For the complete documentation index, see llms.txt. This page is also available as Markdown.

GCP Logging Bucket Deletion

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Hours

Required Data

Gcp Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Disaster Recovery Risks, Data Detection & Response, Cloud Log Tampering Analytics

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)

Severity

Informational

Description

A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection.

Attacker's Goals

Evade detection.

Investigative actions

  • Check which logs were affected by the bucket deletion.

  • Check The cloud identity activity prior/after to the bucket deletion.

Was this helpful?