Analytics BIOC
Informational
✕
GCP IAM Role Deletion
A GCP IAM role was created. An attacker might use this technique to interrupt users' actions.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- Gcp Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Account Access Removal (T1531)
Attacker's goals:
Inhibit users from accessing resources.
Investigative actions:
Check which users were affected by the role deletion. Check what other actions were taken by the identity that deleted the role.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours