GCP logging sink deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Log Tampering Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Informational
Description
A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection.
Attacker's Goals
Evade detection by limiting collected data.
Investigative actions
Identify the logs impacted by the deletion.
Review cloud identity activity before and after the deletion.
Variations
Was this helpful?
