Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)

PremiumReviewedSigma · Medium · v1
Product
gcp
Service
gcp.audit
Author
HuntRule
Published
2026-05-17
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Impact

What it detects

This rule detects GCP storage bucket deletion operations that enable universal bucket hijacking, where an attacker recreates a same-named bucket in another account to intercept data. This tactic redirects storage transfer, pubsub, and logging outputs to adversary-controlled resources.

Related detections9 linkedT1537 — drag to rearrange
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious EBS Snapshot Shared With External Account via CloudTrail
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Azure Activity Logs: AD Hybrid Health AD FS server instance create/update
Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
AWS CloudTrail EC2 CreateInstanceExportTask Failure
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
Pivot detection · T1537 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.