stratus-red-team
stratus-red-team copied to clipboard
New technique: GCS Ransomware through individual deletion
What does this PR do?
- add new technique: GCS Ransomware through individual deletion
Similar to AWS S3 ransomware technique but specific to Cloud Storage bucket. Delete each file (and version) on bucket and put ransom note.
Motivation
This technique is developed as part of Grab's purple teaming activity and we want to share it so more people can get the benefit.
Co-authored-by: Satria Ady Pradana [email protected]
Any reference url of the research blog or threat research with the attack tactic?
This is porting of AWS ransomware attack but within GCP. In the references I put the blog post that is related to AWS, but still applicable to GCP.