Anomalous data access via possible script tool from service account

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detects when a GCP Compute Engine default service account performs admin write operations using a scripting-tool user agent such as curl, wget, or python-requests.

Strategy

This rule monitors GCP data access audit logs for ADMIN_WRITE operations originating from principals matching the Compute Engine default service account pattern (*-compute@developer.gserviceaccount.com), where the User-Agent header indicates a scripting tool. Default Compute Engine service accounts are often broadly scoped and are therefore frequently targeted by attackers after gaining code execution on a VM instance. The use of raw HTTP clients like curl or python-requests for admin-level API calls is atypical for legitimate applications and suggests post-exploitation tooling or a misconfigured workload performing ADMIN_WRITE priviledged operations.

Triage and Response

  • Determine whether {{@method}} is an expected API call for the workload running on the instance associated with this service account.
  • Review the {{@http.useragent}} value and assess whether the invoking process is a known application component or an unexpected script.
  • Identify the GCP resources targeted by the admin write operation and evaluate the potential impact of the action.
  • Check for other recent API calls from this service account around the same timeframe, and whether any deviate from its normal operation pattern.
  • Investigate whether the Compute Engine instance associated with this service account shows signs of compromise, such as unexpected processes, network connections, and other lateral movement indicators.