This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Google Full Network Traffic Packet Capture
Original Source:
[Sigma source]
Title:
Google Full Network Traffic Packet Capture
Status:
test
Description:
Identifies potential full network packet capture in gcp. This feature can potentially be abused to read sensitive data from unencrypted internal traffic.
References:
-https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging
-https://developers.google.com/resources/api-libraries/documentation/compute/v1/java/latest/com/google/api/services/compute/Compute.PacketMirrorings.html
Author:
Austin Songer @austinsonger
Date:
2021-08-13
modified:
2022-10-09
Tags:
-'attack.collection'
-'attack.t1074'
Logsource:
product: gcp
service: gcp.audit
Detection:
selection:
gcp.audit.method_name
:
-'v*.Compute.PacketMirrorings.Get'
-'v*.Compute.PacketMirrorings.Delete'
-'v*.Compute.PacketMirrorings.Insert'
-'v*.Compute.PacketMirrorings.Patch'
-'v*.Compute.PacketMirrorings.List'
-'v*.Compute.PacketMirrorings.aggregatedList'
condition
:
selection
Falsepositives:
-Full Network Packet Capture may be done by a system or network administrator.
-If known behavior is causing false positives, it can be exempted from the rule.
Level:
medium