↳ GitHub sourceAnalytics ruleMedium

Cross-Cloud Suspicious user activity observed in GCP Envourment

Description

'This detection query aims to correlate potentially suspicious user activities logged in Google Cloud Platform (GCP) Audit Logs with security alerts originating from Microsoft Security products. This correlation facilitates the identification of potential cross-cloud security incidents. By summarizing these findings, the query provides valuable insights into cross-cloud identity threats and their associated details, enabling organizations to respond promptly and mitigate potential risks effectively.'
Rule type
Scheduled
Version
1.0.2
Query frequency
1d
Query period
1d
Trigger
gt 0

Declared MITRE coverage

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Connectors

Data types

KQL query

Original query, unchanged.

// Filter GCP Audit Logs to exclude service accounts
GCPAuditLogs 
| where PrincipalEmail !endswith "gserviceaccount.com"
// Exclude system-related authentication information
| where AuthenticationInfo !has ("system:")
// Extract GCP request name and relevant attributes
| extend GCPRequestName= parse_json(Request).name
| extend
    GCPAccoutType= tostring(split(GCPRequestName, "/")[2]),
    GCPUserIdentity = iff(isempty(tostring(split(GCPRequestName, "/")[3])), tostring(parse_json(AuthenticationInfo).principalEmail), "na"), 
    GCPUserIp = tostring(parse_json(RequestMetadata).callerIp),
    GCPCallerUA = tostring(parse_json(RequestMetadata).callerSuppliedUserAgent)
// Filter out empty or service account identities
| where isnotempty(GCPUserIdentity) and GCPUserIdentity !endswith "gserviceaccount.com"
// Select relevant attributes for further analysis
| project
    PrincipalEmail,
    GCPUserIdentity,
    GCPAccoutType,
    GCPRequestName,
    GCPCallerUA,
    Request,
    RequestMetadata,
    GCPUserIp,
    MethodName,
    ServiceName,
    GCPEventTime= TimeGenerated,
    ProjectId
// Join GCP Audit Logs with SecurityAlert data based on user identity and IP
| join kind=inner (    
    SecurityAlert 
    // Exclude alerts from Azure Sentinel
    | where ProductName !in ("Azure Sentinel")
    // Extract IP entities from alert data
    | extend AlertIPEntity=  tostring(extract(@"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}", 0, Entities))
    | extend
        AlertUserUPN = tostring(extract(@'\b[\w\.\-]+@[\w\.\-]+\b', 0, Entities)),
        AlertTime= TimeGenerated
    // Filter out empty user identities and IP entities
    | where isnotempty(AlertIPEntity) and isnotempty(AlertUserUPN)
    )
    on $left.GCPUserIdentity == $right.AlertUserUPN and $left.GCPUserIp == $right.AlertIPEntity
// Summarize the data, calculating time differences and aggregating attributes
| summarize
    FirstAlert=min(AlertTime),
    LastAlert=max(AlertTime),
    TimeDiff=datetime_diff('minute', min(AlertTime), min(GCPEventTime)),
    MethodName=make_set(MethodName),
    ServiceName= make_set(ServiceName),
    GCPProjctId=make_set(ProjectId),
    Request=make_set(Request),
    GCPCallerUA=make_set(GCPCallerUA)
    by
    AlertUserUPN,
    AlertIPEntity,
    GCPUserIp,
    GCPUserIdentity,
    AlertSeverity,
    AlertName,
    AlertLink,
    Description,
    Tactics,
    ProductName,
    SystemAlertId,
    GCPAccoutType
// Extend the data with additional attributes
| extend
    Name = tostring(split(GCPUserIdentity, "@")[0]),
    UPNSuffix = tostring(split(GCPUserIdentity, "@")[1])

Declared entities

IPAccount

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
58e306fe-1c49-4b8f-9b0e-15f25e8f0cd7
Additional source files 2Solutions/Multi Cloud Attack Coverage Essentials - Resource Abuse/Analytic Rules/CrossCloudSuspiciousUserActivityObservedInGCPEnvourment.yamlsource ↗Solutions/Multi Cloud Attack Coverage Essentials - Resource Abuse/Data/Solution_Multi Cloud Attack Coverage Essentials - Resource Abuse.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.