Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “Google Cloud”

29 publications
Technical guideSource-based analysis

Keep an S3 bucket private with Block Public Access

Enable S3 Block Public Access while preserving approved readers. Review the four settings, private CloudFront origins, and practical access tests.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Remove public SSH access from an EC2 security group

Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Give Google Cloud teams access through IAM groups

Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Connect to a Google Cloud VM with IAP and OS Login

Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Get an alert when Google Cloud project access changes

Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Triage a Google Cloud Security Command Center finding

Review a Security Command Center finding, choose repair or a documented exception, and distinguish resource verification from muting and closure.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep a Google Cloud Storage bucket private

Use public access prevention and uniform bucket-level access for Cloud Storage, then test IAM readers, signed links, and application dependencies.

Workload security · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Require authentication between Cloud Run services

Configure Cloud Run service-to-service authentication with a dedicated caller identity, the right ID token audience, and useful negative tests.

Workload security · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Call Vertex AI from Cloud Run without a service account key

Use a Cloud Run service account and ADC to call Vertex AI, separate deployment and runtime permissions, and remove an obsolete prototype key.

AI systems · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Remove unnecessary personal data before sending Vertex AI prompts

Reduce personal data in Vertex AI prompts with field selection, Sensitive Data Protection, deliberate transformations, and safe failure handling.

AI systems · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Recover deleted Google Cloud Storage objects with soft delete

Choose a Cloud Storage soft delete window, restore a specific object generation, validate its contents, and account for retention and cleanup.

Resilience · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Set up Cloud SQL backups and prove you can restore

Configure Cloud SQL PostgreSQL backups, understand retention settings, and rehearse a restore through database validation and application cutover.

Resilience · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep S3 presigned access inside an explicit delegation window

Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.

Identity & access · AWS · By Cloud Security Desk
Research reportSource-based analysis

Find the shared dependencies behind a cloud outage

Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.

Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

A defensible cloud patch queue starts with exploitation evidence

Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.

Detection & response · CISA / NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

Recovery objectives that match the cloud service

Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.

Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk
Technical guideSource-based analysis

Cloud incident severity needs a service impact model

Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.

Detection & response · NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

The bottlenecks that shape a cloud DDoS response

Distinguish bandwidth, packet processing, connection state and application work before choosing a DDoS response or assuming the whole service path is protected.

Resilience · AWS / Azure / Google Cloud / Cloudflare · By Cloud Security Desk
Technical guideSource-based analysis

Trace Google service account impersonation across every hop

A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.

Identity & access · Google Cloud · By Cloud Security Desk
Research noteSource-based analysis

Find the Google audit logs missing from your evidence window

Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.

Detection & response · Google Cloud · By Cloud Security Desk