LoFP LoFP / firewall rules being modified or deleted may be performed by a system administrator. verify that the firewall configuration change was expected.

Techniques

Sample rules

Google Cloud Firewall Modified or Deleted

Description

Detects when a firewall rule is modified or deleted in Google Cloud Platform (GCP).

Detection logic

condition: selection
selection:
  gcp.audit.method_name:
  - v*.Compute.Firewalls.Delete
  - v*.Compute.Firewalls.Patch
  - v*.Compute.Firewalls.Update
  - v*.Compute.Firewalls.Insert