A GCP Cloud SQL DB instance was exported from a production account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Data Detection & Response, Cloud Data Asset Exfiltration
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
A GCP Cloud SQL DB instance was exported to a storage bucket. The DB instance was exported from a production account.
Attacker's Goals
Exfiltrate data to an unknown bucket.
Investigative actions
Check the legitimacy of the referenced destination bucket.
Review further logs for the source Cloud DB instance.
Review further actions performed by the identity.
PreviousA domain was added to the trusted domains list
NextA GCP service account was delegated domain-wide authority in Google Workspace
Was this helpful?
