GCP IAM deny policy creation
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Account Access Removal (T1531)
Severity
Low
Description
An identity created a GCP IAM deny policy.
Attacker's Goals
Interrupt availability of cloud resources by inhibiting access to accounts utilized by legitimate users.
Investigative actions
Examine the details of the created deny policy.
Review the recent activity of the identity.
Variations
Was this helpful?
