Detection rules › YARA-L
GCP Cloud Audit Logging Removed From All Services
Detect when GCP Cloud Audit logs are removed from all services at project or organization level. Audit logging helps organizations maintain security and minimize risk.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Defense Impairment |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| GCP | SetIamPolicy |
Rules detecting the same action
These rules filter on the same operation.
Rule body
// Copyright 2024 Google LLC. Licensed under Apache-2.0.
rule gcp_cloud_audit_logging_removed_from_all_services {
meta:
author = "Google Cloud Security"
description = "Detect when GCP Cloud Audit logs are removed from all services at project or organization level. Audit logging helps organizations maintain security and minimize risk."
rule_id = "mr_6ffed437-4666-433f-8ba8-b6043daef4c5"
rule_name = "GCP Cloud Audit Logging Removed From All Services"
mitre_attack_tactic = "Defense Evasion"
mitre_attack_technique = "Impair Defenses: Disable Cloud Logs"
mitre_attack_url = "https://attack.mitre.org/techniques/T1562/008/"
mitre_attack_version = "v14.1"
type = "Alert"
data_source = "GCP Cloud Audit"
platform = "GCP"
severity = "High"
priority = "High"
events:
$gcp.metadata.event_type = "USER_RESOURCE_UPDATE_PERMISSIONS"
$gcp.metadata.log_type = "GCP_CLOUDAUDIT"
$gcp.metadata.product_event_type = "SetIamPolicy"
$gcp.security_result.action = "ALLOW"
$gcp.security_result.detection_fields["action"] = "REMOVE"
$gcp.security_result.detection_fields["SERVICE"] = "allServices"
$gcp.target.resource.attribute.labels["ser_type"] = "type.googleapis.com/google.iam.v1.logging.AuditData"
$gcp.target.application = "cloudresourcemanager.googleapis.com"
outcome:
//Increase risk score if it is organization wide
$risk_score = max(45 +
if($gcp.target.resource.name = /organizations/,30,0)
)
$mitre_attack_tactic = "Defense Evasion"
$mitre_attack_technique = "Impair Defenses: Disable Cloud Logs"
$mitre_attack_technique_id = "T1562.008"
$event_count = count_distinct($gcp.metadata.id)
$network_http_user_agent = array_distinct($gcp.network.http.user_agent)
$principal_ip = array_distinct($gcp.principal.ip)
$principal_ip_country = array_distinct($gcp.principal.ip_geo_artifact.location.country_or_region)
$principal_ip_state = array_distinct($gcp.principal.ip_geo_artifact.location.state)
$principal_user_id = $gcp.principal.user.userid
$principal_user_display_name = $gcp.principal.user.user_display_name
$target_resource_name = $gcp.target.resource.name
$event_name = $gcp.metadata.product_event_type
condition:
$gcp
}
YARA-L rule structure
Condition
Fires when at least one $gcp event.
Events
$gcp
metadata.log_type = "GCP_CLOUDAUDIT"metadata.product_event_type = "SetIamPolicy"security_result.action = "ALLOW"security_result.detection_fields["action"] = "REMOVE"security_result.detection_fields["SERVICE"] = "allServices"target.resource.attribute.labels["ser_type"] = "type.googleapis.com/google.iam.v1.logging.AuditData"target.application = "cloudresourcemanager.googleapis.com"
Outcome
Outcome variables add context to a detection. When the rule generates an alert, $risk_score is displayed with it.
| Field | Expression |
|---|---|
risk_score | max(45 + if($gcp.target.resource.name = /organizations/,30,0) ) |
event_count | count_distinct($gcp.metadata.id) |
network_http_user_agent | array_distinct($gcp.network.http.user_agent) |
principal_ip | array_distinct($gcp.principal.ip) |
principal_ip_country | array_distinct($gcp.principal.ip_geo_artifact.location.country_or_region) |
principal_ip_state | array_distinct($gcp.principal.ip_geo_artifact.location.state) |
principal_user_id | $gcp.principal.user.userid |
principal_user_display_name | $gcp.principal.user.user_display_name |
target_resource_name | $gcp.target.resource.name |
event_name | $gcp.metadata.product_event_type |