Analytics BIOC Low

GCP data asset shared public

The GCP data asset was publicly shared.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
Gcp Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562)
Detector tags: Cloud Data Asset Public Exposure Data Detection & Response
Attacker's goals:

The attacker wants to maintain indirect control over the resource. The attacker intends to allow public access, making it harder to detect future activity. Attackers are constantly monitoring for public assets to steal sensitive information.

Investigative actions:

Check if the identity intended to change the state of the data asset to public. Change the access policy for the affected asset. Restrict permissions for the identity if needed.

Test period:
N/A (single event)
Deduplication:
5 Days