Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

Vulnerabilities queried from Security Command Center vs Compute Instances

Hello,

    I am using the following REST API queries to fetch all the Vulnerabilities (CVEs) in Compute Instances in my project in GCP. I am trying with two different options. Both seem to fetch different set of Vulnerabilities

Using SCC

https://securitycenter.googleapis.com/v2/projects/myGCPProject/sources/-/findings?pageSize=5000&find...

Using osconfig API

https://osconfig.googleapis.com/v1/projects/myGCPProject/locations/us-south1-a/instances/-/vulnerabi...

osconfig API get lot more CVEs as compared to SCC. Please note the osconfig API, as shown above, is targetted to a specific zone, while the SCC query is for the entire project. I would expect it to fetch lot more CVEs as there are VMs in more than one zone in my GCP project. 

Thanks!

0 1 88
1 REPLY 1

This is the most important part of the best interest way to get the next
day thank you so much 🙏
Top Labels in this Space
Top Solution Authors