Analytics BIOC
Informational
✕
GCP Firewall Rule creation
A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Gcp Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
Attacker's goals:
Access restricted resources.
Investigative actions:
Check if there were any network attempts that fit the created rule. Check the cloud identity activity before and after the rule creation.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours