GCP unauthorized user activity
Incident Management is now generally available! Incident Management is now generally available!
<  Back to rules search

GCP unauthorized user activity




Set up the gcp integration.



Detect when unauthorized activity by a user is detected in GCP


Monitor GCP logs and detect when a user account makes an API request and the request returns the status code equal to 7 within the log attribute @data.protoPayload.status.code. The status code 7 indicates the user account did not have permission to make the API call.

Triage & Response

  1. Determine the user who made the unauthorized calls.
  2. Determine if there is a misconfiguration in IAM permissions or whether an attacker has compromised the user account.