Analytics BIOC Low

A Command Line Interface (CLI) command was executed from a GCP serverless compute service

A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Steal Application Access Token (T1528) Unsecured Credentials (T1552)
Detector tags: Cloud Serverless Function Credentials Theft Analytics
Attacker's goals:

Exfiltrate serverless token and abuse it.

Investigative actions:

Verify whether the serverless-attached identity's credentials were intentionally used in CLI. Check what CLI commands were executed using the serverless attached token. Check if the suspected serverless function is compromised.

Test period:
N/A (single event)
Deduplication:
5 Days
4 variations:
  • Suspicious Command Line Interface (CLI) command was executed from a GCP Cloud Build service Low
  • Suspicious Command Line Interface (CLI) command was executed from a GCP serverless compute service Informational (parent: Low)
  • A Command Line Interface (CLI) command was executed from a GCP Cloud Build service Low
  • Unusual Command Line Interface (CLI) command was executed from a GCP serverless compute service Medium (parent: Low)