Suspicious Activity GCP
This alert occurs when Lacework FortiCNAPP detects suspicious activity related to one or more Google Cloud identities, but with a lower confidence level than a Potentially Compromised GCP alert.
Why this alert is important
This alert could represent an intrusion in its early stages where Lacework FortiCNAPP has not observed enough of the attacker’s activity to distinguish between that and background behaviors.
Investigation
See Investigation in Potentially Compromised GCP.