Google Cloud Security Command Center V1 Client - Class Finding (1.14.2)

Reference documentation and code samples for the Google Cloud Security Command Center V1 Client class Finding.

Security Command Center finding.

A finding is a record of assessment data like security, risk, health, or privacy, that is ingested into Security Command Center for presentation, notification, analysis, policy testing, and enforcement. For example, a cross-site scripting (XSS) vulnerability in an App Engine application is a finding.

Generated from protobuf message google.cloud.securitycenter.v1.Finding

Methods

__construct

Constructor.

Parameters
Name
Description
data
array

Optional. Data for populating the Message object.

↳ name
string

The relative resource name of this finding. See: https://cloud.google.com/apis/design/resource_names#relative_resource_name Example: "organizations/{organization_id}/sources/{source_id}/findings/{finding_id}"

↳ parent
string

The relative resource name of the source the finding belongs to. See: https://cloud.google.com/apis/design/resource_names#relative_resource_name This field is immutable after creation time. For example: "organizations/{organization_id}/sources/{source_id}"

↳ resource_name
string

For findings on Google Cloud resources, the full resource name of the Google Cloud resource this finding is for. See: https://cloud.google.com/apis/design/resource_names#full_resource_name When the finding is for a non-Google Cloud resource, the resourceName can be a customer or partner defined string. This field is immutable after creation time.

↳ state
int

The state of the finding.

↳ category
string

The additional taxonomy group within findings from a given source. This field is immutable after creation time. Example: "XSS_FLASH_INJECTION"

↳ external_uri
string

The URI that, if available, points to a web page outside of Security Command Center where additional information about the finding can be found. This field is guaranteed to be either empty or a well formed URL.

↳ source_properties
array| Google\Protobuf\Internal\MapField

Source specific properties. These properties are managed by the source that writes the finding. The key names in the source_properties map must be between 1 and 255 characters, and must start with a letter and contain alphanumeric characters or underscores only.

↳ security_marks
Google\Cloud\SecurityCenter\V1\SecurityMarks

Output only. User specified security marks. These marks are entirely managed by the user and come from the SecurityMarks resource that belongs to the finding.

↳ event_time
Google\Protobuf\Timestamp

The time the finding was first detected. If an existing finding is updated, then this is the time the update occurred. For example, if the finding represents an open firewall, this property captures the time the detector believes the firewall became open. The accuracy is determined by the detector. If the finding is later resolved, then this time reflects when the finding was resolved. This must not be set to a value greater than the current timestamp.

↳ create_time
Google\Protobuf\Timestamp

The time at which the finding was created in Security Command Center.

↳ severity
int

The severity of the finding. This field is managed by the source that writes the finding.

↳ canonical_name
string

The canonical name of the finding. It's either "organizations/{organization_id}/sources/{source_id}/findings/{finding_id}", "folders/{folder_id}/sources/{source_id}/findings/{finding_id}" or "projects/{project_number}/sources/{source_id}/findings/{finding_id}", depending on the closest CRM ancestor of the resource associated with the finding.

↳ mute
int

Indicates the mute state of a finding (either muted, unmuted or undefined). Unlike other attributes of a finding, a finding provider shouldn't set the value of mute.

↳ finding_class
int

The class of the finding.

↳ indicator
Google\Cloud\SecurityCenter\V1\Indicator

Represents what's commonly known as an Indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion. Reference: https://en.wikipedia.org/wiki/Indicator_of_compromise

↳ vulnerability
Google\Cloud\SecurityCenter\V1\Vulnerability

Represents vulnerability-specific fields like CVE and CVS scores. CVE stands for Common Vulnerabilities and Exposures ( https://cve.mitre.org/about/ )

↳ mute_update_time
Google\Protobuf\Timestamp

Output only. The most recent time this finding was muted or unmuted.

↳ external_systems
array| Google\Protobuf\Internal\MapField

Output only. Third party SIEM/SOAR fields within SCC, contains external system information and external system finding fields.

↳ mitre_attack
Google\Cloud\SecurityCenter\V1\MitreAttack

MITRE ATT&CK tactics and techniques related to this finding. See: https://attack.mitre.org

↳ access
Google\Cloud\SecurityCenter\V1\Access

Access details associated to the Finding, such as more information on the caller, which method was accessed, from where, etc.

↳ connections
array< Google\Cloud\SecurityCenter\V1\Connection >

Contains information about the IP connection associated with the finding.

↳ mute_initiator
string

First known as mute_annotation. Records additional information about the mute operation e.g. mute config that muted the finding, user who muted the finding, etc. Unlike other attributes of a finding, a finding provider shouldn't set the value of mute.

↳ processes
array< Google\Cloud\SecurityCenter\V1\Process >

Represents operating system processes associated with the Finding.

↳ contacts
array| Google\Protobuf\Internal\MapField

Output only. Map containing the points of contact for the given finding. The key represents the type of contact, while the value contains a list of all the contacts that pertain. Please refer to: https://cloud.google.com/resource-manager/docs/managing-notification-contacts#notification-categories { "security": { "contacts": [ { "email": "person1@company.com" }, { "email": "person2@company.com" } ] } }

↳ compliances
array< Google\Cloud\SecurityCenter\V1\Compliance >

Contains compliance information for security standards associated to the finding.

↳ parent_display_name
string

Output only. The human readable display name of the finding source such as "Event Threat Detection" or "Security Health Analytics".

↳ description
string

Contains more detail about the finding.

↳ exfiltration
Google\Cloud\SecurityCenter\V1\Exfiltration

Represents exfiltration associated with the Finding.

↳ iam_bindings
array< Google\Cloud\SecurityCenter\V1\IamBinding >

Represents IAM bindings associated with the Finding.

↳ next_steps
string

Next steps associate to the finding.

↳ containers
array< Google\Cloud\SecurityCenter\V1\Container >

Containers associated with the finding. containers provides information for both Kubernetes and non-Kubernetes containers.

↳ kubernetes
Google\Cloud\SecurityCenter\V1\Kubernetes

Kubernetes resources associated with the finding.

↳ database
Google\Cloud\SecurityCenter\V1\Database

Database associated with the finding.

↳ files
array< Google\Cloud\SecurityCenter\V1\File >

File associated with the finding.

↳ kernel_rootkit

getName

The relative resource name of this finding. See: https://cloud.google.com/apis/design/resource_names#relative_resource_name Example: "organizations/{organization_id}/sources/{source_id}/findings/{finding_id}"

Returns
Type
Description
string

setName

The relative resource name of this finding. See: https://cloud.google.com/apis/design/resource_names#relative_resource_name Example: "organizations/{organization_id}/sources/{source_id}/findings/{finding_id}"

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getParent

The relative resource name of the source the finding belongs to. See: https://cloud.google.com/apis/design/resource_names#relative_resource_name This field is immutable after creation time.

For example: "organizations/{organization_id}/sources/{source_id}"

Returns
Type
Description
string

setParent

The relative resource name of the source the finding belongs to. See: https://cloud.google.com/apis/design/resource_names#relative_resource_name This field is immutable after creation time.

For example: "organizations/{organization_id}/sources/{source_id}"

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getResourceName

For findings on Google Cloud resources, the full resource name of the Google Cloud resource this finding is for. See: https://cloud.google.com/apis/design/resource_names#full_resource_name When the finding is for a non-Google Cloud resource, the resourceName can be a customer or partner defined string. This field is immutable after creation time.

Returns
Type
Description
string

setResourceName

For findings on Google Cloud resources, the full resource name of the Google Cloud resource this finding is for. See: https://cloud.google.com/apis/design/resource_names#full_resource_name When the finding is for a non-Google Cloud resource, the resourceName can be a customer or partner defined string. This field is immutable after creation time.

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getState

The state of the finding.

Returns
Type
Description
int

setState

The state of the finding.

Parameter
Name
Description
var
int
Returns
Type
Description
$this

getCategory

The additional taxonomy group within findings from a given source.

This field is immutable after creation time. Example: "XSS_FLASH_INJECTION"

Returns
Type
Description
string

setCategory

The additional taxonomy group within findings from a given source.

This field is immutable after creation time. Example: "XSS_FLASH_INJECTION"

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getExternalUri

The URI that, if available, points to a web page outside of Security Command Center where additional information about the finding can be found.

This field is guaranteed to be either empty or a well formed URL.

Returns
Type
Description
string

setExternalUri

The URI that, if available, points to a web page outside of Security Command Center where additional information about the finding can be found.

This field is guaranteed to be either empty or a well formed URL.

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getSourceProperties

Source specific properties. These properties are managed by the source that writes the finding. The key names in the source_properties map must be between 1 and 255 characters, and must start with a letter and contain alphanumeric characters or underscores only.

Returns
Type
Description

setSourceProperties

Source specific properties. These properties are managed by the source that writes the finding. The key names in the source_properties map must be between 1 and 255 characters, and must start with a letter and contain alphanumeric characters or underscores only.

Parameter
Name
Description
Returns
Type
Description
$this

getSecurityMarks

Output only. User specified security marks. These marks are entirely managed by the user and come from the SecurityMarks resource that belongs to the finding.

Returns
Type
Description

hasSecurityMarks

clearSecurityMarks

setSecurityMarks

Output only. User specified security marks. These marks are entirely managed by the user and come from the SecurityMarks resource that belongs to the finding.

Parameter
Name
Description
Returns
Type
Description
$this

getEventTime

The time the finding was first detected. If an existing finding is updated, then this is the time the update occurred.

For example, if the finding represents an open firewall, this property captures the time the detector believes the firewall became open. The accuracy is determined by the detector. If the finding is later resolved, then this time reflects when the finding was resolved. This must not be set to a value greater than the current timestamp.

Returns
Type
Description

hasEventTime

clearEventTime

setEventTime

The time the finding was first detected. If an existing finding is updated, then this is the time the update occurred.

For example, if the finding represents an open firewall, this property captures the time the detector believes the firewall became open. The accuracy is determined by the detector. If the finding is later resolved, then this time reflects when the finding was resolved. This must not be set to a value greater than the current timestamp.

Parameter
Name
Description
Returns
Type
Description
$this

getCreateTime

The time at which the finding was created in Security Command Center.

Returns
Type
Description

hasCreateTime

clearCreateTime

setCreateTime

The time at which the finding was created in Security Command Center.

Parameter
Name
Description
Returns
Type
Description
$this

getSeverity

The severity of the finding. This field is managed by the source that writes the finding.

Returns
Type
Description
int

setSeverity

The severity of the finding. This field is managed by the source that writes the finding.

Parameter
Name
Description
var
int
Returns
Type
Description
$this

getCanonicalName

The canonical name of the finding. It's either "organizations/{organization_id}/sources/{source_id}/findings/{finding_id}", "folders/{folder_id}/sources/{source_id}/findings/{finding_id}" or "projects/{project_number}/sources/{source_id}/findings/{finding_id}", depending on the closest CRM ancestor of the resource associated with the finding.

Returns
Type
Description
string

setCanonicalName

The canonical name of the finding. It's either "organizations/{organization_id}/sources/{source_id}/findings/{finding_id}", "folders/{folder_id}/sources/{source_id}/findings/{finding_id}" or "projects/{project_number}/sources/{source_id}/findings/{finding_id}", depending on the closest CRM ancestor of the resource associated with the finding.

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getMute

Indicates the mute state of a finding (either muted, unmuted or undefined). Unlike other attributes of a finding, a finding provider shouldn't set the value of mute.

Returns
Type
Description
int

setMute

Indicates the mute state of a finding (either muted, unmuted or undefined). Unlike other attributes of a finding, a finding provider shouldn't set the value of mute.

Parameter
Name
Description
var
int
Returns
Type
Description
$this

getFindingClass

The class of the finding.

Returns
Type
Description
int

setFindingClass

The class of the finding.

Parameter
Name
Description
var
int
Returns
Type
Description
$this

getIndicator

Represents what's commonly known as an Indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion.

Reference: https://en.wikipedia.org/wiki/Indicator_of_compromise

Returns
Type
Description

hasIndicator

clearIndicator

setIndicator

Represents what's commonly known as an Indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion.

Reference: https://en.wikipedia.org/wiki/Indicator_of_compromise

Parameter
Name
Description
Returns
Type
Description
$this

getVulnerability

Represents vulnerability-specific fields like CVE and CVS scores.

CVE stands for Common Vulnerabilities and Exposures ( https://cve.mitre.org/about/ )

Returns
Type
Description

hasVulnerability

clearVulnerability

setVulnerability

Represents vulnerability-specific fields like CVE and CVS scores.

CVE stands for Common Vulnerabilities and Exposures ( https://cve.mitre.org/about/ )

Parameter
Name
Description
Returns
Type
Description
$this

getMuteUpdateTime

Output only. The most recent time this finding was muted or unmuted.

Returns
Type
Description

hasMuteUpdateTime

clearMuteUpdateTime

setMuteUpdateTime

Output only. The most recent time this finding was muted or unmuted.

Parameter
Name
Description
Returns
Type
Description
$this

getExternalSystems

Output only. Third party SIEM/SOAR fields within SCC, contains external system information and external system finding fields.

Returns
Type
Description

setExternalSystems

Output only. Third party SIEM/SOAR fields within SCC, contains external system information and external system finding fields.

Parameter
Name
Description
Returns
Type
Description
$this

getMitreAttack

MITRE ATT&CK tactics and techniques related to this finding.

See: https://attack.mitre.org

Returns
Type
Description

hasMitreAttack

clearMitreAttack

setMitreAttack

MITRE ATT&CK tactics and techniques related to this finding.

See: https://attack.mitre.org

Parameter
Name
Description
Returns
Type
Description
$this

getAccess

Access details associated to the Finding, such as more information on the caller, which method was accessed, from where, etc.

Returns
Type
Description

hasAccess

clearAccess

setAccess

Access details associated to the Finding, such as more information on the caller, which method was accessed, from where, etc.

Parameter
Name
Description
Returns
Type
Description
$this

getConnections

Contains information about the IP connection associated with the finding.

Returns
Type
Description

setConnections

Contains information about the IP connection associated with the finding.

Parameter
Name
Description
Returns
Type
Description
$this

getMuteInitiator

First known as mute_annotation. Records additional information about the mute operation e.g. mute config that muted the finding, user who muted the finding, etc. Unlike other attributes of a finding, a finding provider shouldn't set the value of mute.

Returns
Type
Description
string

setMuteInitiator

First known as mute_annotation. Records additional information about the mute operation e.g. mute config that muted the finding, user who muted the finding, etc. Unlike other attributes of a finding, a finding provider shouldn't set the value of mute.

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getProcesses

Represents operating system processes associated with the Finding.

Returns
Type
Description

setProcesses

Represents operating system processes associated with the Finding.

Parameter
Name
Description
Returns
Type
Description
$this

getContacts

Output only. Map containing the points of contact for the given finding. The key represents the type of contact, while the value contains a list of all the contacts that pertain. Please refer to: https://cloud.google.com/resource-manager/docs/managing-notification-contacts#notification-categories { "security": { "contacts": [ { "email": "person1@company.com" }, { "email": "person2@company.com" } ] } }

Returns
Type
Description

setContacts

Output only. Map containing the points of contact for the given finding. The key represents the type of contact, while the value contains a list of all the contacts that pertain. Please refer to: https://cloud.google.com/resource-manager/docs/managing-notification-contacts#notification-categories { "security": { "contacts": [ { "email": "person1@company.com" }, { "email": "person2@company.com" } ] } }

Parameter
Name
Description
Returns
Type
Description
$this

getCompliances

Contains compliance information for security standards associated to the finding.

Returns
Type
Description

setCompliances

Contains compliance information for security standards associated to the finding.

Parameter
Name
Description
Returns
Type
Description
$this

getParentDisplayName

Output only. The human readable display name of the finding source such as "Event Threat Detection" or "Security Health Analytics".

Returns
Type
Description
string

setParentDisplayName

Output only. The human readable display name of the finding source such as "Event Threat Detection" or "Security Health Analytics".

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getDescription

Contains more detail about the finding.

Returns
Type
Description
string

setDescription

Contains more detail about the finding.

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getExfiltration

Represents exfiltration associated with the Finding.

Returns
Type
Description

hasExfiltration

clearExfiltration

setExfiltration

Represents exfiltration associated with the Finding.

Parameter
Name
Description
Returns
Type
Description
$this

getIamBindings

Represents IAM bindings associated with the Finding.

Returns
Type
Description

setIamBindings

Represents IAM bindings associated with the Finding.

Parameter
Name
Description
Returns
Type
Description
$this

getNextSteps

Next steps associate to the finding.

Returns
Type
Description
string

setNextSteps

Next steps associate to the finding.

Parameter
Name
Description
var
string
Returns
Type
Description
$this

getContainers

Containers associated with the finding. containers provides information for both Kubernetes and non-Kubernetes containers.

Returns
Type
Description

setContainers

Containers associated with the finding. containers provides information for both Kubernetes and non-Kubernetes containers.

Parameter
Name
Description
Returns
Type
Description
$this

getKubernetes

Kubernetes resources associated with the finding.

Returns
Type
Description

hasKubernetes

clearKubernetes

setKubernetes

Kubernetes resources associated with the finding.

Parameter
Name
Description
Returns
Type
Description
$this

getDatabase

Database associated with the finding.

Returns
Type
Description

hasDatabase

clearDatabase

setDatabase

Database associated with the finding.

Parameter
Name
Description
Returns
Type
Description
$this

getFiles

File associated with the finding.

Returns
Type
Description

setFiles

File associated with the finding.

Parameter
Name
Description
Returns
Type
Description
$this

getKernelRootkit

Kernel Rootkit signature.

Returns
Type
Description

hasKernelRootkit

clearKernelRootkit

setKernelRootkit

Kernel Rootkit signature.

Parameter
Name
Description
Returns
Type
Description
$this
Design a Mobile Site
View Site in Mobile | Classic
Share by: