Container Threat Detection provides runtime security for GKE, detecting active threats inside running containers.
What is Container Threat Detection?
Container Threat Detection is a security service that monitors running containers in Google Kubernetes Engine for malicious activity. Unlike vulnerability scanning that checks container images before deployment, Container Threat Detection observes low-level behavior in the guest kernel of containers at runtime. It can detect cryptominers, malware, reverse shells, and suspicious behavior patterns, alerting security teams through Security Command Center.
Container Threat Detection is included with Security Command Center Premium and Enterprise, enabled by default unless explicitly disabled, and is not compatible with GKE Sandbox.
Core Features
- Cryptominer detection: Identifies cryptocurrency mining processes in containers
- Malware identification: Detects known malicious binaries and behavior patterns
- Reverse shell detection: Alerts on suspicious outbound shell connections
- Suspicious binary execution: Flags unexpected executables running in containers
- Privilege escalation monitoring: Detects attempts to gain elevated privileges
- Container escape detection: Identifies attempts to break out of container isolation
Typical Use Cases
Compromised Container Detection
Attackers who gain access to a container often deploy cryptominers or establish reverse shells for persistent access. Container Threat Detection can identify these activities quickly, enabling faster incident response.
Runtime Security Compliance
Regulatory frameworks increasingly require runtime security monitoring for containerized workloads. Container Threat Detection contributes visibility and an audit trail relevant to compliance requirements such as SOC 2 or PCI-DSS.
Supply Chain Attack Defense
Malicious code hidden in dependencies may not be detected by image scanning alone. Container Threat Detection can catch malicious behavior when compromised packages execute, even if they passed static analysis checks.
Benefits
- Kernel-level visibility: Detection extends to container escape attempts
- Low overhead: Efficient kernel-level monitoring
- Automatic coverage: Available for GKE workloads once SCC Premium/Enterprise is enabled
- Continuous updates: Google’s security team maintains detection rules
- Integrated response: Findings flow into Security Command Center workflows
Integration with innFactory
As a certified Google Cloud Partner, innFactory helps you implement Container Threat Detection as part of a comprehensive GKE security strategy. We configure Security Command Center, design incident response workflows, and integrate threat findings with your security operations tooling.
Available Tiers & Options
Security Command Center Premium / Enterprise
- Full threat detection coverage
- Automated remediation options
- Compliance reporting
- Requires Premium or Enterprise tier
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Container Threat Detection?
Container Threat Detection is a security service that monitors GKE containers for runtime threats. It collects and analyzes low-level behavior in the guest kernel of containers to identify cryptominers, malware, reverse shells, and suspicious activity. Findings appear in Security Command Center for investigation and response.
How does Container Threat Detection work?
Container Threat Detection analyzes system calls and process behavior at the kernel level to identify patterns associated with known malicious behavior, such as cryptocurrency mining or attempts to establish reverse shells.
What threats does it detect?
Container Threat Detection can identify cryptominers, malware execution, reverse shells, suspicious binary execution, privilege escalation attempts, and container escape attempts, where a process tries to break out of its container isolation.
Is Container Threat Detection included with GKE?
Container Threat Detection requires the Premium or Enterprise tier of Security Command Center; it is not part of standard GKE pricing. Once Premium or Enterprise is enabled, Container Threat Detection is active by default and covers GKE clusters, unless explicitly disabled.
Does it impact container performance?
Container Threat Detection is designed for low performance impact through efficient kernel-level monitoring. It is not compatible with GKE Sandbox, which must be disabled on clusters where Container Threat Detection should run.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
