GCP Storage Bucket Permissions Modification
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
File and Directory Permissions Modification (T1222)
Severity
Informational
Description
A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss.
Attacker's Goals
Exfiltrate information.
Investigative actions
Check which data exists in the modified bucket and its classification.
Look for events that involve actions for the bucket data.
Was this helpful?
