Suspicious GCP Log Sink Tampering for Defense Evasion (via gcp)

PremiumReviewedSigma · Medium · v1
Product
gcp
Service
gcp.audit
Author
HuntRule
Published
2026-06-25
Updated
2026-08-28

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects Google Cloud audit-log operations that update, disable, or delete logging sinks and buckets, a defense-evasion tactic used to blind visibility during cloud attacks. Adversaries suppress log export so their subsequent actions are not recorded.

Related detections5 linkedT1685.002 — drag to rearrange
Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
Suspicious AWS CloudTrail Logging Disabled
AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
AWS CloudTrail Trail Stop/Update/Delete Activity
Suspicious GCP Log Sink Tampering for Defense Evasion (via gcp)
Pivot detection · T1685.002 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.