Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “Google Cloud”
29 publicationsKeep an S3 bucket private with Block Public Access
Enable S3 Block Public Access while preserving approved readers. Review the four settings, private CloudFront origins, and practical access tests.
Workload security · AWS · By Cloud Security DeskRemove public SSH access from an EC2 security group
Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.
Workload security · AWS · By Cloud Security DeskGive Google Cloud teams access through IAM groups
Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.
Identity & access · Google Cloud · By Cloud Security DeskConnect to a Google Cloud VM with IAP and OS Login
Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.
Identity & access · Google Cloud · By Cloud Security DeskGet an alert when Google Cloud project access changes
Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.
Detection & response · Google Cloud · By Cloud Security DeskTriage a Google Cloud Security Command Center finding
Review a Security Command Center finding, choose repair or a documented exception, and distinguish resource verification from muting and closure.
Detection & response · Google Cloud · By Cloud Security DeskKeep a Google Cloud Storage bucket private
Use public access prevention and uniform bucket-level access for Cloud Storage, then test IAM readers, signed links, and application dependencies.
Workload security · Google Cloud · By Cloud Security DeskRequire authentication between Cloud Run services
Configure Cloud Run service-to-service authentication with a dedicated caller identity, the right ID token audience, and useful negative tests.
Workload security · Google Cloud · By Cloud Security DeskCall Vertex AI from Cloud Run without a service account key
Use a Cloud Run service account and ADC to call Vertex AI, separate deployment and runtime permissions, and remove an obsolete prototype key.
AI systems · Google Cloud · By Cloud Security DeskRemove unnecessary personal data before sending Vertex AI prompts
Reduce personal data in Vertex AI prompts with field selection, Sensitive Data Protection, deliberate transformations, and safe failure handling.
AI systems · Google Cloud · By Cloud Security DeskRecover deleted Google Cloud Storage objects with soft delete
Choose a Cloud Storage soft delete window, restore a specific object generation, validate its contents, and account for retention and cleanup.
Resilience · Google Cloud · By Cloud Security DeskSet up Cloud SQL backups and prove you can restore
Configure Cloud SQL PostgreSQL backups, understand retention settings, and rehearse a restore through database validation and application cutover.
Resilience · Google Cloud · By Cloud Security DeskKeep Kubernetes audit records useful without logging secrets
Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.
Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskKeep S3 presigned access inside an explicit delegation window
Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.
Identity & access · AWS · By Cloud Security DeskFind the shared dependencies behind a cloud outage
Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.
Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskA defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
Detection & response · CISA / NIST / FIRST · By Cloud Security DeskRecovery objectives that match the cloud service
Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.
Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security DeskMake secret rotation reach every running application
Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.
Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskShort SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Identity & access · OpenSSH · By Cloud Security DeskCloud incident severity needs a service impact model
Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.
Detection & response · NIST / FIRST · By Cloud Security DeskThe bottlenecks that shape a cloud DDoS response
Distinguish bandwidth, packet processing, connection state and application work before choosing a DDoS response or assuming the whole service path is protected.
Resilience · AWS / Azure / Google Cloud / Cloudflare · By Cloud Security DeskTrace Google service account impersonation across every hop
A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.
Identity & access · Google Cloud · By Cloud Security DeskFind the Google audit logs missing from your evidence window
Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.
Detection & response · Google Cloud · By Cloud Security Desk