This repository was archived by the owner on Sep 16, 2026. It is now read-only.
forked from panther-labs/panther-analysis
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathgcp_audit.yml
More file actions
56 lines (56 loc) · 2.17 KB
/
Copy pathgcp_audit.yml
File metadata and controls
56 lines (56 loc) · 2.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
AnalysisType: pack
PackID: PantherManaged.GCP.Audit
Description: Group of all Google Cloud Platform (GCP) Audit detections
PackDefinition:
IDs:
- GCP.Access.Attempts.Violating.IAP.Access.Controls
- GCP.Access.Attempts.Violating.VPC.Service.Controls
- GCP.BigQuery.Large.Scan
- GCP.Cloud.Storage.Buckets.Modified.Or.Deleted
- GCP.CloudBuild.Potential.Privilege.Escalation
- GCP.Cloudfunctions.Functions.Create
- GCP.Cloudfunctions.Functions.Update
- GCP.Cloud.Run.Service.Created
- GCP.Cloud.Run.Service.Created.FOLLOWED.BY.Set.IAM.Policy
- GCP.Cloud.Run.Set.IAM.Policy
- GCP.Compute.IAM.Policy.Update
- GCP.Destructive.Queries
- GCP.DNS.Zone.Modified.or.Deleted
- GCP.Firewall.Rule.Created
- GCP.Firewall.Rule.Deleted
- GCP.Firewall.Rule.Modified
- GCP.GCS.IAMChanges
- GCP.GCS.Public
- GCP.GKE.Kubernetes.Cron.Job.Created.Or.Modified
- GCP.IAM.CorporateEmail
- GCP.IAM.CustomRoleChanges
- GCP.IAM.OrgFolderIAMChanges
- GCP.iam.roles.update.Privilege.Escalation
- GCP.iam.serviceAccountKeys.create
- GCP.Inbound.SSO.Profile.Created
- GCP.Log.Bucket.Or.Sink.Deleted
- GCP.Logging.Settings.Modified
- GCP.Logging.Sink.Modified
- GCP.Permissions.Granted.to.Create.or.Manage.Service.Account.Key
- GCP.Privilege.Escalation.By.Deployments.Create
- GCP.Project.ExternalUserOwnershipInvite
- GCP.Service.Account.Access.Denied
- GCP.Service.Account.or.Keys.Created
- GCP.serviceusage.apiKeys.create.Privilege.Escalation
- GCP.SQL.ConfigChanges
- GCP.Storage.Hmac.Keys.Create
- GCP.User.Added.to.IAP.Protected.Service
- GCP.VPC.Flow.Logs.Disabled
- GCP.Workforce.Pool.Created.or.Updated
- GCP.Workload.Identity.Pool.Created.or.Updated
- GCP.IAM.serviceAccounts.getAccessToken.Privilege.Escalation
- GCP.IAM.serviceAccounts.signJwt.Privilege.Escalation
- GCP.compute.instances.create.Privilege.Escalation
- GCP.IAM.serviceAccounts.signBlob
# Data model
- Standard.GCP.AuditLog
# Globals used in these rules/policies
- panther_gcp_helpers
- panther_base_helpers
- panther_event_type_helpers
DisplayName: "Panther GCP Audit Pack"