This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Aug 15, 2025. It is now read-only.

Repository files navigation

Community Security Analytics (CSA)

Community Security Analytics Logo

As organizations go through the Autonomic Security modernization journey, this repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud. These may assist detection engineers, threat hunters and data governance analysts.

CSA is a set of foundational security analytics designed to provide organizations with a rich baseline of pre-built queries and rules that they can readily use to start analyzing their Google Cloud logs including Cloud Audit logs, VPC Flow logs, DNS logs, and more using cloud-native or third-party analytics tools. The source code is provided as is, without warranty. See Copyright & License below.

Current release include:

The security use cases below are grouped in 6 categories depending on underlying activity type and log sources:

  1. 🚦 Login & Access Patterns
  2. 🔑 IAM, Keys & Secrets Admin Activity
  3. 🏗️ Cloud Provisoning Activity
  4. ☁️ Cloud Workload Usage
  5. 💧 Data Usage
  6. Network Activity

To learn more about the variety of Google Cloud logs, how to enable and natively export these logs to destinations like BigQuery or Google Security Operations for in-depth analytics, refer to Google Cloud Security and access analytics solution guide.

Caution: CSA is not meant to be a comprehensive set of threat detections, but a collection of community-contributed samples to get you started with detective controls. Use CSA in your threat detection and response capabilities (e.g. Security Command Center, Google Security Operations, BigQuery, or third-party SIEM) in conjunction with threat prevention capabilities (e.g. Security Command Center, Cloud Armor, Identity-Aware Proxy and Chrome Enterprise Premium). To learn more about Google’s approach to modern Security Operations, check out the Autonomic Security Operations whitepaper.

Security Analytics Use Cases

Security Monitoring

#Cloud Security ThreatLog SourceAuditDetectATT&CK® Techniques
1
🚦 Login & Access Patterns
1.01Login from a highly-privileged accountWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.02Suspicious login attempt flagged by Google WorkspaceWorkspace Login Audit (Cloud Identity Logs)T1078.004
1.03Excessive login failures from any user identityWorkspace Login Audit (Cloud Identity Logs)T1078.004, T1110
1.10Access attempts violating VPC Service ControlsAudit Logs - PolicyT1078.004, T1537
1.20Access attempts violating IAP (i.e. BeyondCorp) access controlsHTTP(S) LB Logs
1.30Cloud Console accessesAudit Logs - Data AccessT1078.004
2
🔑 IAM, Keys & Secrets Changes
2.02User added to highly-privileged Google GroupWorkspace Admin AuditT1078.004, T1484.001
2.20Permissions granted over a Service AccountAudit Logs - Admin ActivityT1484.002
2.21Permissions granted to impersonate Service AccountAudit Logs - Admin ActivityT1484.002
2.22Permissions granted to create or manage Service Account keysAudit Logs - Admin ActivityT1484.002
2.30Service accounts or keys created by non-approved identityAudit Logs - Admin ActivityT1136.003
2.40User access added (or removed) from IAP-protected HTTPS servicesAudit Logs - Admin ActivityT1484.002
3
🏗️ Cloud Provisioning Activity
3.01Changes made to logging settingsAudit Logs - Admin ActivityT1562.008
3.02Disabling VPC Flows loggingAudit Logs - Admin ActivityT1562.008
3.11Unusual number of firewall rules modified in the last 7 daysAudit Logs - Admin ActivityT1562.007
3.12Firewall rules modified or deleted in the last 24 hrsAudit Logs - Admin ActivityT1562.007
3.13VPN tunnels created or deletedAudit Logs - Admin ActivityT1133
3.14DNS zones modified or deletedAudit Logs - Admin ActivityT1578
3.15Cloud Storage buckets modified or deleted by unfamiliar user identitiesAudit Logs - Admin ActivityT1578
3.20VMs deleted in the last 7 daysAudit Logs - Admin ActivityT1578
3.21Cloud SQL databases created, modified or deletedAudit Logs - Admin ActivityT1578
4
☁️ Cloud Workload Usage
4.01Unusually high API usage by any user identityAudit LogsT1106
4.10Autoscaling usage in the past monthAudit Logs - Admin ActivityT1496
4.11Autoscaling usage per day in the past monthAudit Logs - Admin ActivityT1496
4.20Resource access by certain user identities in the past monthAudit LogsT1106
4.21Resource access by certain user identities in the past month (aggregated by day)Audit LogsT1106
4.30Which users most frequently used LLM models?Audit Logs - Data AccessT1496, AML.T0051, AML.T0057
4.31Usage of LLM models over timeAudit Logs - Data AccessT1496, AML.T0051, AML.T0057
5
💧 Data Usage
5.01Which users most frequently accessed data in the past week?Audit Logs - Data AccessT1530
5.02Which users accessed most amount of data in the past week?Audit Logs - Data AccessT1530
5.03How much data was accessed by each user per day in the past week?Audit Logs - Data AccessT1530
5.04Which users accessed data in a given table in the past month?Audit Logs - Data AccessT1078.004
5.05What tables are most frequently accessed and by whom?Audit Logs - Data AccessT1530
5.06Top 10 queries against BigQuery in the past weekAudit Logs - Data AccessT1530
5.07Any queries doing very large scans?Audit Logs - Data AccessT1530
5.08Any destructive queries or jobs (i.e. update or delete)?Audit LogsT1565.001
5.10Recent data read with granular access and permissions detailsAudit Logs - Data AccessT1074, T1213
5.11Recent dataset activity with granular permissions detailsAudit Logs - Admin ActivityT1074, T1213
5.20Most common data (and metadata) access actions in the past monthAudit Logs - Data AccessT1530
5.30Cloud Storage buckets enumerated by unfamiliar user identitiesAudit Logs - Data AccessT1530
5.31Cloud Storage objects accessed from a new IPAudit Logs - Data AccessT1530
6
Network Activity
6.01Hosts reaching out to many other hosts or ports per hourVPC Flow LogsT1046
6.10Connections from a new IP to an in-scope networkVPC Flow LogsT1018
6.15List all IP addresses with any associated entitiesVPC Flow LogsT1018, T1046
6.20Connections blocked by Cloud ArmorHTTP(S) LB LogsT1071
6.21Log4j 2 vulnerability exploit attemptsHTTP(S) LB LogsT1190
6.22Any remote IP addresses attempting to exploit Log4j 2 vulnerability?HTTP(S) LB LogsT1190
6.23Spring4Shell vulnerability exploit attempts (CVE-2022-22965)HTTP(S) LB LogsT1190
6.30Virus or malware detected by Cloud IDSCloud IDS Threat LogsT1059
6.31Traffic sessions of high severity threats detected by Cloud IDSCloud IDS Threat Logs, Cloud IDS Traffic LogsT1071
6.40Top 10 DNS queried domainsCloud DNS LogsT1071.004

Dataform for CSA on BigQuery

The dataform folder contains the Dataform repo to automate deployment of CSA queries in BigQuery for optimized performance and cost. Use this Dataform repo to operationalize CSA use cases as reports and alerts powered by BigQuery. This Dataform project deploys and orchestrates pre-built ELT pipelines to filter, normalize and model log data leveraging incremental summary tables, lookup tables and views for fast, cost-effective and simpler querying. See underlying README for more details.

CI/CD for CSA on Google Security Operations

The cicd folder contains a set of scripts to help you with storing CSA YARA-L detection rules as code and testing/deploying updates you and your team make in an automated fashion. Whether you use GitHub Actions, Google Cloud Build or Azure DevOps, you can use the corresponding scripts to automatically test and deploy new or modified rules into your Google Security Operations instance. See underlying README for more details.

Support

This is not an officially supported Google product. Queries, rules and other assets in Community Security Analytics (CSA) are community-supported. Please don't hesitate to open a GitHub issue if you have any question or a feature request.

Contributions are also welcome via Github pull requests if you have fixes or enhancements to source code or docs. Please refer to our Contributing guidelines.

Copyright & License

Copyright 2022 Google LLC

Queries, rules and other assets under Community Security Analytics (CSA) are licensed under the Apache license, v2.0. Details can be found in LICENSE file.

About

Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

Topics

Resources

Contributing

Stars

370 stars

Watchers

17 watching

Forks

Releases

Packages

Contributors

Languages