diff --git a/plugins/gcpaudit/rules/gcp_auditlog_rules.yaml b/plugins/gcpaudit/rules/gcp_auditlog_rules.yaml index 9694bd3f..62d2a093 100644 --- a/plugins/gcpaudit/rules/gcp_auditlog_rules.yaml +++ b/plugins/gcpaudit/rules/gcp_auditlog_rules.yaml @@ -6,13 +6,6 @@ - name: json version: 0.7.0 -- macro: never_true - condition: (evt.num=0) - -- macro: always_true - condition: (evt.num>=0) - - - macro: is_binded_delta_to_public condition: > gcp.policyDelta contains "ADD" and (gcp.policyDelta contains "allAuthenticatedUsers"