Impact: Deleted Google Cloud Backup and DR Backup

This document describes a threat finding type in Security Command Center. Threat findings are generated by threat detectors when they detect a potential threat in your cloud resources. For a full list of available threat findings, see Threat findings index .

Overview

Event Threat Detection examines audit logs to detect whether a backup stored in a backup vault has been deleted.

How to respond

To respond to this finding, do the following:

Step 1: Review finding details

  1. Open the Impact: Deleted Google Cloud Backup and DR Backup finding, as detailed in Reviewing findings . The details panel for the finding opens to the Summarytab.
  2. On the Summarytab, review the information in the following sections:
    • What was detected, especially the following fields:
      • Description: information about the detection.
      • Principal subject: a user or service account that has successfully executed an action.
    • Affected resource
      • Resource display name: the project in which the backup frequency was reduced.
    • Related links, especially the following fields:
      • MITRE ATTACK method: link to the MITRE ATT&CK documentation.
      • Logging URI: link to open the Logs Explorer.

Step 2: Research attack and response methods

Contact the owner of the service account in the Principal subjectfield and confirm whether they conducted the action.

What's next

Create a Mobile Website
View Site in Mobile | Classic
Share by: