Back
Idd1fe8d30-4852-463a-b6ee-3b459788b75d
RulenameGCP Security Command Center - Detect Resources with Logging Disabled
DescriptionDetects Google Cloud resources where logging is disabled for services like (Cloud Storage buckets, Firewall rules, Cloud DNS networks) based on Google Cloud Security Command Center findings.
SeverityMedium
TacticsDefenseEvasion
TechniquesT1562
Required data connectorsGoogleSCCDefinition
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Cloud%20Platform%20Security%20Command%20Center/Analytic%20Rules/GCPLoggingDisabled.yaml
Version1.0.0
Arm templated1fe8d30-4852-463a-b6ee-3b459788b75d.json
Deploy To Azure
GoogleCloudSCC
| where tostring(Findings.state) == "ACTIVE"
| extend FindingCategory = tostring(Findings.category)
| where FindingCategory in ("BUCKET_LOGGING_DISABLED", "FIREWALL_RULE_LOGGING_DISABLED", "DNS_LOGGING_DISABLED")
| extend FindingsJson = parse_json(Findings)
| extend Resource = tostring(FindingsJson.resourceName),
         ExternalUri = tostring(FindingsJson.externalUri),
         Description = tostring(FindingsJson.description),
         Severity = tostring(FindingsJson.severity),
         ProjectName = extract(@"projects/([^/]+)", 1, tostring(FindingsJson.resourceName)),
         ResourceType = extract(@"//([a-z0-9_.-]+)/", 1, tostring(FindingsJson.resourceName)),
         SourceProps = parse_json(tostring(FindingsJson.sourceProperties))
// Normalize display-friendly resource id
| extend ResourceName = case(
    Resource contains "firewalls/", extract(@"firewalls/([^/]+)", 1, Resource),
    Resource contains "storage.googleapis.com/", extract(@'storage.googleapis.com/([^/\"]+)', 1, Resource),
    Resource contains "networks/", extract(@"networks/([^/]+)", 1, Resource),
    Resource
  )
| project TimeGenerated, ProjectName, ResourceType, ResourceName, Resource, FindingCategory, Severity, ExternalUri, Description
name: GCP Security Command Center - Detect Resources with Logging Disabled
triggerOperator: gt
query: |
  GoogleCloudSCC
  | where tostring(Findings.state) == "ACTIVE"
  | extend FindingCategory = tostring(Findings.category)
  | where FindingCategory in ("BUCKET_LOGGING_DISABLED", "FIREWALL_RULE_LOGGING_DISABLED", "DNS_LOGGING_DISABLED")
  | extend FindingsJson = parse_json(Findings)
  | extend Resource = tostring(FindingsJson.resourceName),
           ExternalUri = tostring(FindingsJson.externalUri),
           Description = tostring(FindingsJson.description),
           Severity = tostring(FindingsJson.severity),
           ProjectName = extract(@"projects/([^/]+)", 1, tostring(FindingsJson.resourceName)),
           ResourceType = extract(@"//([a-z0-9_.-]+)/", 1, tostring(FindingsJson.resourceName)),
           SourceProps = parse_json(tostring(FindingsJson.sourceProperties))
  // Normalize display-friendly resource id
  | extend ResourceName = case(
      Resource contains "firewalls/", extract(@"firewalls/([^/]+)", 1, Resource),
      Resource contains "storage.googleapis.com/", extract(@'storage.googleapis.com/([^/\"]+)', 1, Resource),
      Resource contains "networks/", extract(@"networks/([^/]+)", 1, Resource),
      Resource
    )
  | project TimeGenerated, ProjectName, ResourceType, ResourceName, Resource, FindingCategory, Severity, ExternalUri, Description
queryFrequency: 1h
description: |
  Detects Google Cloud resources where logging is disabled for services like (Cloud Storage buckets, Firewall rules, Cloud DNS networks) based on Google Cloud Security Command Center findings.
id: d1fe8d30-4852-463a-b6ee-3b459788b75d
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
customDetails:
  Severity: Severity
  Description: Description
  ExternalUri: ExternalUri
  ProjectName: ProjectName
  FindingCategory: FindingCategory
  ResourceType: ResourceType
status: Available
tags:
- Logging
- GCP
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: Medium
requiredDataConnectors:
- connectorId: GoogleSCCDefinition
  dataTypes:
  - GoogleCloudSCC
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Cloud%20Platform%20Security%20Command%20Center/Analytic%20Rules/GCPLoggingDisabled.yaml
alertDetailsOverride:
  alertDescriptionFormat: 'Resource {{ResourceName}} in project {{ProjectName}} (type: {{ResourceType}}) has logging disabled.'
  alertDisplayNameFormat: 'GCP resources with logging disabled: {{ProjectName}} ({{ResourceType}})'
relevantTechniques:
- T1562
tactics:
- DefenseEvasion
entityMappings:
- fieldMappings:
  - identifier: Name
    columnName: ResourceName
  entityType: CloudApplication
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/d1fe8d30-4852-463a-b6ee-3b459788b75d')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/d1fe8d30-4852-463a-b6ee-3b459788b75d')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "Resource {{ResourceName}} in project {{ProjectName}} (type: {{ResourceType}}) has logging disabled.",
          "alertDisplayNameFormat": "GCP resources with logging disabled: {{ProjectName}} ({{ResourceType}})"
        },
        "alertRuleTemplateName": "d1fe8d30-4852-463a-b6ee-3b459788b75d",
        "customDetails": {
          "Description": "Description",
          "ExternalUri": "ExternalUri",
          "FindingCategory": "FindingCategory",
          "ProjectName": "ProjectName",
          "ResourceType": "ResourceType",
          "Severity": "Severity"
        },
        "description": "Detects Google Cloud resources where logging is disabled for services like (Cloud Storage buckets, Firewall rules, Cloud DNS networks) based on Google Cloud Security Command Center findings.\n",
        "displayName": "GCP Security Command Center - Detect Resources with Logging Disabled",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "CloudApplication",
            "fieldMappings": [
              {
                "columnName": "ResourceName",
                "identifier": "Name"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Google%20Cloud%20Platform%20Security%20Command%20Center/Analytic%20Rules/GCPLoggingDisabled.yaml",
        "query": "GoogleCloudSCC\n| where tostring(Findings.state) == \"ACTIVE\"\n| extend FindingCategory = tostring(Findings.category)\n| where FindingCategory in (\"BUCKET_LOGGING_DISABLED\", \"FIREWALL_RULE_LOGGING_DISABLED\", \"DNS_LOGGING_DISABLED\")\n| extend FindingsJson = parse_json(Findings)\n| extend Resource = tostring(FindingsJson.resourceName),\n         ExternalUri = tostring(FindingsJson.externalUri),\n         Description = tostring(FindingsJson.description),\n         Severity = tostring(FindingsJson.severity),\n         ProjectName = extract(@\"projects/([^/]+)\", 1, tostring(FindingsJson.resourceName)),\n         ResourceType = extract(@\"//([a-z0-9_.-]+)/\", 1, tostring(FindingsJson.resourceName)),\n         SourceProps = parse_json(tostring(FindingsJson.sourceProperties))\n// Normalize display-friendly resource id\n| extend ResourceName = case(\n    Resource contains \"firewalls/\", extract(@\"firewalls/([^/]+)\", 1, Resource),\n    Resource contains \"storage.googleapis.com/\", extract(@'storage.googleapis.com/([^/\\\"]+)', 1, Resource),\n    Resource contains \"networks/\", extract(@\"networks/([^/]+)\", 1, Resource),\n    Resource\n  )\n| project TimeGenerated, ProjectName, ResourceType, ResourceName, Resource, FindingCategory, Severity, ExternalUri, Description\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "DefenseEvasion"
        ],
        "tags": [
          "Logging",
          "GCP"
        ],
        "techniques": [
          "T1562"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}