An Adventure in Google Cloud threat detection
ID: 857c0e1b-f6a8-5585-b67e-9872173563f9
STIX ID: report--857c0e1b-f6a8-5585-b67e-9872173563f9
Feed Name: Datadog Security Labs
This post presents practical Google Cloud threat detection techniques aligned to attacker TTPs, including detections for service account key creation (persistence), anomalous GPU-based VM creation for cryptomining, misuse of default service accounts from outside GCP, Cloud SQL export exfiltration to external buckets, SSH key injection via project metadata, and creation of privileged service accounts. It provides example commands (gcloud/Stratus Red Team), representative audit log snippets, and precise log query patterns with enrichment guidance (e.g., IP intelligence, exclusions) to improve detection fidelity and reduce false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
