Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.08 KB

MATCH-S00627.md

File metadata and controls

33 lines (26 loc) · 1.08 KB

Rules: GCP Audit Pub/Sub Subscriber Modified

Description

Detect when a change to a GCP Pub/Sub Subscription has been made. This could stop audit logs from being sent.

Additional Details

Detail Value
Type Templated Match
Category Defense Evasion
Apply Risk to Entities user_username, srcDevice_ip
Signal Name GCP Audit Pub/Sub Subscriber Modified
Summary Expression User: {{user_username}} performed action: {{action}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0006, _mitreAttackTechnique:T1552, _mitreAttackTechnique:T1552.005, _mitreAttackTechnique:T1562, _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1562.008, _mitreAttackTechnique:T1562.001

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema listMatches
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username