Clankerusecase
GCP detection coverage
← Back to main site
Home/ Targets/ GCP

GCP detections

Clankerusecase tracks 15 detection use cases covering the GCP attack surface across 16 MITRE ATT&CK techniques.

Detections targeting Google Cloud Platform — Cloud Audit Logs, IAM, Compute, GKE.

Open Detection Library → View on the matrix
15Use cases
16Techniques
3Articles
5Kill-chain phases

Top techniques on GCP (16)

Delivery (1)

[LLM] Vertex AI model upload to default predictable staging bucket (bucket-squat exposure) Bespoke delivery · hunting ΣPDD

Exploitation (1)

[LLM] Vertex AI model deployment following default-staged upload (poisoned-model deploy) Bespoke exploit · hunting PDD

Installation (6)

GCP project external principal added as owner Internal install · alerting DD GCP Compute Engine firewall rule modified Internal install · alerting DD GCP custom IAM role created Internal install · alerting DD GCP Cloud Logging bucket deleted Internal install · alerting DD GCP Cloud Logging sink modified Internal install · alerting DD GCP Cloud Storage bucket permissions modified Internal install · alerting DD

Command & Control (1)

[LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD

Actions on Objectives (6)

GCP service-account key created Internal actions · alerting DD Detect New Open GCP Storage Buckets ESCU actions · alerting P gcp detect oauth token abuse ESCU actions · hunting P GCP Kubernetes cluster scan detection ESCU actions · alerting P [LLM] GCS bucket deletion of a logging-sink / data-stream destination (bucket-hijack precursor) Bespoke actions · hunting ΣPDD [LLM] Foreign / non-Vertex principal accessing Vertex AI staging-bucket objects Bespoke actions · hunting ΣPDD

Recent articles citing GCP-targeted detections