Google Cloud SQL database modified

Goal

Detect when a Google Cloud SQL database has been modified.

Strategy

This rule lets you monitor Google Cloud SQL admin activity audit logs to determine when one of the following methods is invoked:

  • cloudsql.instances.create
  • cloudsql.instances.create
  • cloudsql.users.update

Triage and response

  1. Review the Google Cloud SQL database and ensure it is configured properly with the correct permissions.
PREVIEWING: raul.perezclavero/SDCD-1411-document-full-repo-pathspecs