Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
List all activities where data access logging (ADMIN_READ, DATA_READ, or DATA_WRITE) is disabled for GCP services through IAM policy modifications.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Google Cloud Platform Audit Logs |
| ID | 8f3a9b2d-5c6e-4a1f-9d8c-3e7b4f9a6c2d |
| Tactics | DefenseEvasion |
| Techniques | T1562.008 |
| Required Connectors | GCPAuditLogsDefinition |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
GCPAuditLogs |
✓ | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
↑ Back to Hunting Queries · Back to Google Cloud Platform Audit Logs