Summary
After diving deep into GCP, we know the GCP infrastructure is very similar to other popular cloud providers. We highlighted the importance of understanding the varying verbosity of logs emitted by GCP services, emphasizing the need for investigators to seek corroborating evidence to confirm events. GCP’s centralized logging system, which flows into Logs Explorer, is a powerful tool for administrators to troubleshoot routine issues and for investigators to delve into event correlations across the GCP ecosystem.
We learned about similarities between how GCP organizes its buckets and objects, which is conceptually similar to AWS. Cloud SCC offers a dashboard or a security scorecard on infrastructure for administrators. At the same time, for investigators, it is a goldmine of findings, with detailed information on where to look when kicking off an investigation. Cloud SCC offers unique insights into vulnerabilities without deploying specific agents within the hosts. Finally...