New attack technique: Disable VPC Flow Logs on a Subnet (gcp.defense-evasion.remove-vpc-flow-logs)#794
Merged
christophetd merged 3 commits intomainfrom Apr 8, 2026
Conversation
b50e60b to
bab7a4c
Compare
7d31013 to
52d7f70
Compare
bab7a4c to
cf57c77
Compare
52d7f70 to
cb89728
Compare
cf57c77 to
160d7a2
Compare
cb89728 to
ebe092e
Compare
160d7a2 to
b2b868a
Compare
ebe092e to
9ed6f7f
Compare
c7f3f03 to
fc6b129
Compare
Base automatically changed from
simon.marechal/gcp-defense-evasion-remove-project-from-organization
to
main
April 8, 2026 09:54
…evasion.remove-vpc-flow-logs) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
9ed6f7f to
0949c0a
Compare
christophetd
reviewed
Apr 8, 2026
v2/internal/attacktechniques/gcp/defense-evasion/remove-vpc-flow-logs/main.go
Show resolved
Hide resolved
christophetd
approved these changes
Apr 8, 2026
Contributor
christophetd
left a comment
There was a problem hiding this comment.
Looking good, tested it and working well too
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
New attack technique:
gcp.defense-evasion.remove-vpc-flow-logsMotivation
GCP parity with existing AWS attack techniques.
Test results
stratus detonate gcp.defense-evasion.remove-vpc-flow-logsv1.compute.subnetworks.patchappears in GCP Admin Activity audit logs (no audit log observed — may require non-default DATA_WRITE audit config)Checklist