GCP API calls indicating Compute Engine external IP assignment
ID:gcp_compute_engine_external_ip_assigned
Data type:Google Cloud Platform
Severity:
Informational
- Medium
MITRE ATT&CK:TA0003:T1133
Description
AlphaSOC detected that an external IP address was assigned to a Google Cloud Compute Engine instance. External IPs provide direct internet connectivity to instances. While sometimes required for legitimate purposes, unexpected external IP assignments may indicate an attacker establishing external access for persistence or command and control.
Impact
Assigning an external IP to an instance exposes it directly to the internet, significantly increasing the attack surface. Attackers may use this access to establish persistent backdoors, exfiltrate data, or enable command and control communications. Instances with external IPs are subject to scanning and exploitation attempts from the internet.
Severity
| Severity | Condition |
|---|---|
Informational | External IP assigned to instance |
Low | External IP assigned with anomalous behavioral patterns |
Medium | External IP assigned in suspicious context |