Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 961 Bytes

MATCH-S00713.md

File metadata and controls

34 lines (27 loc) · 961 Bytes

Rules: GCP Instance Deletion

Description

Detects the deletion of an instance in GCP.

Additional Details

Detail Value
Type Templated Match
Category Defense Evasion
Apply Risk to Entities srcDevice_ip, user_username
Signal Name GCP Instance Deletion
Summary Expression GCP Instance Deletion Detected: {{action}} with IP: {{srcDevice_ip}} and User: {{user_username}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1578, _mitreAttackTechnique:T1578.003

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema listMatches
Normalized Schema lower
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username