
Summary
This detection rule monitors Google Cloud Storage for modifications or deletions of storage buckets. Specifically, it identifies activities performed through the Google Cloud Platform (GCP) audit logs by tracking specific method names that pertain to bucket operations, including 'storage.buckets.delete', 'storage.buckets.insert', 'storage.buckets.update', and 'storage.buckets.patch'. When any of these operations are detected, it raises an alert to signify a potential impact on the data integrity or availability of cloud storage resources. This rule is particularly relevant for ensuring that any unauthorized or unusual changes to storage buckets are promptly investigated, as such actions may indicate malicious activity or misconfiguration leading to data loss or breaches.
Categories
- Cloud
- GCP
Data Sources
- Cloud Service
- Cloud Storage
Created: 2021-08-14