Investigating GCP Incidents

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth abuse, following Security Command Center findings, and scoping IAM and resource changes. Use when responding to a suspected GCP compromise, investigating a leaked service-account key, working a Security Command Center or Event Threat Detection alert, or reconstructing what a principal did across a GCP organization.

trilwu e88d5b1 8.5 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/investigating-gcp-incidents commit e88d5b1ff2

Frequently asked questions

npx skillmds add trilwu/investigating-gcp-incidents