google-cloud-platform
Installation
SKILL.md
Google Cloud Platform — detection-relevant internals
This skill covers GCP cloud infrastructure security telemetry and the internals needed to detect abuse.
1. Cloud Audit Logs
GCP generates four types of audit logs:
| Log type | What it captures | Default | Detection use |
|---|---|---|---|
| Admin Activity | Resource configuration changes (create, delete, modify) | Always on, cannot be disabled | Primary detection source — control plane operations |
| Data Access | Resource data read/write (e.g. reading a GCS object) | Off by default (must enable) | Data exfiltration detection — critical gap if not enabled |
| System Event | GCP-initiated system actions | Always on | Infrastructure changes by Google (maintenance, auto-scaling) |
| Policy Denied | Access denied by VPC Service Controls or org policies | Always on | Privilege probing, policy bypass attempts |