Unusual GCP Event for a User

A machine learning job detected an GCP Audit event that, while not inherently suspicious or abnormal, is being made by a user context that does not normally use the event action. This can be the result of compromised credentials or keys as someone uses a valid account to persist, move laterally, or exfiltrate data.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2025/10/06"
  3integration = ["gcp"]
  4maturity = "production"
  5min_stack_comments = "New job added"
  6min_stack_version = "9.4.0"
  7updated_date = "2026/09/18"
  8
  9[rule]
 10anomaly_threshold = 75
 11author = ["Elastic"]
 12description = """
 13A machine learning job detected an GCP Audit event that, while not inherently suspicious or abnormal, is being made by a
 14user context that does not normally use the event action. This can be the result of compromised credentials or keys as
 15someone uses a valid account to persist, move laterally, or exfiltrate data.
 16"""
 17false_positives = [
 18    """
 19    New or unusual user event activity can be due to manual troubleshooting or reconfiguration; changes in cloud
 20    automation scripts or workflows; adoption of new services; or changes in the way services are used.
 21    """,
 22]
 23from = "now-2h"
 24interval = "15m"
 25license = "Elastic License v2"
 26machine_learning_job_id = "gcp_audit_rare_method_for_a_user_email_ea"
 27name = "Unusual GCP Event for a User"
 28setup = """## Setup
 29
 30This rule requires the installation of associated Machine Learning jobs, as well as data coming in from GCP.
 31
 32### Anomaly Detection Setup
 33
 34Once the rule is enabled, the associated Machine Learning job will start automatically. You can view the Machine Learning job linked under the "Definition" panel of the detection rule. If the job does not start due to an error, the issue must be resolved for the job to commence successfully. For more details on setting up anomaly detection jobs, refer to the [helper guide](https://www.elastic.co/guide/en/kibana/current/xpack-ml-anomalies.html).
 35
 36### GCP Audit logs Integration Setup
 37The Google Cloud Platform (GCP) Audit logs integration allows you to collect logs and metrics from Google Cloud Platform (GCP) with Elastic Agent.
 38
 39#### The following steps should be executed in order to add the Elastic Agent System "Google Cloud Platform (GCP) Audit logs" integration to your system:
 40- Go to the Kibana home page and click “Add integrations”.
 41- In the query bar, search for “Google Cloud Platform (GCP) Audit logs” and select the integration to see more details about it.
 42- Click “Add Google Cloud Platform (GCP) Audit logs".
 43- Configure the integration.
 44- Click “Save and Continue”.
 45- For more details on the integration refer to the [helper guide](https://www.elastic.co/docs/current/integrations/gcp).
 46"""
 47references = ["https://www.elastic.co/guide/en/security/current/prebuilt-ml-jobs.html"]
 48risk_score = 21
 49rule_id = "2e08f34c-691c-497e-87de-5d794a1b2a53"
 50severity = "low"
 51tags = [
 52    "Domain: Cloud",
 53    "Data Source: GCP",
 54    "Data Source: Google Cloud Platform",
 55    "Data Source: GCP Audit Logs",
 56    "Rule Type: ML",
 57    "Rule Type: Machine Learning",
 58    "Resources: Investigation Guide",
 59    "Platform: GCP",
 60]
 61type = "machine_learning"
 62
 63[[rule.threat]]
 64framework = "MITRE ATT&CK"
 65
 66[[rule.threat.technique]]
 67id = "T1078"
 68name = "Valid Accounts"
 69reference = "https://attack.mitre.org/techniques/T1078/"
 70
 71[[rule.threat.technique.subtechnique]]
 72id = "T1078.004"
 73name = "Cloud Accounts"
 74reference = "https://attack.mitre.org/techniques/T1078/004/"
 75
 76[rule.threat.tactic]
 77id = "TA0001"
 78name = "Initial Access"
 79reference = "https://attack.mitre.org/tactics/TA0001/"
 80
 81[[rule.threat]]
 82framework = "MITRE ATT&CK"
 83
 84[[rule.threat.technique]]
 85id = "T1021"
 86name = "Remote Services"
 87reference = "https://attack.mitre.org/techniques/T1021/"
 88
 89[[rule.threat.technique.subtechnique]]
 90id = "T1021.007"
 91name = "Cloud Services"
 92reference = "https://attack.mitre.org/techniques/T1021/007/"
 93
 94[rule.threat.tactic]
 95id = "TA0008"
 96name = "Lateral Movement"
 97reference = "https://attack.mitre.org/tactics/TA0008/"
 98
 99[[rule.threat]]
100framework = "MITRE ATT&CK"
101
102[[rule.threat.technique]]
103id = "T1078"
104name = "Valid Accounts"
105reference = "https://attack.mitre.org/techniques/T1078/"
106
107[[rule.threat.technique.subtechnique]]
108id = "T1078.004"
109name = "Cloud Accounts"
110reference = "https://attack.mitre.org/techniques/T1078/004/"
111
112[rule.threat.tactic]
113id = "TA0003"
114name = "Persistence"
115reference = "https://attack.mitre.org/tactics/TA0003/"
116
117[[rule.threat]]
118framework = "MITRE ATT&CK"
119
120[[rule.threat.technique]]
121id = "T1041"
122name = "Exfiltration Over C2 Channel"
123reference = "https://attack.mitre.org/techniques/T1041/"
124
125[rule.threat.tactic]
126id = "TA0010"
127name = "Exfiltration"
128reference = "https://attack.mitre.org/tactics/TA0010/"
129
130[[rule.threat]]
131framework = "MITRE ATT&CK"
132
133[[rule.threat.technique]]
134id = "T1078"
135name = "Valid Accounts"
136reference = "https://attack.mitre.org/techniques/T1078/"
137
138[[rule.threat.technique.subtechnique]]
139id = "T1078.004"
140name = "Cloud Accounts"
141reference = "https://attack.mitre.org/techniques/T1078/004/"
142
143[rule.threat.tactic]
144id = "TA0005"
145name = "Defense Evasion"
146reference = "https://attack.mitre.org/tactics/TA0005/"

References

Related rules

to-top