GCP unauthorized user activity
<  Back to rules search

GCP unauthorized user activity





Detect when unauthorized activity by a user is detected in GCP


Monitor GCP logs and detect when a user account makes an API request and the request returns the status code equal to 7 within the log attribute @data.protoPayload.status.code. The status code 7 indicates the user account did not have permission to make the API call.

Triage and response

  1. Determine the user who made the unauthorized calls.
  2. Determine if there is a misconfiguration in IAM permissions or whether an attacker has compromised the user account.