M ManySignal
Detection Pack Google Cloud Platform

GCP Detection Pack

58 production-ready detection rules for Google Cloud Audit Logs, Security Command Center, GKE, BigQuery, and Cloud Storage. Full MITRE ATT&CK coverage activated with a single click.

Pack summary

Detection rules
58
Critical severity
16
Data sources
8
ATT&CK techniques
22

What's included

58 rules across 6 threat categories targeting GCP-specific attack patterns.

IAM & Privilege Escalation 16 rules

Service account key abuse, org policy bypass, IAM binding escalation, workload identity attacks.

Data Exfiltration 14 rules

GCS public buckets, BigQuery exposure, Secret Manager access, Cloud SQL export.

Audit & Logging Tampering 8 rules

Log sink deletion, org policy constraint removal, SCC finding suppression.

Compute & Container Abuse 10 rules

GKE cluster-admin binding, Cloud Function deployment, Compute metadata SSRF.

Network & Firewall 6 rules

VPC peering to external projects, firewall all-inbound rules, DNS hijacking.

SCC & Workspace Alerts 4 rules

Security Command Center high-severity findings and Google Workspace admin alerts.

Detection rules (20 of 58 shown)

Showing 20 representative rules. All 58 rules activate with one click.

Rule name Severity
GCP Audit Log Export Sink Deleted Critical
GCP Project IAM Policy Modified — Privilege Escalation Critical
Service Account Key Created by Non-Provisioning Principal High
GCP Organization Policy Constraint Disabled Critical
GCS Bucket Made Publicly Accessible High
Mass GCS Object Download High
GCP Secret Manager Secret Accessed by Unusual Identity High
Compute Instance Metadata Server SSRF Detected Critical
GKE Cluster Admin ClusterRoleBinding Created Critical
GCP Firewall Rule Created to Allow All Inbound Traffic High
Security Command Center High-Severity Finding Critical
GCP VPC Peering Created to External Project High
Cloud Function Deployed with Environment Variable Containing Secret High
GCP Identity-Aware Proxy Policy Removed High
Google Workspace Super Admin Account Used from New Location High
GCP Billing Account Disabled or Modified Medium
Pub/Sub Subscription Created on Sensitive Topic Medium
GCP AI Platform (Vertex AI) Notebook Instance Created Low
Cloud DNS Zone Modified — Hijacking Risk High
BigQuery Dataset Made Public Critical

Prerequisites

  • GCP Audit Log sinks configured to export Admin Activity and Data Access logs to Pub/Sub
  • Security Command Center Standard or Premium tier enabled at organisation level
  • GKE audit logging enabled (API server audit logs forwarded to Cloud Logging)
  • BigQuery Data Access logging enabled for datasets containing sensitive data

GCP Detection Pack: frequently asked questions

What GCP services does this detection pack cover?

The GCP detection pack covers Cloud Audit Logs (Admin Activity and Data Access), Security Command Center findings, Cloud Armor WAF events, Google Kubernetes Engine (GKE) audit logs, Google Workspace Admin/Login audit logs, VPC Flow Logs, and Cloud DNS logs. Admin Activity logs are enabled by default; Data Access logs must be explicitly enabled per service.

How does ManySignal ingest GCP logs?

ManySignal connects to GCP via Pub/Sub log sinks. A log sink is configured in your GCP project or organisation to export filtered audit logs to a Pub/Sub topic. ManySignal's GCP connector subscribes to that topic for real-time ingestion. Backfill is supported via Cloud Logging API.

Does the pack cover GKE workload-level threats?

Yes — GKE Audit Logs (Kubernetes API server events) are ingested for API server-level detections: cluster-admin binding creation, pod exec access to privileged containers, service account token exfiltration, and namespace creation patterns consistent with cluster takeover.

Can this pack detect BigQuery data exfiltration?

Yes. Data Access Logs for BigQuery must be enabled. The pack includes rules for large query result exports, newly authorised external users on sensitive datasets, and BigQuery datasets made public. Data Access logs can be high volume — ManySignal filters to high-signal events.

Does ManySignal support GCP Assured Workloads or sovereign cloud zones?

ManySignal's GCP connector works with standard GCP and Assured Workloads regions. For data residency requirements, the Pub/Sub topic and ManySignal tenant can be configured to retain data within specific regions.

Full GCP threat coverage in minutes

58 GCP detection rules with MITRE ATT&CK mapping, real-time Pub/Sub ingestion, and automated investigation timelines.