
Summary
The "Google Full Network Traffic Packet Capture" detection rule is designed to identify instances of potential unauthorized packet captures within Google Cloud Platform (GCP). This rule focuses particularly on activities that leverage the GCP audit log methods associated with packet mirroring. Packet mirroring can be misused to capture and analyze sensitive unencrypted data traveling over internal network traffic, thus posing a significant security risk. By monitoring for specific method names such as `Compute.PacketMirrorings.Get`, `Compute.PacketMirrorings.Delete`, `Compute.PacketMirrorings.Insert`, and others, the rule establishes a detection mechanism that triggers alerts whenever these potentially malicious actions are detected in the audit logs. It is crucial for organizations utilizing GCP to understand the implications of packet mimicking features and to have robust monitoring in place to prevent data breaches from unauthorized access.
Categories
- Cloud
- GCP
Data Sources
- Cloud Service
- Application Log
Created: 2021-08-13