For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/30a-b8b-80f.md. A documentation index is available at /llms.txt.

Google Cloud Storage Bucket contents downloaded without authentication

Goal

Detect unauthenticated access to an object in a GCS bucket (bucket_name).

Strategy

Monitor GCS bucket (bucket_name) for get requests(@evt.name:storage.objects.get) made by unauthenticated users (@usr.id).

Triage and response

Investigate the logs and determine whether or not the accessed bucket: {{bucket_name}} should be accessible to unauthenticated users.

Changelog

  • 27 October 2022 - updated tags.