<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GCP Forensics — Blog</title>
    <link>https://www.gcpforensics.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Sun, 27 Sep 2026 20:44:33 GMT</lastBuildDate>
    <atom:link href="https://www.gcpforensics.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>GCP Data Access logs: off by default, and other blind spots</title>
      <link>https://www.gcpforensics.com/en/blog/data-access-logs-limitations</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/data-access-logs-limitations</guid>
      <description>Why GCP Data Access audit logs are the usual dead end: off by default, 30-day retention, what goes unseen without them, and what to enable before an incident.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>A GCP compromise walkthrough (fictional case study)</title>
      <link>https://www.gcpforensics.com/en/blog/fictional-gcp-compromise-walkthrough</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/fictional-gcp-compromise-walkthrough</guid>
      <description>A fictional Google Cloud incident investigated end to end: leaked CI key, Owner for a Gmail account, startup-script backdoor, public bucket, deleted log sink.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>VPC Flow Logs analysis in GCP: spotting exfiltration</title>
      <link>https://www.gcpforensics.com/en/blog/vpc-flow-logs-exfiltration</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/vpc-flow-logs-exfiltration</guid>
      <description>Use Google Cloud VPC Flow Logs in an investigation: record fields, sampling caveats, egress per external IP, and matching audit-log attacker IPs to VM traffic.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GCP log sink deleted? Detecting defense evasion in logs</title>
      <link>https://www.gcpforensics.com/en/blog/defense-evasion-log-sinks</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/defense-evasion-log-sinks</guid>
      <description>How attackers blind Google Cloud defenders: deleted or redirected log sinks, exclusions, log buckets, Data Access logging removed, SCC alerts. What remains.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GCS and BigQuery exfiltration: evidence in audit logs</title>
      <link>https://www.gcpforensics.com/en/blog/gcs-bigquery-exfiltration</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/gcs-bigquery-exfiltration</guid>
      <description>Prove or rule out data theft from Cloud Storage and BigQuery: bulk storage.objects.get, public buckets, HMAC keys, cross-project copies, shared disk images.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GCP crypto mining and startup-script backdoors: detection</title>
      <link>https://www.gcpforensics.com/en/blog/compute-engine-abuse-startup-scripts-mining</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/compute-engine-abuse-startup-scripts-mining</guid>
      <description>Detect Compute Engine abuse in Google Cloud audit logs: startup-script backdoors, SSH keys in metadata, OS Login removed, GPU VMs, VM bursts and unused regions.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GCP service account impersonation: tracing the chain</title>
      <link>https://www.gcpforensics.com/en/blog/service-account-impersonation</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/service-account-impersonation</guid>
      <description>Trace service account impersonation in Google Cloud audit logs: GenerateAccessToken, SignBlob, serviceAccountDelegationInfo, actAs and Token Creator grants.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SetIamPolicy abuse: finding owner grants and outsiders</title>
      <link>https://www.gcpforensics.com/en/blog/iam-policy-abuse-setiampolicy</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/iam-policy-abuse-setiampolicy</guid>
      <description>Read SetIamPolicy audit entries like an investigator: bindingDeltas, Owner granted to Gmail accounts, unknown domains, allUsers, Token Creator, org policies.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Leaked GCP service account key: how to investigate it</title>
      <link>https://www.gcpforensics.com/en/blog/leaked-service-account-key</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/leaked-service-account-key</guid>
      <description>A service account key leaked in a repo or CI log? Find its key ID, every IP that used it and what it did via serviceAccountKeyName, then contain it in order.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GCP audit logs analysis: step by step in your browser</title>
      <link>https://www.gcpforensics.com/en/blog/analyze-gcp-audit-logs</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/analyze-gcp-audit-logs</guid>
      <description>Analyze Google Cloud audit logs and VPC Flow Logs step by step: export as JSON, drop the files, read the verdict, findings, timeline and remediation checklist.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cloud Audit Logs types explained, and how to export them</title>
      <link>https://www.gcpforensics.com/en/blog/cloud-audit-logs-explained</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/cloud-audit-logs-explained</guid>
      <description>Admin Activity, Data Access, System Event and Policy Denied audit logs: what each records, retention, the fields that matter, and four ways to export them.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Cloud incident response: a compromised project</title>
      <link>https://www.gcpforensics.com/en/blog/google-cloud-incident-response</link>
      <guid isPermaLink="true">https://www.gcpforensics.com/en/blog/google-cloud-incident-response</guid>
      <description>Your Google Cloud project may be compromised. The order of operations: contain the identity, preserve the audit logs, scope with methodNames, then eradicate.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>