Malicious Cloud Storage Destruction by Cloud Build Service Account

PremiumReviewedSigma · Medium · v1
Product
gcp
Service
gcp.audit
Author
HuntRule
Published
2026-05-20
Updated
2026-08-28

ATT&CK techniques

Initial Access → Impact
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

What it detects

This rule detects a Google Cloud Build default service account invoking storage bucket or object deletion which was abused to destroy data by triggering builds that ran attacker controlled steps. Destructive storage operations originating from a cloudbuild or compute default service account rather than a human principal indicate potential data destruction through the Cloud Build pipeline.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Secure Deletion of Free Space via Cipher (via process_creation)
HamsaUpdate Wiper Trigger via F5UPDATER ConfirmDeleteFiles Argument (via process_creation)
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Malicious Scheduled Task Deploying DYNOWIPER Payload (via process_creation)
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Malicious Cloud Storage Destruction by Cloud Build Service Account
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.