Platform / product
gcp Sigma detection rules
26 community-maintained Sigma detection rules in the library target the gcp platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
GCP Access Policy Deleted
mediumDetects when an access policy that is applied to a GCP cloud resource is deleted. An adversary would be able to remove access policies to gain access to a GCP cloud resource.
gcp · gcp.audit
GCP Break-glass Container Workload Deployed
mediumDetects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.
gcp · gcp.audit
Google Cloud DNS Zone Modified or Deleted
mediumIdentifies when a DNS Zone is modified or deleted in Google Cloud.
gcp · gcp.audit
Google Cloud Firewall Modified or Deleted
mediumDetects when a firewall rule is modified or deleted in Google Cloud Platform (GCP).
gcp · gcp.audit
Google Cloud Kubernetes Admission Controller
mediumIdentifies when an admission controller is executed in GCP Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
gcp · gcp.audit
Google Cloud Kubernetes CronJob
mediumIdentifies when a Google Cloud Kubernetes CronJob runs in Azure Cloud. Kubernetes Job is a controller that creates one or more pods and ensures that a specified number of them successfully terminate. Kubernetes Job can be used to run containers that perform finite tasks for batch jobs. Kubernetes CronJob is used to schedule Jobs. An Adversary may use Kubernetes CronJob for scheduling execution of malicious code that would run as a container in the cluster.
gcp · gcp.audit
Google Cloud Kubernetes RoleBinding
mediumDetects the creation or patching of potential malicious RoleBinding. This includes RoleBindings and ClusterRoleBinding.
gcp · gcp.audit
Google Cloud Kubernetes Secrets Modified or Deleted
mediumIdentifies when the Secrets are Modified or Deleted.
gcp · gcp.audit
Google Cloud Re-identifies Sensitive Information
mediumIdentifies when sensitive information is re-identified in google Cloud.
gcp · gcp.audit
Google Cloud Service Account Disabled or Deleted
mediumIdentifies when a service account is disabled or deleted in Google Cloud.
gcp · gcp.audit
Google Cloud Service Account Modified
mediumIdentifies when a service account is modified in Google Cloud.
gcp · gcp.audit
Google Cloud SQL Database Modified or Deleted
mediumDetect when a Cloud SQL DB has been modified or deleted.
gcp · gcp.audit
Google Cloud Storage Buckets Modified or Deleted
mediumDetects when storage bucket is modified or deleted in Google Cloud.
gcp · gcp.audit
Google Cloud VPN Tunnel Modified or Deleted
mediumIdentifies when a VPN Tunnel Modified or Deleted in Google Cloud.
gcp · gcp.audit
Google Full Network Traffic Packet Capture
mediumIdentifies potential full network packet capture in gcp. This feature can potentially be abused to read sensitive data from unencrypted internal traffic.
gcp · gcp.audit
Google Workspace Application Access Level Modified
mediumDetects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.
gcp · google_workspace.admin
Google Workspace Application Removed
mediumDetects when an an application is removed from Google Workspace.
gcp · google_workspace.admin
Google Workspace Government Attack Warning
mediumDetects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor
gcp · google_workspace.login
Google Workspace Granted Domain API Access
mediumDetects when an API access service account is granted domain authority.
gcp · google_workspace.admin
Google Workspace MFA Disabled
mediumDetects when multi-factor authentication (MFA) is disabled.
gcp · google_workspace.admin
Google Workspace Out Of Domain Email Forwarding
mediumDetects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.
gcp · google_workspace.login
Google Workspace Role Modified or Deleted
mediumDetects when an a role is modified or deleted in Google Workspace.
gcp · google_workspace.admin
Google Workspace Role Privilege Deleted
mediumDetects when an a role privilege is deleted in Google Workspace.
gcp · google_workspace.admin
Google Workspace User Granted Admin Privileges
mediumDetects when an Google Workspace user is granted admin privileges.
gcp · google_workspace.admin
Suspicious Login Activity Classified By Google
mediumDetects Google Workspace login activity that's classified as suspicious by Google.
gcp · google_workspace.login
Google Cloud Storage Buckets Enumeration
lowDetects when storage bucket is enumerated in Google Cloud.
gcp · gcp.audit