GCP shielded_vm Mappings

Shielded VMs are virtual machines (VMs) on Google Cloud hardened by a set of security controls that help defend against rootkits and bootkits. Shielded VMs leverage advanced platform security capabilities such as secure and measured boot, a virtual trusted platform module (vTPM), UEFI firmware, and integrity monitoring.

Mappings

Capability ID Capability Description Category Value ATT&CK ID ATT&CK Name
shielded_vm Shielded VM protect significant T1542 Pre-OS Boot
shielded_vm Shielded VM protect partial T1014 Rootkit