GCP Audit Alerts for Google Cloud Storage Bucket Enumeration via Listing APIs

Triggers on GCP audit events indicating Storage bucket listing (storage.buckets.list or listChannels).

FreeReviewedSigma · Low · v5
Product
gcp
Service
gcp.audit
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-08-14
Updated
2026-07-31

What it detects

This rule identifies attempts to enumerate Google Cloud Storage buckets by matching Cloud Audit log events for bucket listing methods. Attackers commonly enumerate accessible buckets to discover targets before attempting access, misconfiguration exploitation, or data discovery. It relies on GCP audit telemetry capturing the API method name for storage bucket listing calls.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.