Google Compute Engine firewall rule modified

Goal

Detect when a firewall rule is created, modified or deleted.

Strategy

Monitor Google Compute Engine activity audit logs to determine when any of the following methods are invoked:

  • v1.compute.firewalls.delete
  • v1.compute.firewalls.insert
  • v1.compute.firewalls.patch

Triage and response

  1. Review the log and role and ensure the permissions are scoped properly.
  2. Review the users associated with the role and ensure they should have the permissions attached to the role.