GCP Bucket permissions modified
Incident Management is now generally available! Incident Management is now generally available!
<  Back to rules search

GCP Bucket permissions modified

gcp

Classification:

compliance

Set up the gcp integration.

Overview

Goal

Detect when permissions have changed on a GCS Bucket.

Strategy

Monitor GCS bucket admin activity audit logs to determine the following method is invoked:

  • storage.setIamPermissions

Triage & Response

  1. Review the bucket permissions and ensure they are not overly permissive.