How Expel goes detection sprinting in Google Cloud
ID: 5caf6ccd-bc2c-52de-94da-32c014d06770
STIX ID: report--5caf6ccd-bc2c-52de-94da-32c014d06770
Feed Name: Expel Blog
Date Published: 2021-08-03
Date Updated: 2026-04-27
Author: Ian Cooper; Christopher Vantine; Sam Lipton
Expel outlines a two-week Google Cloud Platform detection sprint that targets service account impersonation—particularly attacks that deploy multiple cloud functions to capture credentials—by leveraging Admin Activity audit logs and implementing a detection in their Josie engine that flags bursts of unique cloud function deployments within a short window; the post describes their iterative process (ideate, evaluate, create, appreciate), testing and tuning with Datadog, and preparing detections for production with triage guidance and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
