Google Cloud Storage Buckets Modified or Deleted
Description
Detects when storage bucket is modified or deleted in Google Cloud.
Query · sigma
selection: gcp.audit.method_name: - storage.buckets.delete - storage.buckets.insert - storage.buckets.update - storage.buckets.patch condition: selection
Known false positives
- Storage Buckets being modified or deleted may be performed by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- Storage Buckets modified or deleted from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.