles used
|
IAM |
Security Health Analytics
|
Redis role used on org
|
IAM |
Security Health Analytics
|
Service account role separation
|
IAM |
Security Health Analytics
|
Service account key not rotated
|
IAM |
Security Health Analytics
|
User managed service account key
|
IAM |
Security Health Analytics
|
KMS key not rotated
|
Cloud KMS |
Security Health Analytics
|
KMS project has owner
|
Cloud KMS |
Security Health Analytics
|
KMS public key
|
Cloud KMS |
Security Health Analytics
|
Too many KMS users
|
Cloud KMS |
Security Health Analytics
|
Audit logging disabled
|
日志记录 |
Security Health Analytics
|
Bucket logging disabled
|
日志记录 |
Security Health Analytics
|
Locked retention policy not set
|
日志记录 |
Security Health Analytics
|
Log not exported
|
日志记录 |
Security Health Analytics
|
Object versioning disabled
|
日志记录 |
Security Health Analytics
|
Audit config not monitored
|
监控 |
Security Health Analytics
|
Bucket IAM not monitored
|
监控 |
Security Health Analytics
|
Custom role not monitored
|
监控 |
Security Health Analytics
|
Firewall not monitored
|
监控 |
Security Health Analytics
|
Network not monitored
|
监控 |
Security Health Analytics
|
Owner not monitored
|
监控 |
Security Health Analytics
|
Route not monitored
|
监控 |
Security Health Analytics
|
MFA not enforced
|
身份验证 |
Security Health Analytics
|
Default network
|
网络 |
Security Health Analytics
|
DNS logging disabled
|
网络 |
Security Health Analytics
|
Legacy network
|
网络 |
Security Health Analytics
|
Load balancer logging disabled
|
网络 |
Security Health Analytics
|
Org policy Confidential VM policy
|
组织政策 |
Security Health Analytics
|
Org policy location restriction
|
组织政策 |
Security Health Analytics
|
Pubsub CMEK disabled
|
Pub/Sub |
Security Health Analytics
|
AlloyDB auto backup disabled
|
AlloyDB |
Security Health Analytics
|
AlloyDB backups disabled
|
AlloyDB |
Security Health Analytics
|
AlloyDB CMEK disabled
|
AlloyDB |
Security Health Analytics
|
AlloyDB log min error statement severity
|
AlloyDB |
Security Health Analytics
|
AlloyDB log min messages
|
AlloyDB |
Security Health Analytics
|
AlloyDB log error verbosity
|
AlloyDB |
Security Health Analytics
|
AlloyDB public IP
|
AlloyDB |
Security Health Analytics
|
AlloyDB SSL not enforced
|
AlloyDB |
Security Health Analytics
|
Auto backup disabled
|
Cloud SQL |
Security Health Analytics
|
Public SQL instance
|
Cloud SQL |
Security Health Analytics
|
SSL not enforced
|
Cloud SQL |
Security Health Analytics
|
SQL CMEK disabled
|
Cloud SQL |
Security Health Analytics
|
SQL contained database authentication
|
Cloud SQL |
Security Health Analytics
|
SQL cross DB ownership chaining
|
Cloud SQL |
Security Health Analytics
|
SQL external scripts enabled
|
Cloud SQL |
Security Health Analytics
|
SQL local infile
|
Cloud SQL |
Security Health Analytics
|
SQL log checkpoints disabled
|
Cloud SQL |
Security Health Analytics
|
SQL log connections disabled
|
Cloud SQL |
Security Health Analytics
|
SQL log disconnections disabled
|
Cloud SQL |
Security Health Analytics
|
SQL log duration disabled
|
Cloud SQL |
Security Health Analytics
|
SQL log error verbosity
|
Cloud SQL |
Security Health Analytics
|
SQL log lock waits disabled
|
Cloud SQL |
Security Health Analytics
|
SQL log min duration statement enabled
|
Cloud SQL |
Security Health Analytics
|
SQL log min error statement
|
Cloud SQL |
Security Health Analytics
|
SQL log min error statement severity
|
Cloud SQL |
Security Health Analytics
|
SQL log min messages
|
Cloud SQL |
Security Health Analytics
|
SQL log executor stats enabled
|
Cloud SQL |
Security Health Analytics
|
SQL log hostname enabled
|
Cloud SQL |
Security Health Analytics
|
SQL log parser stats enabled
|
Cloud SQL |
Security Health Analytics
|
SQL log planner stats enabled
|
Cloud SQL |
Security Health Analytics
|
SQL log statement
|
Cloud SQL |
Security Health Analytics
|
SQL log statement stats enabled
|
Cloud SQL |
Security Health Analytics
|
SQL log temp files
|
Cloud SQL |
Security Health Analytics
|
SQL no root password
|
Cloud SQL |
Security Health Analytics
|
SQL public IP
|
Cloud SQL |
Security Health Analytics
|
SQL remote access enabled
|
Cloud SQL |
Security Health Analytics
|
SQL skip show database disabled
|
Cloud SQL |
Security Health Analytics
|
SQL trace flag 3625
|
Cloud SQL |
Security Health Analytics
|
SQL user connections configured
|
Cloud SQL |
Security Health Analytics
|
SQL user options configured
|
Cloud SQL |
Security Health Analytics
|
SQL weak root password
|
Cloud SQL |
Security Health Analytics
|
Bucket CMEK disabled
|
Cloud Storage |
Security Health Analytics
|
Bucket policy only disabled
|
Cloud Storage |
Security Health Analytics
|
Public bucket ACL
|
Cloud Storage |
Security Health Analytics
|
Public log bucket
|
Cloud Storage |
Security Health Analytics
|
Flow logs disabled
|
子网 |
Security Health Analytics
|
Flow logs settings not recommended
|
子网 |
Security Health Analytics
|
Private Google access disabled
|
子网 |
Security Health Analytics
|
AWS findings
|
AWS |
Security Health Analytics
|
Accessible Git repository
|
Web 应用 |
Web Security Scanner
|
Accessible SVN repository
|
Web 应用 |
Web Security Scanner
|
Accessible ENV File
|
Web 应用 |
Web Security Scanner
|
Cacheable password input
|
Web 应用 |
Web Security Scanner
|
Clear text password
|
Web 应用 |
Web Security Scanner
|
Insecure allow origin ends with validation
|
Web 应用 |
Web Security Scanner
|
Insecure allow origin starts with validation
|
Web 应用 |
Web Security Scanner
|
Invalid content type
|
Web 应用 |
Web Security Scanner
|
Invalid header
|
Web 应用 |
Web Security Scanner
|
Mismatching security header values
|
Web 应用 |
Web Security Scanner
|
Misspelled security header name
|
Web 应用 |
Web Security Scanner
|
Mixed content
|
Web 应用 |
Web Security Scanner
|
Outdated library
|
Web 应用 |
Web Security Scanner
|
Server side request forgery
|
Web 应用 |
Web Security Scanner
|
Session ID leak
|
Web 应用 |
Web Security Scanner
|
SQL injection
|
Web 应用 |
Web Security Scanner
|
Struts insecure deserialization
|
Web 应用 |
Web Security Scanner
|
XSS
|
Web 应用 |
Web Security Scanner
|
XSS angular callback
|
Web 应用 |
Web Security Scanner
|
XSS error
|
Web 应用 |
Web Security Scanner
|
XXE reflected file leakage
|
Web 应用 |
Web Security Scanner
|
Prototype pollution
|
Web 应用 |
Web Security Scanner
|
Hsts Misconfiguration
|
Web 应用 |
Web Security Scanner
|
Content Security Policy Header Missing
|
Web 应用 |
Web Security Scanner
|
Content Security Policy Header Misconfigured
|
Web 应用 |
Web Security Scanner
|
Cross-Origin-Opener-Policy Header Missing
|
Web 应用 |
Web Security Scanner
|
Clickjacking Protection Missing
|
Web 应用 |
Web Security Scanner
|
IAM role has excessive permissions
|
IAM |
IAM Recommender
|
Service agent role replaced with basic role
|
IAM |
IAM Recommender
|
Service agent granted basic role
|
IAM |
IAM Recommender
|
Unused IAM role
|
IAM |
IAM Recommender
|
Assumed identity has excessive permissions
|
IAM |
云基础设施授权管理
|
Group has excessive permissions
|
IAM |
云基础设施授权管理
|
User has excessive permissions
|
IAM |
云基础设施授权管理
|
User is inactive
|
IAM |
云基础设施授权管理
|
Group is inactive
|
IAM |
云基础设施授权管理
|
Assumed identity is inactive
|
IAM |
云基础设施授权管理
|
Overly permissive trust policy enforced on assumed identity
|
IAM |
云基础设施授权管理
|
Assumed identity has lateral movement risk
|
IAM |
云基础设施授权管理
|
Floor settings violation
|
Model Armor |
Model Armor
|
SHA Canned Module Drifted
|
安全状况 |
安全状况
|
SHA Custom Module Drifted
|
安全状况 |
安全状况
|
SHA Custom Module Deleted
|
安全状况 |
安全状况
|
Org Policy Canned Constraint Drifted
|
安全状况 |
安全状况
|
Org Policy Canned Constraint Deleted
|
安全状况 |
安全状况
|
Org Policy Custom Constraint Drifted
|
安全状况 |
安全状况
|
Org Policy Custom Constraint Deleted
|
安全状况 |
安全状况
|
Disable VPC External IPv6
|
安全状况 |
安全状况
|
Disable VPC Internal IPv6
|
安全状况 |
安全状况
|
Require OS Login
|
安全状况 |
安全状况
|
Restrict Authorized Networks
|
安全状况 |
安全状况
|
Require VPC Connector
|
安全状况 |
安全状况
|
Disabled Serial Port Access
|
安全状况 |
安全状况
|
Skip Default Network Creation
|
安全状况 |
安全状况
|
Allowed Ingress
|
安全状况 |
安全状况
|
Uniform Bucket Level Access
|
安全状况 |
安全状况
|
Allowed VPC Egress
|
安全状况 |
安全状况
|
OS vulnerability
|
Compute Engine |
虚拟机管理器
|
Container image vulnerability
|
Artifact Registry |
Artifact Registry 漏洞评估
|
Software vulnerability
|
Agent Platform |
AI Protection
|
Public sensitive data
|
数据资产 |
Sensitive Data Protection
|
Secrets in environment variables
|
无服务器计算 |
Sensitive Data Protection
|
Secrets in storage
|
数据资产 |
Sensitive Data Protection
|
Gemini model not protected by Model Armor
|
Model Armor |
Model Armor
|
Gemini model detected
|
Model Armor |
Model Armor
|