logo

An Adventure in Google Cloud threat detection

ID: 857c0e1b-f6a8-5585-b67e-9872173563f9

STIX ID: report--857c0e1b-f6a8-5585-b67e-9872173563f9

Feed Name: Datadog Security Labs

Date Published: 2023-04-24

Date Updated: 2026-04-27

...
...

This post presents practical Google Cloud threat detection techniques aligned to attacker TTPs, including detections for service account key creation (persistence), anomalous GPU-based VM creation for cryptomining, misuse of default service accounts from outside GCP, Cloud SQL export exfiltration to external buckets, SSH key injection via project metadata, and creation of privileged service accounts. It provides example commands (gcloud/Stratus Red Team), representative audit log snippets, and precise log query patterns with enrichment guidance (e.g., IP intelligence, exclusions) to improve detection fidelity and reduce false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.