google-cloud-platform

Installation
SKILL.md

Google Cloud Platform — detection-relevant internals

This skill covers GCP cloud infrastructure security telemetry and the internals needed to detect abuse.


1. Cloud Audit Logs

GCP generates four types of audit logs:

Log type What it captures Default Detection use
Admin Activity Resource configuration changes (create, delete, modify) Always on, cannot be disabled Primary detection source — control plane operations
Data Access Resource data read/write (e.g. reading a GCS object) Off by default (must enable) Data exfiltration detection — critical gap if not enabled
System Event GCP-initiated system actions Always on Infrastructure changes by Google (maintenance, auto-scaling)
Policy Denied Access denied by VPC Service Controls or org policies Always on Privilege probing, policy bypass attempts

Audit log structure

Installs
3
First Seen
Sep 16, 2026