What is Event Threat Detection?
Event Threat Detection is a built-in security service in Security Command Center Premium that continuously analyzes the Cloud Logging stream for an organization or individual projects for threats. The service uses known indicators of compromise (IoCs) and behavioral analysis to identify suspicious activities such as malware, cryptomining, or data exfiltration, and is regularly updated with new detection rules.
Core Features
- Automatic analysis of Cloud Audit Logs and other log sources
- Detection of malware, cryptomining, and unusual behavior
- Near real-time notifications for threats (typical latency under 15 minutes)
- Custom modules for organization-specific detection rules
- Integration with Security Command Center for a central overview and export to external SIEM systems
Typical Use Cases
Detection of Compromised Accounts: Event Threat Detection identifies unusual IAM activities such as access from unusual regions or creation of suspicious service accounts.
Malware Detection: The service detects known malware communication patterns and suspicious network activities that could indicate compromised workloads.
Compliance Monitoring: Continuous monitoring for security-relevant configuration changes and suspicious administrator activities to meet audit requirements.
Benefits
- Automatic detection without manual log analysis
- Use of Google’s threat intelligence and continuously updated detection rules
- Central security overview in Security Command Center
- Fast response through near real-time findings
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Event Threat Detection: setup of Security Command Center, integration into existing security workflows, and development of incident response processes.
Available Tiers & Options
Security Command Center Premium
- Automatic threat detection
- Continuous log analysis
- Integration with SIEM systems
- Custom detection rules via custom modules
- Only available in Premium tier
- Requires Security Command Center
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Event Threat Detection?
Event Threat Detection is a built-in service of Security Command Center Premium that continuously analyzes Cloud Audit Logs and other logs in the Cloud Logging stream for threats and generates findings for suspicious activities.
What threats are detected?
The service detects malware, cryptomining, unusual IAM activities, data exfiltration, SSH brute-force attacks, and suspicious API calls, based on known indicators of compromise and behavioral anomalies.
How quickly are threats detected?
Event Threat Detection analyzes logs in near real-time. Detection latency is typically under 15 minutes between when a log entry is written and when a finding becomes available.
Can I create custom detection rules?
Yes, in addition to Google's predefined detection rules, Event Threat Detection offers custom modules for defining your own detection rules. For advanced SIEM use cases, you can also connect Google Security Operations (Chronicle).
Which Security Command Center tier do I need?
Event Threat Detection is part of the Premium tier of Security Command Center, which adds advanced threat detection, attack path analysis, and compliance monitoring on top of the Standard tier.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
