Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit

PremiumReviewedSigma · Medium · v1
Product
gcp
Service
gcp.audit
Author
HuntRule
Published
2026-08-23
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Impact

What it detects

This rule detects v1.compute.disks.setIamPolicy operations that modify the IAM policy on a Compute Engine disk. Adversaries bind privileged roles such as roles/owner to an external principal to share a disk out of the victim project for data exfiltration. Granting broad access to a disk resource enables theft of the data stored on it without directly reading the volume.

Related detections9 linkedT1537 — drag to rearrange
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
AWS CloudTrail EC2 CreateInstanceExportTask Failure
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Pivot detection · T1537 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.