Skip to content

Commit

Permalink
[sync] Add privilege escalation detection in GCP (#47) (#1072)
Browse files Browse the repository at this point in the history
Co-authored-by: Oleh Melenevskyi <[email protected]>
Co-authored-by: Ariel Ropek <[email protected]>
  • Loading branch information
3 people authored Jan 30, 2024
1 parent bbb3b2b commit e1b3b35
Showing 1 changed file with 57 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
AnalysisType: rule
RuleID: "GCP Privilege Escalation By Deployments Create"
DisplayName: "GCP.Privilege.Escalation.By.Deployments.Create"
Description: "Detects privilege escalation in GCP by taking over the deploymentsmanager.deployments.create permission"
Enabled: true
LogTypes:
- GCP.AuditLog
Severity: High
DedupPeriodMinutes: 60
Threshold: 1
Reference: https://rhinosecuritylabs.com/gcp/privilege-escalation-google-cloud-platform-part-1/
Reports:
MITRE ATT&CK:
- TA0004:T1548
Detection:
- All:
- KeyPath: protoPayload.authorizationInfo[*].granted
Condition: Contains
Value: true
- KeyPath: protoPayload.authorizationInfo[*].permission
Condition: Contains
Value: deploymentmanager.deployments.create
Tests:
- Name: privilege-escalation
ExpectedResult: true
Log:
protoPayload:
authorizationInfo:
- granted: true
permission: deploymentmanager.deployments.create
methodName: v2.deploymentmanager.deployments.insert
serviceName: deploymentmanager.googleapis.com
receiveTimestamp: "2024-01-19 13:47:19.465856238"
resource:
labels:
name: test-vm-deployment
project_id: panther-threat-research
type: deployment
severity: NOTICE
timestamp: "2024-01-19 13:47:18.279921000"
- Name: fail
ExpectedResult: false
Log:
protoPayload:
authorizationInfo:
- granted: афдиу
permission: deploymentmanager.deployments.create
methodName: v2.deploymentmanager.deployments.insert
serviceName: deploymentmanager.googleapis.com
receiveTimestamp: "2024-01-19 13:47:19.465856238"
resource:
labels:
name: test-vm-deployment
project_id: panther-threat-research
type: deployment
severity: NOTICE
timestamp: "2024-01-19 13:47:18.279921000"

0 comments on commit e1b3b35

Please sign in to comment.