heroui logo

Google Cloud Re-identifies Sensitive Information

Sigma Rules

View Source
Summary
This rule is designed to detect instances where sensitive information is re-identified in Google Cloud using the DLP (Data Loss Prevention) APIs. The detection condition is triggered by the audit logs from Google Cloud when the 'projects.content.reidentify' method is called. The identification of re-identified sensitive information is crucial for organizations aiming to enforce their data security and compliance policies. By monitoring for this specific method usage in audit logs, security teams can proactively respond to potential data exposure or mismanagement of sensitive information. This rule may return false positives, as the conditions for re-identification could be met in scenarios that do not pose a threat, labeled as 'Unknown'. Overall, maintaining vigilance when dealing with sensitive information in cloud environments is paramount to preventing data leaks and ensuring user privacy.
Categories
  • Cloud
  • GCP
Data Sources
  • Cloud Service
  • Application Log
Created: 2021-08-15