Skip to content

Conversation

@rahul0216
Copy link
Collaborator

Change(s):

  • Introduces multiple new analytic rules for Google Cloud Platform audit logs, including detection for bulk VM snapshot deletion, DNSSEC disabling, data access logging exemptions, open firewall rule creation, org policy deletion, public storage buckets, and VPC flow logs disabling. Adds hunting queries for data access logging, firewall operations, org policy modifications, and VPN tunnel creation/deletion.

Reason for Change(s):

  • Added new analytical rules and hunting queries

Version Updated:

  • Yes

Testing Completed:

  • Yes

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

Introduces multiple new analytic rules for Google Cloud Platform audit logs, including detection for bulk VM snapshot deletion, DNSSEC disabling, data access logging exemptions, open firewall rule creation, org policy deletion, public storage buckets, and VPC flow logs disabling. Adds hunting queries for data access logging, firewall operations, org policy modifications, and VPN tunnel creation/deletion.
@contentautomationbot
Copy link

Hello how are you I am GitHub bot
😀😀
I see that you changed templates under the detections/analytic rules folder. Did you remember to update the version of the templates you changed?
If not, and if you want customers to be aware that a new version of this template is available, please update the version property of the template you changed.

@v-atulyadav v-atulyadav added the Solution Solution specialty review needed label Jan 15, 2026
@rahul0216 rahul0216 marked this pull request as ready for review January 15, 2026 18:32
@rahul0216 rahul0216 requested review from a team as code owners January 15, 2026 18:32
@rahul0216 rahul0216 added the P0 label Jan 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content-Package P0 Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants