GCP VPC Firewall Rule Deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Defense Evasion (TA0005)
ATT&CK Technique
Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
Severity
Informational
Description
A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources.
Attacker's Goals
Access restricted resources.
Investigative actions
Check if there were any network attempts that fit the deleted rule.
Check The cloud identity activity prior/after to the rule deletion.
PreviousGCP Virtual Private Network Route Deletion
NextGlobally uncommon high entropy module was loaded
Was this helpful?
