investigating-gcp-incidents

Installation
SKILL.md

Investigating GCP Incidents

The completeness of a GCP investigation is decided before the incident, by which audit logs were enabled. The single most damaging mistake is reading an empty query result as "nothing happened" when the real answer is "that log category was never turned on." Establish visibility first; conclude second.

GCP's audit model is not AWS's and not Azure's. Two categories are always on and two are mostly off, and knowing which is which is the difference between a scoped investigation and a false all-clear.

When to Use

  • Responding to a suspected compromise in a GCP project or organization
  • Investigating a leaked or abused service-account key
  • Working a Security Command Center, Event Threat Detection, or Chronicle alert
  • Reconstructing a principal's activity across projects
  • Scoping IAM policy or resource changes after a suspected privilege escalation
Installs
20
GitHub Stars
146
First Seen
Jul 31, 2026
investigating-gcp-incidents — trilwu/secskills