I was recently pointed to some #fresh GCP documentation from @TheIceRoot
For your reading pleasure is a complete list of P4SAs (per-project-per-product) Service Accounts and their default roles 📯
https://t.co/vlxzZXKY9K
☁️ Google Cloud Incident Response Cheat Sheet
* Overview of IR in GCP
* Logs for threat hunting and incident response
* Log analysis
* Service accounts
* GCP attack matrix
By @TheIceRoot#cybersecurity#infosec
https://t.co/mpGrbrPeeX
We've lined up a venue for fwd:cloudsec 2024! Mark your calendars for June 17-18 in Arlington, VA. Ticket sales and CFP will open in early January. For those interested in sponsoring, we'll have a prospectus in the next few weeks. Email [email protected] if interested.
Ever wonder how attackers breach the cloud? Jay Chen and Noah McDonald will walk through common cloud attack vectors and a real breach incident in this #sectorca presentation, starting at 2:45 in 714AB. https://t.co/VPHqIikKyq
85% of organizations have hard-coded credentials in VMs, say Jay Chen and Noah MacDonald. Their talk on cloud oversight is ongoing at #sectorca in 714AB. https://t.co/VPHqIikKyq
We just heard all about how upset gamers compromised the cloud with SIM-Swap, thanks to Jay Chen and Noah McDonald at #sectorca. They're wrapping up now in 714AB. https://t.co/VPHqIikKyq
Unfortunately @orcasec got their terminology wrong in their report by calling the cloud build SA , a ‘Default SA’, then I PERPETUATED it! - apologies. There are only 2 default SAs. The compute and app engine SA. The Cloud Build SA is not a default SA, it is a P4 SA. 1/3