Google Cloud Platform Exfiltration: A Threat Hunting Guide
ID: 6319bbf3-abe4-5783-88ff-c0aad08182b8
STIX ID: report--6319bbf3-abe4-5783-88ff-c0aad08182b8
Feed Name: Mitiga
**Executive Summary:** This report describes a GCP-focused data-exfiltration technique where an attacker who compromises a developer account recreates sensitive Compute Images in a project with storage permissions, uses Cloud Build to export images into Cloud Storage, and then copies those objects to an external attacker bucket; the report details relevant log events (e.g., v1.compute.images.insert, storage.objects.create/get/list, ServiceUsage.EnableService), highlights detection gaps in Cloud Storage logging, and recommends mitigations such as VPC Service Controls and organization restriction headers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
