GCP Data Access logs: off by default, and other blind spots
Why GCP Data Access audit logs are the usual dead end: off by default, 30-day retention, what goes unseen without them, and what to enable before an incident.
This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.
Why GCP Data Access audit logs are the usual dead end: off by default, 30-day retention, what goes unseen without them, and what to enable before an incident.
A fictional Google Cloud incident investigated end to end: leaked CI key, Owner for a Gmail account, startup-script backdoor, public bucket, deleted log sink.
Use Google Cloud VPC Flow Logs in an investigation: record fields, sampling caveats, egress per external IP, and matching audit-log attacker IPs to VM traffic.
How attackers blind Google Cloud defenders: deleted or redirected log sinks, exclusions, log buckets, Data Access logging removed, SCC alerts. What remains.
Prove or rule out data theft from Cloud Storage and BigQuery: bulk storage.objects.get, public buckets, HMAC keys, cross-project copies, shared disk images.
Detect Compute Engine abuse in Google Cloud audit logs: startup-script backdoors, SSH keys in metadata, OS Login removed, GPU VMs, VM bursts and unused regions.
Read SetIamPolicy audit entries like an investigator: bindingDeltas, Owner granted to Gmail accounts, unknown domains, allUsers, Token Creator, org policies.
A service account key leaked in a repo or CI log? Find its key ID, every IP that used it and what it did via serviceAccountKeyName, then contain it in order.
Analyze Google Cloud audit logs and VPC Flow Logs step by step: export as JSON, drop the files, read the verdict, findings, timeline and remediation checklist.
Admin Activity, Data Access, System Event and Policy Denied audit logs: what each records, retention, the fields that matter, and four ways to export them.
Your Google Cloud project may be compromised. The order of operations: contain the identity, preserve the audit logs, scope with methodNames, then eradicate.
This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.