Suspicious Cross-Project Compute Snapshot Creation via GCP Audit

PremiumReviewedSigma · Medium · v1
Product
gcp
Service
gcp.audit
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Defense Evasion → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Impact

What it detects

This rule detects v1.compute.snapshots.insert operations that carry CrossEntityControlAuditMetadata, indicating a snapshot created across project boundaries. Adversaries copy a disk snapshot into an attacker-controlled project to exfiltrate its contents outside the victim environment. Cross-project snapshot movement is a strong indicator of cloud data theft rather than routine backup activity.

Related detections9 linkedT1537 — drag to rearrange
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Possible Azure Storage Ransomware via Customer-Managed Key Encryption
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
Suspicious Cross-Project Compute Snapshot Creation via GCP Audit
Pivot detection · T1537 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.