Analytics BIOC
Informational
✕
GCP Firewall Rule Modification
A GCP firewall rule was modified. An attacker might use this technique to access restricted resources.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Gcp Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
Attacker's goals:
Access restricted resources.
Investigative actions:
Check if there were any network attempts that fit the deleted rule. Check The cloud identity activity prior/after to the rule deletion.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours