kevmap

Log sources › gcp:audit

gcp:audit

Inverted view: what can be detected if this is the log you have. IaaS, Office Suite, SaaS

11
channels
11
analytics
8
techniques
8
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
API Key Created, OAuth Client Registered DC0010 User Account Modification AN1471 1
Directory API Access DC0013 User Account Metadata AN1618 1
Directory API Access: users.list or groups.list DC0013 User Account Metadata AN0642 1
None DC0064 Command Execution AN0017 1
Write operations to storage DC0055 File Access AN0043 1
admin.googleapis.com DC0067 Logon Session Creation AN1504 1
compute.instances.setMetadata DC0061 File Modification AN0352 1
drive.activity DC0002 User Account Authentication AN1505 1
google.iam.credentials.generateAccessToken / serviceAccountTokenCreator DC0088 Logon Session Metadata AN1348 1
iam.serviceAccounts.keys.create, os-login.sshPublicKeys.add DC0010 User Account Modification AN1470 1
login.event DC0002 User Account Authentication AN1506 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1021.007 Cloud Serviceslateral movement10
T1074 Data Stagedcollection20
T1078.004 Cloud Accountsstealth, persistence, privilege escalation, initial access411
T1087 Account Discoverydiscovery166
T1087.003 Email Accountdiscovery00
T1098.001 Additional Cloud Credentialspersistence, privilege escalation30
T1098.004 SSH Authorized Keyspersistence, privilege escalation01
T1199 Trusted Relationshipinitial access21

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2022-40684Fortinet Multiple Products T1098.004 Mapped
CVE-2022-41082Microsoft Exchange Server T1087 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-53704SonicWall SonicOS T1078.004 T1199 Mapped