Google Compute Engine network created

gcp

Classification:

attack

이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect when a Google Compute Engine network is created.

Strategy

This rule lets you monitor Google Compute Engine activity audit logs to determine when the following method is invoked to create a new Compute Engine network:

  • beta.compute.networks.insert
  • v*.compute.networks.insert

An attacker could create a compute network with the intention of enabling cryptomining and bypassing networking limitations.

Triage and response

Review the Compute Engine network.

Changelog

  • 17 August 2023 - Updated query to replace attribute @threat_intel.results.subcategory:tor with @threat_intel.results.category:tor.