GCP Security Command Center - Detect DNSSEC disabled for DNS zones

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Detects Google Cloud DNS zones where DNSSEC is disabled using Security Command Center findings (DNSSEC_DISABLED). Disabling DNSSEC increases risk of DNS hijacking and man-in-the-middle attacks. This analytic rule alerts on findings where DNSSEC is reported as disabled for a managed zone.

Attribute Value
Type Analytic Rule
Solution Google Cloud Platform Security Command Center
ID a9c7a4be-b7e7-4045-8028-0d1ffaa049af
Severity Medium
Status Available
Kind Scheduled
Tactics Collection, CommandAndControl, DefenseEvasion
Techniques T1557, T1071.004, T1562.001
Required Connectors GoogleSCCDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
GoogleCloudSCC ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Google Cloud Platform Security Command Center