GCP IAM - Top source IP addresses with failed actions

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Query searches for source IP addresses with top failed actions count.

Attribute Value
Type Hunting Query
Solution GoogleCloudPlatformIAM
ID 2f906618-68e1-49ae-a961-8483cb7b6523
Severity Low
Tactics Discovery
Techniques T1580, T1526
Required Connectors GCPIAMDataConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
GCPIAM ?
GCP_IAM_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to GoogleCloudPlatformIAM