Detect New Open GCP Storage Buckets

Description

This search looks for GCP PubSub events where a user has created an open/public GCP Storage bucket.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Security Monitoring

Category

Adversary Tactics

Alert Volume

This search looks for GCP PubSub events where a user has created an open/public GCP Storage bucket.

SPL Difficulty

None

Journey

Stage 3

MITRE ATT&CK Tactics

Collection

MITRE ATT&CK Techniques

Data from Cloud Storage Object

Data from Cloud Storage Object

Data Sources

GCP
Audit Trail

   Help

Detect New Open GCP Storage Buckets Help

This search relies on the Splunk Add-on for Google Cloud Platform, setting up a Cloud Pub/Sub input, along with the relevant GCP PubSub topics and logging sink to capture GCP Storage Bucket events (https://cloud.google.com/logging/docs/routing/overview).

   Search

Open in Search