Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.01 KB

MATCH-S00611.md

File metadata and controls

33 lines (26 loc) · 1.01 KB

Rules: GCP Audit ListQueues

Description

This could indicate that an adversary is attempting to collect information for later attack. When successful, the List Queues event returns all queues that may be valid targets for further probing/attack.

Additional Details

Detail Value
Type Templated Match
Category Discovery
Apply Risk to Entities user_username, srcDevice_ip
Signal Name GCP Audit ListQueues
Summary Expression User: {{user_username}} performed action: {{action}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0043, _mitreAttackTactic:TA0007, _mitreAttackTechnique:T1526

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema description
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username