Google Full Network Traffic Packet Capture

 Original Source: [Sigma source]
Title: Google Full Network Traffic Packet Capture
Status: test
Description:Identifies potential full network packet capture in gcp. This feature can potentially be abused to read sensitive data from unencrypted internal traffic.
References:
  -https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging
  -https://developers.google.com/resources/api-libraries/documentation/compute/v1/java/latest/com/google/api/services/compute/Compute.PacketMirrorings.html
Author: Austin Songer @austinsonger
Date: 2021-08-13
modified:2022-10-09
Tags:
  • -'attack.collection'
  • -'attack.t1074'
Logsource:
  • product: gcp
  • service: gcp.audit
Detection:
  selection:
    gcp.audit.method_name:
      -'v*.Compute.PacketMirrorings.Get'
      -'v*.Compute.PacketMirrorings.Delete'
      -'v*.Compute.PacketMirrorings.Insert'
      -'v*.Compute.PacketMirrorings.Patch'
      -'v*.Compute.PacketMirrorings.List'
      -'v*.Compute.PacketMirrorings.aggregatedList'

  condition:selection
Falsepositives:
  -Full Network Packet Capture may be done by a system or network administrator.
  -If known behavior is causing false positives, it can be exempted from the rule.
Level: medium