Google Cloud Security Command Center: Threat Detection and Response

Security Command Center is Google Cloud's native security monitoring platform. This guide covers SCC Premium tier setup, finding types, threat detection with Event Threat Detection, Security Health Analytics, automated remediation with Cloud Functions, and integration with SIEM systems.

Most organizations discover security incidents from external parties — a customer reports unusual behavior, a security researcher reports a vulnerability, or a third-party tool alerts on suspicious API calls. By that point, the attacker has already had time to escalate privileges, exfiltrate data, or establish persistence.

Security Command Center (SCC) is Google Cloud's native threat detection and security posture management platform. Unlike third-party tools that receive GCP event data with latency, SCC has deep, real-time integration with GCP services — it can detect threats like credential exfiltration, cryptomining, and data exfiltration within minutes of the behavior occurring.

This guide covers the practical implementation: enabling SCC, understanding finding types, configuring automated response, and integrating with your security operations workflow.

SCC Tiers: Standard vs Premium vs Enterprise

Standard (free): Misconfiguration findings, Basic Threat Detection, Security Health Analytics with a limited ruleset. Good for initial visibility but misses most real-world threats.

Premium ($0.45/node-hour for GKE, $0.003/API call for Cloud APIs): Adds Event Threat Detection, Container Threat Detection, advanced Security Health Analytics, and Rapid Vulnerability Detection. This is the tier where SCC becomes a real threat detection platform.

Enterprise (contact sales): Adds multi-cloud support (AWS, Azure), AI-powered threat investigation, and attack path simulation.

For production workloads, Premium is the minimum. The cost is typically less than 5% of compute spend and significantly less than licensing a third-party CSPM tool.

# Enable SCC for your organization
gcloud services enable securitycenter.googleapis.com   --project=my-project

# Enable SCC Premium features
gcloud scc settings update   --organization=ORGANIZATION_ID   --enable-asset-discovery

# Activate Security Health Analytics
gcloud scc settings update   --organization=ORGANIZATION_ID   --service=SECURITY_HEALTH_ANALYTICS   --enable

Understanding SCC Finding Categories

SCC organizes findings into three categories:

Vulnerabilities: Static weaknesses in your GCP configuration — open firewall rules, public Cloud Storage buckets, missing encryption, etc. These findings persist until you fix the underlying configuration.

Threats: Active threat indicators — detected malware, credential access attempts, crypto mining activity, lateral movement. These are time-sensitive events requiring immediate investigation.

Misconfigurations: Deviations from security best practices — missing audit logging, disabled VPC Flow Logs, over-permissive IAM policies.

Key Finding Types to Prioritize

Critical threats (respond within 1 hour):

  • Malware: Cryptomining Bad Domain — Node or pod is making DNS requests to known cryptomining pools
  • Persistence: IAM Anomalous Grant — IAM policy was modified by a service account that normally doesn't perform IAM changes
  • Exfiltration: BigQuery Data Exfiltration — Large BigQuery export to an external project
  • Initial Access: Suspicious Login — Login from a new geolocation or using compromised credentials (based on Have I Been Pwned data)

High vulnerabilities (fix within 24 hours):

  • Public bucket ACL — Cloud Storage bucket is publicly readable
  • Open firewall — Firewall rule allows SSH or RDP from 0.0.0.0/0
  • Full API access — Service account or VM has cloud-platform OAuth scope
  • Audit logging disabled — Data Access audit logs not configured for a project

Querying and Managing Findings

# List active Critical and High findings
gcloud scc findings list ORGANIZATION_ID   --filter="state='ACTIVE' AND (severity='CRITICAL' OR severity='HIGH')"   --format="table(name,category,severity,createTime)"   --order-by="severity,createTime desc"

# List all active threat findings
gcloud scc findings list ORGANIZATION_ID   --filter="state='ACTIVE' AND finding_class='THREAT'"   --format="table(name,category,resourceName,createTime)"

# Get details of a specific finding
gcloud scc findings describe FINDING_NAME   --format=json | jq '.sourceProperties'

The sourceProperties field contains the raw evidence for the finding — API call details, IP addresses, user agents, and other forensic data.

Event Threat Detection: Real-Time Threat Detection

Event Threat Detection (ETD) analyzes Cloud Audit Logs in real time and matches them against threat intelligence rules. It detects:

  • Brute force attacks against Kubernetes API server
  • Privilege escalation through IAM modification
  • Data exfiltration via unusual BigQuery exports or Cloud Storage downloads
  • Cryptomining via DNS requests to known mining pool domains
  • Credential compromise by detecting credentials appearing in public code repositories

ETD runs automatically once SCC Premium is enabled — no configuration required. Findings appear in the SCC console within 2-5 minutes of the triggering event.

For GKE clusters specifically, enable Container Threat Detection:

gcloud container clusters update my-cluster   --region=europe-west4   --enable-security-posture   --workload-vulnerability-scanning=standard

Container Threat Detection adds runtime protection: it detects unexpected processes running inside containers (shell spawned by a web server, network scan tools, etc.).

Security Health Analytics: Continuous Posture Monitoring

Security Health Analytics (SHA) continuously scans your GCP resources against a ruleset of 100+ security controls. Unlike one-time compliance scans, SHA updates findings within minutes of a configuration change.

# View all active SHA findings for your project
gcloud scc findings list ORGANIZATION_ID   --filter="state='ACTIVE' AND source_properties.finding_provider_uri:'securityhealthanalytics'"   --format="table(name,category,severity,resourceName)"

# Get statistics: findings by category
gcloud scc findings list ORGANIZATION_ID   --filter="state='ACTIVE'"   --format=json |   jq '[.[] | .category] | group_by(.) | map({category: .[0], count: length}) | sort_by(.count) | reverse'

Commonly found SHA issues in new GCP environments:

  1. KMS key rotation disabled: Encryption keys not set for annual rotation
  2. VPC flow logs disabled: Needed for network forensics and compliance
  3. Audit logs not configured: Data Access logs not enabled for BigQuery, Cloud Storage, etc.
  4. Default service accounts with project editor: Compute Engine default SA has excessive permissions
  5. Public Cloud Storage buckets: AllUsers or allAuthenticatedUsers have read access

Automated Remediation

For high-confidence findings, automate immediate remediation to reduce exposure time. Use Cloud Pub/Sub notifications from SCC to trigger Cloud Functions.

# Create a Pub/Sub topic for SCC notifications
gcloud pubsub topics create scc-findings

# Create SCC notification config to push findings to Pub/Sub
gcloud scc notifications create scc-high-findings   --organization=ORGANIZATION_ID   --description="High and Critical SCC Findings"   --pubsub-topic=projects/my-project/topics/scc-findings   --filter="state='ACTIVE' AND (severity='CRITICAL' OR severity='HIGH')"
# cloud_function/main.py — Auto-remediation for public buckets
import base64
import json
import functions_framework
from google.cloud import storage

@functions_framework.cloud_event
def remediate_scc_finding(cloud_event):
    pubsub_message = base64.b64decode(cloud_event.data["message"]["data"]).decode("utf-8")
    finding_data = json.loads(pubsub_message)

    finding = finding_data.get("finding", {})
    category = finding.get("category", "")
    severity = finding.get("severity", "")
    resource_name = finding.get("resourceName", "")

    # Handle specific finding types
    if category == "PUBLIC_BUCKET_ACL" and severity in ["CRITICAL", "HIGH"]:
        remediate_public_bucket(resource_name)
    elif category == "OPEN_FIREWALL" and severity == "CRITICAL":
        # Alert only — don't auto-modify firewall rules as they may be intentional
        send_alert_to_security_team(finding)

def remediate_public_bucket(resource_name: str):
    """Remove public access from a Cloud Storage bucket."""
    # Resource name format: //storage.googleapis.com/projects/_/buckets/BUCKET_NAME
    bucket_name = resource_name.split("/")[-1]

    client = storage.Client()
    bucket = client.bucket(bucket_name)

    # Remove public access
    bucket.iam_configuration.public_access_prevention = "enforced"
    bucket.patch()

    print(f"Removed public access from bucket: {bucket_name}")
    send_alert_to_security_team({
        "action": "auto_remediated",
        "resource": bucket_name,
        "category": "PUBLIC_BUCKET_ACL",
    })
# Deploy the remediation function
gcloud functions deploy scc-auto-remediate   --gen2   --runtime=python311   --region=europe-west4   --source=.   --entry-point=remediate_scc_finding   --trigger-topic=scc-findings   --service-account=scc-remediation-sa@my-project.iam.gserviceaccount.com   --memory=256Mi

Be conservative with automated remediation — only automate changes with very low false positive rates and no risk of causing application downtime. Auto-closing public buckets is safe; auto-modifying firewall rules is not.

SIEM Integration

Export SCC findings to your SIEM (Splunk, QRadar, Chronicle) for correlation with other security signals:

# Export all SCC findings to BigQuery for analysis and SIEM
gcloud scc bigquery-exports create scc-bq-export   --organization=ORGANIZATION_ID   --dataset=projects/my-project/datasets/scc_findings   --filter="state='ACTIVE'"

# For real-time export to Pub/Sub (for SIEM integration)
gcloud scc notifications create scc-all-findings-stream   --organization=ORGANIZATION_ID   --pubsub-topic=projects/my-project/topics/scc-all-findings   --filter="state='ACTIVE'"

With findings in BigQuery, you can run security analytics:

-- Count findings by category and severity over the last 30 days
SELECT
  category,
  severity,
  COUNT(*) AS finding_count,
  MIN(create_time) AS first_seen,
  MAX(create_time) AS last_seen
FROM `my-project.scc_findings.findings`
WHERE create_time >= TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 30 DAY)
  AND state = 'ACTIVE'
GROUP BY 1, 2
ORDER BY finding_count DESC;

-- Find resources with the most active findings
SELECT
  resource_name,
  COUNT(*) AS finding_count,
  ARRAY_AGG(DISTINCT category ORDER BY category) AS categories
FROM `my-project.scc_findings.findings`
WHERE state = 'ACTIVE'
GROUP BY 1
ORDER BY 2 DESC
LIMIT 20;

Incident Response Playbook

When SCC raises a Critical threat finding, follow this response process:

  1. Triage (0-15 minutes): Review the finding's sourceProperties for evidence. Determine if it's a true positive or false positive.

  2. Contain (15-60 minutes): For confirmed incidents:

    • Revoke the affected service account's keys: gcloud iam service-accounts disable SA_EMAIL
    • Isolate the affected VM by removing it from its firewall rules
    • For GKE: drain the affected node: kubectl drain NODE_NAME --ignore-daemonsets
  3. Investigate (1-24 hours): Use Cloud Audit Logs to reconstruct the attack timeline:

    gcloud logging read      'protoPayload.authenticationInfo.principalEmail="compromised-sa@project.iam.gserviceaccount.com" AND timestamp>="2025-01-01T00:00:00Z"'      --format="table(timestamp,protoPayload.methodName,protoPayload.resourceName)"
    
  4. Remediate: Fix the root cause, rotate credentials, and update controls to prevent recurrence.

  5. Document: Record the finding ID, timeline, actions taken, and root cause in your incident management system.

For Zero Trust security architecture that complements SCC, see our BeyondCorp Enterprise guide. For preventing data exfiltration at the network level, see our VPC Service Controls guide.