2026 Critical Cloud Control Plane Detection: GCP Cloud Shell / Metadata Startup-Script Abuse

Detects suspicious modifications to Google Cloud Platform compute instance metadata, specifically the enabling of serial ports or the addition of startup scripts, which can be leveraged to execute arbitrary commands on a virtual machine. This rule also monitors for the initiation of GCP Cloud Shell environments, which may be used as a platform for further administrative activity.