For the complete documentation index, see llms.txt. This page is also available as Markdown.

GCP Firewall Rule creation

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Hours

Required Data

Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify System Firewall: Cloud Firewall (T1686.001)

Severity

Informational

Description

A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas.

Attacker's Goals

Access restricted resources.

Investigative actions

  • Check if there were any network attempts that fit the created rule.

  • Check the cloud identity activity before and after the rule creation.

Was this helpful?