Skip to content

Commit e1672e8

Browse files
committed
fix(rule/google): changing 'exists(log.protoPayload.request.policy.auditConfigs)' to 'exists(log.protoPayload.request.policy.bindings) to improve detection logic
1 parent 33c8530 commit e1672e8

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

rules/cloud/google/gcp_iam_policy_changed.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,4 +27,4 @@ description: |
2727
where: |
2828
oneof("log.protoPayloadServiceName", ["cloudresourcemanager.googleapis.com", "pubsub.googleapis.com"]) &&
2929
oneof("log.protoPayloadMethodName", ["SetIamPolicy", "google.iam.v1.IAMPolicy.SetIamPolicy"]) &&
30-
exists("log.protoPayload.request.policy.auditConfigs") && contains("log.logName", "activity") && exists("origin.user")
30+
exists("log.protoPayload.request.policy.bindings") && contains("log.logName", "activity") && exists("origin.user")

0 commit comments

Comments
 (0)