Analytics BIOC Informational

GCP Storage Bucket deletion

A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Gcp Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Data Destruction (T1485)
Detector tags: Cloud Data Asset Disaster Recovery Risks Data Detection & Response
Attacker's goals:

Data destruction.

Investigative actions:

Check which data was deleted from the bucket.

Test period:
N/A (single event)
Deduplication:
3 Hours
2 variations:
  • First time seen deleting a GCP Storage Bucket containing sensitive data Medium (parent: Informational)
  • GCP Storage Bucket containing sensitive data was deleted Low (parent: Informational)