Detections
- Home
- - Detections
- -DT116
- ID: DT116
- Created: 29th April 2025
- Updated: 29th April 2025
- Platform: Google Cloud Platform (GCP)
- Contributor: The ITM Team
GCP Unauthorized System or Service Modification
Monitor Google Cloud Audit Logs to detect unauthorized creation or modification of compute, storage, and IAM resources. Subjects creating GCP resources without authorization may be staging infrastructure for exfiltration or persistent insider access.
Where to Configure/Access
- Google Cloud Logging (Audit Logs): https://console.cloud.google.com/logs
- Admin Activity Logs Documentation: https://cloud.google.com/logging/docs/audit
Detection Methods
Monitor Admin Activity logs for key methods:
- compute.instances.insert(VMs)
- storage.buckets.create(Buckets)
- compute.disks.insert(Persistent disks)
- iam.serviceAccounts.create(Service Accounts)
Use Log-Based Metrics and Cloud Monitoring alerting for policy violations.
Monitor project and folder-level activity for resource creation.
Indicators
- VMs or services created in unauthorized folders or projects.
- New service accounts with high privileges.
- Missing mandatory labels (environment, owner, compliance status).
Sections
| ID | Name | Description | 
|---|---|---|
| ME028 | Delegated Access via Managed Service Providers | An organization entrusts a Managed Service Provider (MSP) with administrative or operational access to its digital environment - typically for IT support, system maintenance, or development functions. This access is often persistent, privileged, and spans sensitive infrastructure or data environments. 
 The means is established when MSP personnel, including potential subjects, are permitted to authenticate into the client’s environment from systems or networks entirely outside the client's visibility or jurisdiction. These MSP endpoints may be unmanaged, unmonitored, or physically located in regions where customer organization's policies, incident response authority, or legal recourse do not apply. 
 This creates an unobservable access channel: the subject operates from infrastructure beyond the reach of the customer organization's logging, endpoint detection, or identity correlation. The organization is therefore unable to monitor or verify who accessed what, when, or from where—rendering all downstream actions unauditable by the customer organization's internal security teams, unless mirrored within the client-controlled environment. 
 The exposure can be compounded by the MSP’s internal controls (or lack thereof). Weak credential custody practices, shared administrative accounts, inadequate background checks, or poor workforce segmentation create conditions where privileged misuse or unauthorized access can occur without attribution or immediate detection. The subject does not require escalation—they begin with sanctioned access and operate under delegated trust, often without the constraints applied to internal staff. 
 This structural dependency - privileged access held externally, without enforceable oversight - creates the necessary conditions for an insider infringement to occur with low risk of interruption or accountability. | 
| IF009.006 | Installing Crypto Mining Software | The subject installs and operates unauthorized cryptocurrency mining software on organizational systems, leveraging compute, network, and energy resources for personal financial gain. This activity subverts authorized system use policies, degrades operational performance, increases attack surface, and introduces external control risks. 
 Characteristics
 
 Example ScenarioA subject installs a customized  | 
| IF027.005 | Destructive Malware Deployment | The subject deploys destructive malware; software designed to irreversibly damage systems, erase data, or disrupt operational availability. Unlike ransomware, which encrypts files to extort payment, destructive malware is deployed with the explicit intent to delete, corrupt, or disable systems and assets without recovery. Its objective is disruption or sabotage, not necessarily for direct financial gain. 
 This behavior may include: 
 
 
 Insiders may deploy destructive malware as an act of retaliation (e.g. prior to departure), sabotage (e.g. to disrupt an investigation or competitor), or under coercion. Detonation may be manual or scheduled, and in some cases the malware is disguised as routine tooling to delay detection. 
 Destructive deployment is high-severity and often coincides with forensic tampering or precursor access based infringements (e.g. file enumeration or backup deletion). |