Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.

Series

Google Cloud IR foundations

5 posts in this series. Read them in order or jump to any one.

  1. Google Cloud incident response: a compromised project

    Your Google Cloud project may be compromised. The order of operations: contain the identity, preserve the audit logs, scope with methodNames, then eradicate.

  2. Cloud Audit Logs types explained, and how to export them

    Admin Activity, Data Access, System Event and Policy Denied audit logs: what each records, retention, the fields that matter, and four ways to export them.

  3. GCP audit logs analysis: step by step in your browser

    Analyze Google Cloud audit logs and VPC Flow Logs step by step: export as JSON, drop the files, read the verdict, findings, timeline and remediation checklist.

  4. A GCP compromise walkthrough (fictional case study)

    A fictional Google Cloud incident investigated end to end: leaked CI key, Owner for a Gmail account, startup-script backdoor, public bucket, deleted log sink.

  5. GCP Data Access logs: off by default, and other blind spots

    Why GCP Data Access audit logs are the usual dead end: off by default, 30-day retention, what goes unseen without them, and what to enable before an incident.

All posts in this series

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.