Google Cloud Storage Bucket enumerated
이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다.Goal
Detect when a service account lists out GCS Buckets.
Strategy
This rule lets you monitor GCS bucket admin activity audit logs to determine when a service account invokes the following method:
Triage and response
Determine whether this service account should be making list bucket calls.
- If the account was compromised, secure the account and investigate how it was compromised and if the account made other unauthorized calls.
- If the owner of the service account intended to make the
ListBuckets
API call, consider whether this API call is needed. It could cause a security issue for the application to know the name of the bucket it needs to access. If it’s not needed, modify this rule’s filter to stop generating signals for this specific service account.