Alerts related to data source "Gcp Audit Log".
A Cloud DB instance was exported to an unknown destination
A cloud function was created with an unusual runtime
A cloud identity created or modified a security group
A cloud identity executed an API call from an unusual country
A cloud identity had escalated its permissions
A cloud identity invoked IAM related persistence operations
A cloud identity performed multiple unusual activities
A cloud instance was stopped
A cloud storage configuration was modified
A Command Line Interface (CLI) command was executed from a GCP serverless compute service
A container registry was created or deleted
A GCP Cloud SQL DB instance was exported from a production account
A Kubernetes API operation was successfully invoked by an anonymous user
A Kubernetes cluster role binding was created or deleted
A Kubernetes cluster role was created
A Kubernetes cluster was created or deleted
A Kubernetes ConfigMap was created or deleted
A Kubernetes Cronjob was created
A Kubernetes DaemonSet was created
A Kubernetes dashboard service account was used outside the cluster
A Kubernetes deployment was created
A Kubernetes ephemeral container was created
A Kubernetes namespace was created or deleted
A Kubernetes node service account activity from external IP
A Kubernetes Pod was created with a sidecar container
A Kubernetes Pod was deleted
A Kubernetes ReplicaSet was created
A Kubernetes role binding was created or deleted
A Kubernetes secret was created or deleted
A Kubernetes service account executed an unusual API call
A Kubernetes service account has enumerated its permissions
A Kubernetes service account was created or deleted
A Kubernetes service was created or deleted
A Kubernetes StatefulSet was created
Abnormal Allocation of compute resources in multiple regions
AI model discovery
Allocation of multiple cloud compute resources
An identity accessed a backup cloud storage
An identity accessed a cloud storage for the first time
An identity initiated a download of multiple cloud objects
An identity performed a suspicious download of multiple cloud storage objects
An operation was performed by an identity from a domain that was not seen in the organization
An unusual cloud identity was granted permissions to a BigQuery resource
An unusual read activity of cloud object
BigQuery table or query results exfiltrated to a foreign project
Billing admin role was removed
Cloud access key creation
Cloud activity from a high-risk IP address
Cloud AI agent was modified
Cloud compute instance user data script modification
Cloud compute serial console access
Cloud identity reached a throttling API rate
Cloud impersonation attempt by unusual identity type
Cloud infrastructure enumeration activity
Cloud instance creation attempt
Cloud instance deletion attempt
Cloud Organizational policy was created or modified
Cloud penetration testing tool activity
Cloud resource logging was disabled
Cloud snapshot created or modified
Cloud storage automatic backup disabled
Cloud storage delete protection disabled
Cloud user performed multiple actions that were denied
Compute activity in dormant cloud region
Data exfiltration from cloud database
Deletion of multiple cloud resources
Denied API call by a Kubernetes service account
GCP administrative role granted to a cloud identity
GCP data asset shared public
GCP Firewall Rule creation
GCP Firewall Rule Modification
GCP IAM deny policy creation
GCP IAM Role Deletion
GCP IAM Service Account Key Deletion
GCP Logging Bucket Deletion
GCP logging sink deletion
GCP logging sink modification
GCP Pub/Sub Subscription Deletion
GCP Pub/Sub Topic Deletion
GCP sensitive Cloud Run role granted
GCP sensitive compute role granted
GCP sensitive Deployment Manager role granted
GCP sensitive Functions role granted
GCP sensitive IAM role granted
GCP sensitive role granted to group
GCP sensitive Secret Manager role granted
GCP sensitive storage role granted
GCP Service Account creation
GCP Service Account Deletion
GCP Service Account Disable
GCP service account impersonation attempt
GCP Service Account key creation
GCP set IAM policy activity
GCP Storage Bucket Configuration Modification
GCP Storage Bucket deletion
GCP Storage Bucket Permissions Modification
GCP Virtual Private Cloud (VPC) Network Deletion
GCP Virtual Private Network Route Creation
GCP Virtual Private Network Route Deletion
GCP VPC Firewall Rule Deletion
IAM Enumeration sequence
IAM role was created
Impossible travel by a cloud identity
Kubernetes admission controller activity
Kubernetes cluster events deletion
Kubernetes enumeration activity
Kubernetes network policy modification
Kubernetes Pod Created with host Inter Process Communications (IPC) namespace
Kubernetes Pod created with host process ID (PID) namespace
Kubernetes Pod Created With Sensitive Volume
Kubernetes pod creation from unknown container image registry
Kubernetes pod creation with host network
Kubernetes Privileged Pod Creation
Kubernetes secrets enumeration for the first time
Kubernetes service account activity outside the cluster
Kubernetes vulnerability scanning tool usage
Logging was impaired via external encryption key
ML artifacts destruction
Multi region enumeration activity
Multiple cloud snapshots export
Multiple failed logins from a single IP
Multiple risk indicators for a cloud identity
Network sniffing detected in Cloud environment
New cloud identity created with administrative policy
Potential denial of wallet abusing AI services
Remote usage of an App engine Service Account token
Remote usage of VM Service Account token
Storage enumeration activity
Suspicious AI Dataset Download
Suspicious AI Dataset Label Modification
Suspicious AI model usage from a Tor exit node
Suspicious API call from a Tor exit node
Suspicious cloud compute instance SSH keys modification attempt
Suspicious cloud user data modification attempt followed by VM restart
Suspicious heavy allocation of compute resources - possible mining activity
Suspicious identity downloaded multiple objects from a bucket
Suspicious ML Model Download
Suspicious secrets dump activity
Unusual AI dataset modification
Unusual AI Knowledge Base Modification
Unusual AI model invocation
Unusual AI RAG Knowledge Base Modification
Unusual certificate management activity
Unusual cloud identity impersonation
Unusual cross projects activity
Unusual exec into a Kubernetes Pod
Unusual IAM enumeration activity by a non-user Identity
Unusual Identity and Access Management (IAM) activity
Unusual key management activity
Unusual Kubernetes secret access
Unusual resource modification by newly seen IAM user
Unusual secret management activity
Unusual user-agent for a cloud identity
Was this helpful?