GCP Logging Bucket Deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Data Detection & Response, Cloud Log Tampering Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Informational
Description
A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection.
Attacker's Goals
Evade detection.
Investigative actions
Check which logs were affected by the bucket deletion.
Check The cloud identity activity prior/after to the bucket deletion.
Was this helpful?
