Skip to content

GCP.SecurityCenter reference

Source: src/GCP/SecurityCenter/BigQueryExport.ts

A project-scoped Security Command Center BigQuery export that writes findings to a dataset.

Exports have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Export id is identity. Dataset, filter, and description update in place.

BigQueryExport: Creating a BigQuery Export

Section titled “BigQueryExport: Creating a BigQuery Export”
const dataset = yield* GCP.BigQuery.Dataset("SccFindings", {
location: "US",
forceDestroy: true,
});
const exp = yield* GCP.SecurityCenter.BigQueryExport("High", {
dataset: dataset.name,
description: "high severity",
filter: 'severity="HIGH"',
});

BigQueryExport: Updating a BigQuery Export

Section titled “BigQueryExport: Updating a BigQuery Export”
const exp = yield* GCP.SecurityCenter.BigQueryExport("High", {
dataset: dataset.name,
description: "high and critical",
filter: 'severity="HIGH" OR severity="CRITICAL"',
});

Source: src/GCP/SecurityCenter/EventThreatDetectionSettingsCustomModule.ts

A project-scoped Event Threat Detection custom module.

Custom modules have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Module id and type are identity (the id is server-assigned). Display name, description, enablement, and config update in place.

EventThreatDetectionSettingsCustomModule: Creating a Custom Module

Section titled “EventThreatDetectionSettingsCustomModule: Creating a Custom Module”
const module = yield* GCP.SecurityCenter.EventThreatDetectionSettingsCustomModule(
"BadIp",
{
type: "CONFIGURABLE_BAD_IP",
displayName: "alchemy_bad_ip",
description: "test bad ip",
config: {
metadata: {
severity: "LOW",
description: "test",
recommendation: "investigate",
},
ips: ["192.0.2.1"],
},
},
);

EventThreatDetectionSettingsCustomModule: Updating a Custom Module

Section titled “EventThreatDetectionSettingsCustomModule: Updating a Custom Module”
const module = yield* GCP.SecurityCenter.EventThreatDetectionSettingsCustomModule(
"BadIp",
{
type: "CONFIGURABLE_BAD_IP",
enablementState: "DISABLED",
},
);

Source: src/GCP/SecurityCenter/FolderBigQueryExport.ts

A folder-scoped Security Command Center BigQuery export.

Exports have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Export id and folder are identity. Dataset, filter, and description update in place.

FolderBigQueryExport: Creating a BigQuery Export

Section titled “FolderBigQueryExport: Creating a BigQuery Export”

Export active findings to a dataset

const dataset = yield* GCP.BigQuery.Dataset("SccFindings", {
location: "US",
forceDestroy: true,
});
const exp = yield* GCP.SecurityCenter.FolderBigQueryExport("Findings", {
dataset: `projects/${dataset.project}/datasets/${dataset.datasetId}`,
filter: 'state="ACTIVE"',
description: "active findings",
});

Named export on an explicit folder

const exp = yield* GCP.SecurityCenter.FolderBigQueryExport("Findings", {
folder: "folders/123456789",
exportId: "active-findings",
dataset: "projects/my-project/datasets/scc",
});

FolderEventThreatDetectionSettingsCustomModule

Section titled “FolderEventThreatDetectionSettingsCustomModule”

Source: src/GCP/SecurityCenter/FolderEventThreatDetectionSettingsCustomModule.ts

A folder-scoped Event Threat Detection custom module.

Custom modules have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. The module id is assigned by the API. Folder and type are identity. Config, enablement, display name, and description update in place.

FolderEventThreatDetectionSettingsCustomModule: Creating a Custom Module

Section titled “FolderEventThreatDetectionSettingsCustomModule: Creating a Custom Module”
const module = yield* GCP.SecurityCenter.FolderEventThreatDetectionSettingsCustomModule(
"BadIp",
{
type: "CONFIGURABLE_BAD_IP",
config: {
metadata: { severity: "LOW" },
ips: ["192.0.2.1"],
},
description: "test bad ip",
},
);

Source: src/GCP/SecurityCenter/FolderMuteConfig.ts

A folder-scoped Security Command Center mute config.

Mute configs have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Mute config id, folder, and type are identity. Filter, description, display name, and expiry update in place.

Mute low-severity findings

const mute = yield* GCP.SecurityCenter.FolderMuteConfig("Low", {
filter: 'severity="LOW"',
description: "mute low findings",
});

Named config on an explicit folder

const mute = yield* GCP.SecurityCenter.FolderMuteConfig("Low", {
folder: "folders/123456789",
muteConfigId: "mute-low",
filter: 'severity="LOW"',
type: "STATIC",
});

Source: src/GCP/SecurityCenter/FolderNotificationConfig.ts

A folder-scoped Security Command Center notification config.

Notification configs have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Config id and folder are identity. Pub/Sub topic, filter, and description update in place.

FolderNotificationConfig: Creating a Notification Config

Section titled “FolderNotificationConfig: Creating a Notification Config”

Stream findings to Pub/Sub

const topic = yield* GCP.PubSub.Topic("SccFindings", {});
const config = yield* GCP.SecurityCenter.FolderNotificationConfig(
"Findings",
{
pubsubTopic: topic.name,
filter: 'state="ACTIVE"',
description: "active findings",
},
);

Named config on an explicit folder

const config = yield* GCP.SecurityCenter.FolderNotificationConfig(
"Findings",
{
folder: "folders/123456789",
configId: "active-findings",
pubsubTopic: "projects/my-project/topics/scc",
},
);

FolderSecurityHealthAnalyticsSettingsCustomModule

Section titled “FolderSecurityHealthAnalyticsSettingsCustomModule”

Source: src/GCP/SecurityCenter/FolderSecurityHealthAnalyticsSettingsCustomModule.ts

A folder-scoped Security Health Analytics custom module.

Custom modules have no labels field — Alchemy stamps ownership into customConfig.description so list / nuke can find them. The module id is assigned by the API. Folder is identity. Display name, custom config, and enablement update in place.

FolderSecurityHealthAnalyticsSettingsCustomModule: Creating a Custom Module

Section titled “FolderSecurityHealthAnalyticsSettingsCustomModule: Creating a Custom Module”
const module = yield* GCP.SecurityCenter.FolderSecurityHealthAnalyticsSettingsCustomModule(
"Unused",
{
customConfig: {
predicate: { expression: 'resource.name == "alchemy-nonexistent"' },
resourceSelector: {
resourceTypes: ["compute.googleapis.com/Instance"],
},
severity: "LOW",
recommendation: "No action required.",
},
},
);

Source: src/GCP/SecurityCenter/MuteConfig.ts

A project-scoped Security Command Center mute config that hides matching findings from the default view.

Mute configs have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Id and type are identity. Filter, description, and expiry update in place.

const mute = yield* GCP.SecurityCenter.MuteConfig("Low", {
filter: 'severity="LOW"',
description: "mute low severity",
});
const mute = yield* GCP.SecurityCenter.MuteConfig("Low", {
filter: 'severity="LOW" OR severity="MEDIUM"',
description: "mute low and medium",
});

Source: src/GCP/SecurityCenter/NotificationConfig.ts

A project-scoped Security Command Center notification config that publishes findings to a Pub/Sub topic.

Notification configs have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Config id is identity. Description, Pub/Sub topic, and streaming filter update in place.

NotificationConfig: Creating a Notification Config

Section titled “NotificationConfig: Creating a Notification Config”
const topic = yield* GCP.PubSub.Topic("SccFindings", {});
const config = yield* GCP.SecurityCenter.NotificationConfig("High", {
pubsubTopic: topic.name,
description: "high severity",
streamingConfig: { filter: 'severity="HIGH"' },
});

NotificationConfig: Updating a Notification Config

Section titled “NotificationConfig: Updating a Notification Config”
const config = yield* GCP.SecurityCenter.NotificationConfig("High", {
pubsubTopic: topic.name,
description: "high and critical",
streamingConfig: { filter: 'severity="HIGH" OR severity="CRITICAL"' },
});

Source: src/GCP/SecurityCenter/OrganizationBigQueryExport.ts

An organization-scoped Security Command Center BigQuery export.

Exports have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Export id and organization are identity. Dataset, filter, and description update in place.

OrganizationBigQueryExport: Creating a BigQuery Export

Section titled “OrganizationBigQueryExport: Creating a BigQuery Export”

Export active findings to a dataset

const dataset = yield* GCP.BigQuery.Dataset("SccFindings", {
location: "US",
forceDestroy: true,
});
const exp = yield* GCP.SecurityCenter.OrganizationBigQueryExport(
"Findings",
{
dataset: `projects/${dataset.project}/datasets/${dataset.datasetId}`,
filter: 'state="ACTIVE"',
description: "active findings",
},
);

Named export on an explicit organization

const exp = yield* GCP.SecurityCenter.OrganizationBigQueryExport(
"Findings",
{
organization: "organizations/123456789",
exportId: "active-findings",
dataset: "projects/my-project/datasets/scc",
},
);

OrganizationEventThreatDetectionSettingsCustomModule

Section titled “OrganizationEventThreatDetectionSettingsCustomModule”

Source: src/GCP/SecurityCenter/OrganizationEventThreatDetectionSettingsCustomModule.ts

An organization-scoped Event Threat Detection custom module.

Custom modules have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. The module id is assigned by the API. Organization and type are identity. Config, enablement, display name, and description update in place.

OrganizationEventThreatDetectionSettingsCustomModule: Creating a Custom Module

Section titled “OrganizationEventThreatDetectionSettingsCustomModule: Creating a Custom Module”
const module = yield* GCP.SecurityCenter.OrganizationEventThreatDetectionSettingsCustomModule(
"BadIp",
{
type: "CONFIGURABLE_BAD_IP",
config: {
metadata: { severity: "LOW" },
ips: ["192.0.2.1"],
},
description: "test bad ip",
},
);

Source: src/GCP/SecurityCenter/OrganizationMuteConfig.ts

An organization-scoped Security Command Center mute config.

Mute configs have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Mute config id, organization, and type are identity. Filter, description, display name, and expiry update in place.

OrganizationMuteConfig: Creating a Mute Config

Section titled “OrganizationMuteConfig: Creating a Mute Config”

Mute low-severity findings

const mute = yield* GCP.SecurityCenter.OrganizationMuteConfig("Low", {
filter: 'severity="LOW"',
description: "mute low findings",
});

Named config on an explicit organization

const mute = yield* GCP.SecurityCenter.OrganizationMuteConfig("Low", {
organization: "organizations/123456789",
muteConfigId: "mute-low",
filter: 'severity="LOW"',
type: "STATIC",
});

Source: src/GCP/SecurityCenter/OrganizationsNotificationConfig.ts

An organization-scoped Security Command Center notification config that publishes findings to a Pub/Sub topic.

Notification configs have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Config id and organization are identity. Description, Pub/Sub topic, and streaming filter update in place.

OrganizationsNotificationConfig: Creating a Notification Config

Section titled “OrganizationsNotificationConfig: Creating a Notification Config”

Publish high-severity findings

const topic = yield* GCP.PubSub.Topic("OrgFindings", {});
const config = yield* GCP.SecurityCenter.OrganizationsNotificationConfig(
"High",
{
pubsubTopic: topic.name,
description: "high severity",
streamingConfig: { filter: 'severity="HIGH"' },
},
);

Named config on an explicit organization

const config = yield* GCP.SecurityCenter.OrganizationsNotificationConfig(
"High",
{
organization: "organizations/123456789",
configId: "high-findings",
pubsubTopic: topic.name,
streamingConfig: { filter: 'severity="HIGH"' },
},
);

OrganizationsSecurityHealthAnalyticsSettingsCustomModule

Section titled “OrganizationsSecurityHealthAnalyticsSettingsCustomModule”

Source: src/GCP/SecurityCenter/OrganizationsSecurityHealthAnalyticsSettingsCustomModule.ts

An organization-scoped Security Health Analytics custom module.

Custom modules have no labels field — Alchemy stamps ownership into customConfig.description so list / nuke can find them. Module id, organization, and display name are identity (the id is server-assigned). Enablement and custom config update in place.

OrganizationsSecurityHealthAnalyticsSettingsCustomModule: Creating a Custom Module

Section titled “OrganizationsSecurityHealthAnalyticsSettingsCustomModule: Creating a Custom Module”

Always-true compute instance check

const module = yield* GCP.SecurityCenter.OrganizationsSecurityHealthAnalyticsSettingsCustomModule(
"AlwaysTrue",
{
displayName: "AlchemyAlwaysTrue",
customConfig: {
predicate: { expression: 'resource.name == "alchemy-nonexistent"' },
resourceSelector: {
resourceTypes: ["compute.googleapis.com/Instance"],
},
severity: "LOW",
description: "always true",
recommendation: "n/a",
},
},
);

Named module on an explicit organization

const module = yield* GCP.SecurityCenter.OrganizationsSecurityHealthAnalyticsSettingsCustomModule(
"AlwaysTrue",
{
organization: "organizations/123456789",
displayName: "AlchemyAlwaysTrue",
customConfig: {
predicate: { expression: 'resource.name == "alchemy-nonexistent"' },
resourceSelector: {
resourceTypes: ["compute.googleapis.com/Instance"],
},
severity: "LOW",
},
},
);

SecurityHealthAnalyticsSettingsCustomModule

Section titled “SecurityHealthAnalyticsSettingsCustomModule”

Source: src/GCP/SecurityCenter/SecurityHealthAnalyticsSettingsCustomModule.ts

A project-scoped Security Health Analytics custom module.

Custom modules have no labels field — Alchemy stamps ownership into customConfig.description so list / nuke can find them. Module id and display name are identity (the id is server-assigned). Enablement and custom config update in place.

SecurityHealthAnalyticsSettingsCustomModule: Creating a Custom Module

Section titled “SecurityHealthAnalyticsSettingsCustomModule: Creating a Custom Module”
const module = yield* GCP.SecurityCenter.SecurityHealthAnalyticsSettingsCustomModule(
"AlwaysTrue",
{
displayName: "AlchemyAlwaysTrue",
customConfig: {
predicate: { expression: 'resource.name == "alchemy-nonexistent"' },
resourceSelector: {
resourceTypes: ["compute.googleapis.com/Instance"],
},
severity: "LOW",
description: "always true",
recommendation: "n/a",
},
},
);

SecurityHealthAnalyticsSettingsCustomModule: Updating a Custom Module

Section titled “SecurityHealthAnalyticsSettingsCustomModule: Updating a Custom Module”
const module = yield* GCP.SecurityCenter.SecurityHealthAnalyticsSettingsCustomModule(
"AlwaysTrue",
{
enablementState: "DISABLED",
displayName: "AlchemyAlwaysTrue",
customConfig: {
predicate: { expression: 'resource.name == "alchemy-nonexistent"' },
resourceSelector: {
resourceTypes: ["compute.googleapis.com/Instance"],
},
severity: "LOW",
},
},
);