GCP Logging Sink Deletion

Cortex XDR Analytics Alert Reference by Alert name

Product
Cortex XDR
Last date published
2024-06-04
Category
Analytics Alert Reference
Order
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Hours

Required Data

  • Requires:
    • Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Severity

Low

Description

A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination.
An attacker might use this technique to evade detection.

Attacker's Goals

Evade detection.

Investigative actions

  • Check which logs were affected by the deletion.
  • Check the cloud identity activity prior/after to the entity deletion.