Classifies Google Cloud SCC incidents
Google Cloud SCC
- Details
- Content
- Dependencies
- Version History
This pack leverages the features of Google Cloud Security to provide an organization-wide framework for detection and response.
Name | Description |
---|---|
GoogleCloudSCC - Classifier | |
GoogleCloudSCC - Incoming Mapper | Maps incoming Google Cloud SCC incident fields. |
Name | Description |
---|---|
GoogleCloudSCC Finding SourceProperties AppCategory | |
GoogleCloudSCC Finding ExternalURI | |
GoogleCloudSCC Finding SourceProperties PageId | |
GoogleCloudSCC Finding SourceProperties NumBytes | |
GoogleCloudSCC Finding EventTime | |
GoogleCloudSCC Finding SourceProperties MfaDetails | |
GoogleCloudSCC Finding SourceProperties Timestamp | Last Timestamp of the finding's sourceproperties. |
GoogleCloudSCC Finding SourceProperties ExceptionInstructions | |
GoogleCloudSCC Finding SourceProperties ProjectId | |
GoogleCloudSCC Finding Category | |
GoogleCloudSCC Finding SourceProperties ActivationTrigger | |
GoogleCloudSCC Finding SourceProperties LastLocation | |
GoogleCloudSCC Finding Name | Name of the finding. |
GoogleCloudSCC Finding SourceProperties AppSessionId | |
GoogleCloudSCC Finding SourceProperties RiskLevel | |
GoogleCloudSCC Finding SourceProperties ID | |
GoogleCloudSCC Finding SourceProperties DstTimezone | |
GoogleCloudSCC Finding SourceProperties Domain | |
GoogleCloudSCC Finding FirstDiscovered | |
GoogleCloudSCC Finding SourceProperties Alert | |
GoogleCloudSCC Recommendation | |
GoogleCloudSCC Finding SourceProperties LastCountry | |
GoogleCloudSCC Finding SourceProperties Page | |
GoogleCloudSCC Finding SourceProperties Threshold | |
GoogleCloudSCC Finding SourceProperties CCI | |
GoogleCloudSCC Finding SourceProperties User | |
GoogleCloudSCC Finding SourceProperties ExposedService | |
GoogleCloudSCC Resource Project DisplayName | Displayname of the resource. |
GoogleCloudSCC Finding SourceProperties UserIP | |
GoogleCloudSCC Finding SourceProperties LastRegion | |
GoogleCloudSCC Finding SourceProperties ScannerName | |
GoogleCloudSCC Finding SourceProperties SrcLocation | |
GoogleCloudSCC Finding SourceProperties DstRegion | |
GoogleCloudSCC Finding SourceProperties ReactivationCount | |
GoogleCloudSCC Finding SourceProperties PageEndtime | |
GoogleCloudSCC Overview | |
GoogleCloudSCC Resource Name | |
GoogleCloudSCC Finding SourceProperties CCL | |
GoogleCloudSCC Finding SourceProperties Severity | |
GoogleCloudSCC Finding SourceProperties ClientBytes | |
GoogleCloudSCC Finding SourceProperties DstLocation | |
GoogleCloudSCC Finding SourceProperties TenantName | |
Google Cloud SCC Organization ID | Unique Id of the organization |
GoogleCloudSCC Finding SourceProperties Device | |
GoogleCloudSCC Resource ParentName | |
GoogleCloudSCC Finding SourceProperties SrcGeoIpSrc | |
GoogleCloudSCC Finding SourceProperties ReqCnt | |
GoogleCloudSCC Finding SourceProperties SlcLongitute | |
GoogleCloudSCC Finding SourceProperties SrcZipcode | |
GoogleCloudSCC Finding SourceProperties App | |
GoogleCloudSCC Finding SourceProperties BrowserSessionId | |
GoogleCloudSCC Finding SourceProperties SeverityLevel | |
GoogleCloudSCC Finding SourceProperties DstIP | |
GoogleCloudSCC Finding SourceProperties PageDuration | |
GoogleCloudSCC Finding SourceProperties SrcTimezone | |
GoogleCloudSCC Resource ParentDisplayName | |
GoogleCloudSCC Finding SourceProperties Site | |
GoogleCloudSCC Finding SourceProperties UserAgent | |
GoogleCloudSCC Finding SourceProperties InsertionEpochTimestamp | |
GoogleCloudSCC Finding SourceProperties AlertType | |
GoogleCloudSCC Finding SourceProperties RiskLevelId | |
GoogleCloudSCC Finding URL | |
GoogleCloudSCC Finding CreateTime | |
GoogleCloudSCC Finding SourceProperties Count | |
GoogleCloudSCC Finding SourceProperties SlcLatitude | |
GoogleCloudSCC Finding SourceProperties SrcRegion | |
GoogleCloudSCC Finding SourceProperties PageStarttime | |
GoogleCloudSCC Finding SourceProperties RespCnt | |
GoogleCloudSCC Finding SourceProperties OrganizationUnit | |
GoogleCloudSCC Finding SourceProperties UserKey | |
GoogleCloudSCC Finding SourceProperties UrNormalized | |
GoogleCloudSCC Finding SourceProperties AccessMethod | |
GoogleCloudSCC Finding SourceProperties OrigTy | |
GoogleCloudSCC Asset DisplayName | Asset name |
GoogleCloudSCC Parent Resource ParentDisplayName | |
GoogleCloudSCC Finding SourceProperties ServerBytes | |
GoogleCloudSCC Finding SourceProperties EventType | |
GoogleCloudSCC Finding SourceProperties DstCountry | |
GoogleCloudSCC Finding Parent | Parent of the finding. |
GoogleCloudSCC Finding SourceProperties DstZipcode | |
GoogleCloudSCC Finding SourceProperties DstGeoipSrc | |
GoogleCloudSCC Finding SourceProperties HostName | |
GoogleCloudSCC Finding SourceProperties LastDevice | |
GoogleCloudSCC Finding SourceProperties UserGenerated | |
GoogleCloudSCC Finding SourceProperties Browser | |
GoogleCloudSCC Resource ProjectName | |
GoogleCloudSCC Security Marks | |
GoogleCloudSCC Finding MostRecentlySeen | |
GoogleCloudSCC Finding SourceProperties Browser Version | |
GoogleCloudSCC Finding SourceProperties TrafficType | |
GoogleCloudSCC Finding SourceProperties Acked | |
GoogleCloudSCC Finding SourceProperties SrcCountry | |
GoogleCloudSCC Finding SourceProperties LastApp | |
GoogleCloudSCC Finding SourceProperties ProfileId |
Name | Description |
---|---|
Google Cloud SCC Finding |
Name | Description |
---|---|
Google Cloud SCC (Partner Contribution) | Security Command Center is a security and risk management platform for Google Cloud. Security Command Center enables you to understand your security and data attack surface by providing asset inventory and discovery, identifying vulnerabilities and threats, and helping you mitigate and remediate risks across an organization. This integration helps you to perform tasks related to findings and assets. |
Name | Description |
---|---|
Google Cloud SCC Finding | Google Cloud SCC Finding Layout |
Name | Description |
---|---|
GoogleCloudSCC - Classifier | Classifies Google Cloud SCC incidents |
GoogleCloudSCC - Incoming Mapper | Maps incoming Google Cloud SCC incident fields. |
Name | Description |
---|---|
GoogleCloudSCC Finding SourceProperties MfaDetails | |
GoogleCloudSCC Finding SourceProperties ExposedService | |
GoogleCloudSCC Finding Name | Name of the finding. |
GoogleCloudSCC Resource ParentDisplayName | |
GoogleCloudSCC Finding SourceProperties Site | |
GoogleCloudSCC Finding SourceProperties NumBytes | |
GoogleCloudSCC Finding SourceProperties Device | |
GoogleCloudSCC Asset DisplayName | Asset name |
GoogleCloudSCC Finding SourceProperties AlertType | |
GoogleCloudSCC Finding SourceProperties SrcRegion | |
GoogleCloudSCC Security Marks | |
GoogleCloudSCC Finding SourceProperties Severity | |
GoogleCloudSCC Finding SourceProperties SlcLatitude | |
GoogleCloudSCC Finding SourceProperties ID | |
GoogleCloudSCC Finding SourceProperties Browser Version | |
Google Cloud SCC Organization ID | Unique Id of the organization |
GoogleCloudSCC Finding SourceProperties PageDuration | |
GoogleCloudSCC Finding SourceProperties ActivationTrigger | |
GoogleCloudSCC Finding SourceProperties DstTimezone | |
GoogleCloudSCC Finding SourceProperties ClientBytes | |
GoogleCloudSCC Finding SourceProperties RiskLevel | |
GoogleCloudSCC Finding SourceProperties LastLocation | |
GoogleCloudSCC Finding SourceProperties UserKey | |
GoogleCloudSCC Finding SourceProperties Threshold | |
GoogleCloudSCC Finding SourceProperties LastApp | |
GoogleCloudSCC Finding URL | |
GoogleCloudSCC Finding SourceProperties DstGeoipSrc | |
GoogleCloudSCC Finding SourceProperties OrganizationUnit | |
GoogleCloudSCC Finding SourceProperties ExceptionInstructions | |
GoogleCloudSCC Finding Parent | Parent of the finding. |
GoogleCloudSCC Finding SourceProperties ProfileId | |
GoogleCloudSCC Finding SourceProperties TrafficType | |
GoogleCloudSCC Finding SourceProperties PageStarttime | |
GoogleCloudSCC Finding SourceProperties UserGenerated | |
GoogleCloudSCC Finding SourceProperties SrcGeoIpSrc | |
GoogleCloudSCC Finding SourceProperties LastRegion | |
GoogleCloudSCC Finding SourceProperties Acked | |
GoogleCloudSCC Finding SourceProperties UrNormalized | |
GoogleCloudSCC Finding SourceProperties ScannerName | |
GoogleCloudSCC Finding SourceProperties Alert | |
GoogleCloudSCC Finding SourceProperties TenantName | |
GoogleCloudSCC Finding SourceProperties Domain | |
GoogleCloudSCC Finding SourceProperties Timestamp | Last Timestamp of the finding's sourceproperties. |
GoogleCloudSCC Resource Name | |
GoogleCloudSCC Finding SourceProperties Browser | |
GoogleCloudSCC Finding SourceProperties DstIP | |
GoogleCloudSCC Finding SourceProperties CCL | |
GoogleCloudSCC Parent Resource ParentDisplayName | |
GoogleCloudSCC Finding SourceProperties ReactivationCount | |
GoogleCloudSCC Finding SourceProperties RespCnt | |
GoogleCloudSCC Finding SourceProperties SrcZipcode | |
GoogleCloudSCC Finding SourceProperties SlcLongitute | |
GoogleCloudSCC Finding SourceProperties ServerBytes | |
GoogleCloudSCC Finding SourceProperties AppSessionId | |
GoogleCloudSCC Finding SourceProperties User | |
GoogleCloudSCC Overview | |
GoogleCloudSCC Finding SourceProperties DstRegion | |
GoogleCloudSCC Finding SourceProperties Count | |
GoogleCloudSCC Finding SourceProperties CCI | |
GoogleCloudSCC Finding SourceProperties SeverityLevel | |
GoogleCloudSCC Recommendation | |
GoogleCloudSCC Finding SourceProperties EventType | |
GoogleCloudSCC Finding MostRecentlySeen | |
GoogleCloudSCC Finding SourceProperties DstLocation | |
GoogleCloudSCC Finding SourceProperties DstZipcode | |
GoogleCloudSCC Finding SourceProperties ReqCnt | |
GoogleCloudSCC Finding SourceProperties SrcCountry | |
GoogleCloudSCC Finding SourceProperties UserIP | |
GoogleCloudSCC Finding SourceProperties SrcTimezone | |
GoogleCloudSCC Finding SourceProperties OrigTy | |
GoogleCloudSCC Finding SourceProperties SrcLocation | |
GoogleCloudSCC Resource ParentName | |
GoogleCloudSCC Finding SourceProperties PageEndtime | |
GoogleCloudSCC Finding SourceProperties LastDevice | |
GoogleCloudSCC Finding FirstDiscovered | |
GoogleCloudSCC Finding SourceProperties AccessMethod | |
GoogleCloudSCC Finding SourceProperties BrowserSessionId | |
GoogleCloudSCC Finding SourceProperties RiskLevelId | |
GoogleCloudSCC Finding ExternalURI | |
GoogleCloudSCC Finding SourceProperties Page | |
GoogleCloudSCC Finding SourceProperties InsertionEpochTimestamp | |
GoogleCloudSCC Finding SourceProperties PageId |
Name | Description |
---|---|
Google Cloud SCC Finding |
Name | Description |
---|---|
Google Cloud SCC (Partner Contribution) | Security Command Center is a security and risk management platform for Google Cloud. Security Command Center enables you to understand your security and data attack surface by providing asset inventory and discovery, identifying vulnerabilities and threats, and helping you mitigate and remediate risks across an organization. This integration helps you to perform tasks related to findings and assets. |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Pack Name | Pack By |
---|---|
Common Types | By: Cortex XSOAR |
Phishing | By: Cortex XSOAR |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Classifiers
GoogleCloudSCC - Classifier
- updated from version to 6.0.0
Incident Fields
- GoogleCloudSCC Finding SourceProperties Page
- GoogleCloudSCC Finding SourceProperties ServerBytes
- GoogleCloudSCC Finding SourceProperties TrafficType
- GoogleCloudSCC Finding Parent
- GoogleCloudSCC Finding SourceProperties ScannerName
- GoogleCloudSCC Finding SourceProperties SlcLongitute
- GoogleCloudSCC Finding SourceProperties LastRegion
- GoogleCloudSCC Finding SourceProperties UserKey
- GoogleCloudSCC Overview
- GoogleCloudSCC Resource ProjectName
- GoogleCloudSCC Finding SourceProperties HostName
- GoogleCloudSCC Finding SourceProperties ClientBytes
- GoogleCloudSCC Finding SourceProperties LastLocation
- GoogleCloudSCC Finding SourceProperties PageStarttime
- GoogleCloudSCC Finding SourceProperties LastApp
- GoogleCloudSCC Finding SourceProperties SeverityLevel
- GoogleCloudSCC Finding SourceProperties RespCnt
- GoogleCloudSCC Finding SourceProperties Severity
- GoogleCloudSCC Finding SourceProperties ProjectId
- GoogleCloudSCC Resource ParentName
- GoogleCloudSCC Finding SourceProperties DstIP
- GoogleCloudSCC Asset DisplayName
- GoogleCloudSCC Finding SourceProperties SrcCountry
- GoogleCloudSCC Finding SourceProperties LastCountry
- GoogleCloudSCC Finding SourceProperties DstRegion
- GoogleCloudSCC Finding SourceProperties DstTimezone
- GoogleCloudSCC Security Marks
- GoogleCloudSCC Finding SourceProperties Domain
- GoogleCloudSCC Finding SourceProperties User
- GoogleCloudSCC Finding SourceProperties ReqCnt
- GoogleCloudSCC Finding SourceProperties OrigTy
- GoogleCloudSCC Finding SourceProperties Threshold
- GoogleCloudSCC Finding SourceProperties SrcTimezone
- GoogleCloudSCC Finding SourceProperties RiskLevelId
- GoogleCloudSCC Finding SourceProperties UserIP
- GoogleCloudSCC Finding SourceProperties LastDevice
- GoogleCloudSCC Finding SourceProperties AccessMethod
- GoogleCloudSCC Finding SourceProperties ExposedService
- GoogleCloudSCC Finding SourceProperties PageEndtime
- GoogleCloudSCC Finding SourceProperties PageId
- GoogleCloudSCC Finding SourceProperties NumBytes
- GoogleCloudSCC Finding SourceProperties Acked
- GoogleCloudSCC Finding SourceProperties App
- GoogleCloudSCC Finding SourceProperties Browser Version
- GoogleCloudSCC Finding SourceProperties ProfileId
- GoogleCloudSCC Finding SourceProperties DstZipcode
- GoogleCloudSCC Finding SourceProperties InsertionEpochTimestamp
- GoogleCloudSCC Finding SourceProperties UrNormalized
- GoogleCloudSCC Finding SourceProperties RiskLevel
- GoogleCloudSCC Finding SourceProperties Site
- GoogleCloudSCC Finding Category
- GoogleCloudSCC Finding SourceProperties SrcLocation
- GoogleCloudSCC Finding SourceProperties UserAgent
- GoogleCloudSCC Finding CreateTime
- GoogleCloudSCC Recommendation
- GoogleCloudSCC Resource Project DisplayName
- GoogleCloudSCC Finding SourceProperties Device
- GoogleCloudSCC Finding URL
- GoogleCloudSCC Resource Name
- GoogleCloudSCC Finding SourceProperties SrcZipcode
- GoogleCloudSCC Finding SourceProperties DstLocation
- GoogleCloudSCC Finding SourceProperties AppCategory
- GoogleCloudSCC Finding SourceProperties DstCountry
- GoogleCloudSCC Finding SourceProperties PageDuration
- GoogleCloudSCC Finding EventTime
- GoogleCloudSCC Finding SourceProperties SlcLatitude
- GoogleCloudSCC Finding SourceProperties ID
- GoogleCloudSCC Finding SourceProperties ActivationTrigger
- GoogleCloudSCC Finding ExternalURI
- GoogleCloudSCC Finding SourceProperties UserGenerated
- GoogleCloudSCC Finding MostRecentlySeen
- GoogleCloudSCC Finding SourceProperties ReactivationCount
- GoogleCloudSCC Parent Resource ParentDisplayName
- Google Cloud SCC Organization ID
- GoogleCloudSCC Finding SourceProperties DstGeoipSrc
- GoogleCloudSCC Finding SourceProperties AppSessionId
- GoogleCloudSCC Finding SourceProperties OrganizationUnit
- GoogleCloudSCC Finding SourceProperties SrcGeoIpSrc
- GoogleCloudSCC Finding SourceProperties Browser
- GoogleCloudSCC Finding SourceProperties CCI
- GoogleCloudSCC Finding SourceProperties Timestamp
- GoogleCloudSCC Finding FirstDiscovered
- GoogleCloudSCC Finding SourceProperties Count
- GoogleCloudSCC Resource ParentDisplayName
- GoogleCloudSCC Finding SourceProperties TenantName
- GoogleCloudSCC Finding SourceProperties BrowserSessionId
- GoogleCloudSCC Finding SourceProperties MfaDetails
- GoogleCloudSCC Finding SourceProperties SrcRegion
- GoogleCloudSCC Finding SourceProperties AlertType
- GoogleCloudSCC Finding SourceProperties EventType
- GoogleCloudSCC Finding SourceProperties CCL
- GoogleCloudSCC Finding SourceProperties Alert
- GoogleCloudSCC Finding Name
- GoogleCloudSCC Finding SourceProperties ExceptionInstructions
Incident Types
- Google Cloud SCC Finding
Integrations
Google Cloud SCC
- Added support for multi organization
- Added Organization ID in command outputs and layout
- Updated the Docker image to: demisto/google-api-py3:1.0.0.36366.
Layouts
Google Cloud SCC Finding
Google Cloud SCC Finding
Included Organization ID field in layout
Mappers
GoogleCloudSCC - Incoming Mapper
- Added mapping for Organization ID
- 22118
- 21693
- 14484
- 14439
- 14469
- 14483
- 14380
- 14422
- 14465
- 14442
- 14490
- 14492
- 14493
- 14130
- 14489
- 14382
- 14502
- 14124
- 14482
- 14503
- 14499
- 14466
- 12770
- 14501
- 14375
- 12795
- 14350
- 14507
- 13848
- 14378
- 13857
- 14512
- 14384
- 14516
- 14500
- 14481
- 14464
- 14522
- 14459
- 14525
- 14523
- 14076
- 14532
- 14368
- 14519
- 14455
- 13905
- 14537
- 14540
- 14538
- 14372
- 14072
- 14524
- 14498
- 14536
- 14302
- 14550
- 14505
- 14542
- 14468
- 14555
- 14556
- 14541
- 14526
- 14552
- 12335
- 14529
- 14561
- 14470
- 14331
- 13676
- 14475
- 11589
- 14568
- 14569
- 14565
- 13875
- 14558
- 13550
- 14578
- 14579
- 13902
- 14583
- 14511
- 14557
- 14585
- 14587
- 14476
- 14451
- 14596
- 14553
- 14517
- 14508
- 14605
- 14609
- 14607
- 14599
- 14480
- 14600
- 14545
- 14608
- 14604
- 14548
- 14543
- 14602
- 14590
- 14430
- 14611
- 14614
- 14376
- 14613
- 14612
- 14531
- 14591
- 13994
- 14564
- 14615
- 13924
- 14352
- 14626
- 14635
- 14633
- 14632
- 14622
- 14634
- 14625
- 14631
- 14636
- 14598
Download
PUBLISHER
PLATFORMS
INFO
Certification | Certified | Read more |
Supported By | Partner | |
Created | March 31, 2021 | |
Last Release | February 14, 2024 |