Skip to main content

investigating-gcp-incidents

Investigate a suspected Google Cloud compromise from the control plane — Cloud Audit Logs (Admin Activity, Data Access, System Event, Policy Denied), Cloud Logging, and VPC Flow Logs — to reconstruct IAM and service-account abuse, key creation, data access, and log tampering into a timeline. Use when the evidence is GCP audit logs rather than a host. Service-account keys and IAM bindings are the usual attack path; preserve the audit logs before retention lapses.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
EvilFreelancer/secs
آخر نشاط في المصدر
٨ أغسطس ٢٠٢٦ في ٢٠:٥٦
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٩
التفرعات
٢

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.