Analytics BIOC
Low
✕
A Command Line Interface (CLI) command was executed from a GCP serverless compute service
A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Steal Application Access Token (T1528) Unsecured Credentials (T1552)
Detector tags: Cloud Serverless Function Credentials Theft Analytics
Attacker's goals:
Exfiltrate serverless token and abuse it.
Investigative actions:
Verify whether the serverless-attached identity's credentials were intentionally used in CLI. Check what CLI commands were executed using the serverless attached token. Check if the suspected serverless function is compromised.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
4 variations:
- Suspicious Command Line Interface (CLI) command was executed from a GCP Cloud Build service Low
- Suspicious Command Line Interface (CLI) command was executed from a GCP serverless compute service Informational (parent: Low)
- A Command Line Interface (CLI) command was executed from a GCP Cloud Build service Low
- Unusual Command Line Interface (CLI) command was executed from a GCP serverless compute service Medium (parent: Low)