Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1686 ✕
Download CSV Show ATT&CK heatmapGCP Firewall Rule Modification Informational Cloud
A GCP firewall rule was modified. An attacker might use this technique to access restricted resources.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 3 Hours
ATT&CK tactics: Defense Impairment (TA0112)ATT&CK techniques: Disable or Modify System Firewall: Cloud Firewall (T1686.001)Required data: Gcp Audit LogAttacker's goals: Access restricted resources.Investigative actions: Check if there were any network attempts that fit the deleted rule. Check The cloud identity activity prior/after to the rule deletion.