GCP security_command_center Mappings

Security Command Center (SCC) provides analysts with a centralized dashboard for cyber situational awareness by aggregating threat and vulnerability reports. SCC works by scanning for weaknesses or monitoring an organization's logging stream for anomalies (e.g., Google Workspace logs, containers, vulnerabilities in web applications, and hypervisor-level instrumentation). To further mitigate risks in the infrastructure, SCC easily integrates with other Google Cloud security solutions: Cloud DLP, Chronicle, Binary Authorization, Cloud Armor, and 3rd party solutions (e.g., SIEM, SOAR). The cyber-attacks in this solution are correlated to SCC's premium tier which included additional security features for: Event Threat Detection, Container Threat Detection, Virtual Machine Threat Detection, Web Security Scanner, and Security Health Analytics

Mappings

Capability ID Capability Description Category Value ATT&CK ID ATT&CK Name
security_command_center Security Command Center detect significant T1204.003 Malicious Image
security_command_center Security Command Center detect significant T1525 Implant Internal Image
security_command_center Security Command Center detect significant T1133 External Remote Services
security_command_center Security Command Center detect significant T1505.003 Web Shell
security_command_center Security Command Center detect significant T1105 Ingress Tool Transfer
security_command_center Security Command Center detect significant T1059.004 Unix Shell
security_command_center Security Command Center detect significant T1071.004 DNS
security_command_center Security Command Center detect significant T1110 Brute Force
security_command_center Security Command Center detect significant T1078.004 Cloud Accounts
security_command_center Security Command Center detect significant T1562 Impair Defenses
security_command_center Security Command Center detect significant T1567 Exfiltration Over Web Service
security_command_center Security Command Center detect significant T1567.002 Exfiltration to Cloud Storage
security_command_center Security Command Center detect significant T1505.001 SQL Stored Procedures
security_command_center Security Command Center detect significant T1098.001 Additional Cloud Credentials
security_command_center Security Command Center detect significant T1562.007 Disable or Modify Cloud Firewall
security_command_center Security Command Center protect significant T1589.001 Credentials
security_command_center Security Command Center detect significant T1496 Resource Hijacking
security_command_center Security Command Center protect significant T1213.003 Code Repositories
security_command_center Security Command Center protect minimal T1040 Network Sniffing
security_command_center Security Command Center detect significant T1190 Exploit Public-Facing Application
security_command_center Security Command Center detect significant T1078.001 Default Accounts
security_command_center Security Command Center detect significant T1542 Pre-OS Boot
security_command_center Security Command Center detect significant T1542.003 Bootkit
security_command_center Security Command Center detect significant T1014 Rootkit
security_command_center Security Command Center detect significant T1070 Indicator Removal on Host
security_command_center Security Command Center detect significant T1484 Domain Policy Modification
security_command_center Security Command Center detect significant T1136.003 Cloud Account
security_command_center Security Command Center detect significant T1562.008 Disable Cloud Logs
security_command_center Security Command Center detect significant T1578 Modify Cloud Compute Infrastructure
security_command_center Security Command Center detect partial T1530 Data from Cloud Storage Object