10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Google Cloud (GCP) logo

Google Cloud (GCP)

مباشرالهوية والوصول

موصّل Google Cloud (GCP) — للقراءة فقط، بدون وكيل

Audits your Google Cloud (GCP) project security posture — project IAM (service-account keys, primitive-role sprawl, inactive and external principals, public bindings), enabled APIs and API-key restrictions, Cloud Audit Log coverage and retention, VPC firewall exposure (SSH/RDP open to the internet), and public Cloud Storage buckets. Read-only.

ما الذي نفحصه

  • Project IAM policy bindings, service accounts and their key metadata, API keys and their restrictions, and enabled APIs (never resource data or key material)
  • Audit-log configuration and retention, VPC firewall rules, and Cloud Storage bucket IAM policies (never object contents)

مراقبة بصلاحية القراءة فقط — لا يتغيّر شيء في بيانات Google Cloud (GCP) الخاصة بك ما لم تُفعّل المعالجة التلقائية وتمنح وصول الكتابة بشكل منفصل.

النتائج الأمنية

يتم تشغيل 17 قاعدة كشف في كل فحص لـ Google Cloud (GCP). تأتي كل نتيجة مع شرح بلغة واضحة، والأدلة التي تدعمها، وخطوات المعالجة.

  • CRITICALPublic exposure

    GCP IAM binding grants access to all (public) users

  • CRITICALPublic exposure

    GCP Cloud Storage bucket is public

  • HIGHStale access

    GCP service-account key not rotated in over 90 days

  • HIGHOver permission

    GCP service account has a project-level Owner/Editor role

  • HIGHExternal access

    External user has access to the GCP project

  • HIGHMisconfig

    GCP API key has no application (referrer/IP) restriction

  • HIGHPublic exposure

    GCP firewall allows SSH/RDP from the entire internet

  • MEDIUMOver permission

    GCP user has a project-level Owner/Editor primitive role

  • MEDIUMMisconfig

    GCP organization does not enforce MFA (2-Step Verification)

  • MEDIUMMisconfig

    GCP project has an overly-permissive API enabled

  • MEDIUMStale access

    GCP API key not rotated in over 90 days

  • MEDIUMMisconfig

    GCP Cloud Audit Logs are disabled for a service

  • MEDIUMMisconfig

    Vertex AI is enabled with no vertexai.* org policy

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWStale access

    GCP service account has been inactive for over 90 days

  • LOWMisconfig

    GCP log retention is shorter than 30 days

  • LOWMisconfig

    GCP project still has the legacy default network

كيفية ربط Google Cloud (GCP)

  1. الخطوة 1

    سجّل حسابًا أو سجّل الدخول إلى 8200.dev

  2. الخطوة 2

    انتقل إلى Connectors ← Google Cloud (GCP)

  3. الخطوة 3

    انقر على Connect وامنح التفويض عبر شاشة الموافقة الخاصة بـ Google Cloud (GCP)

  4. الخطوة 4

    يقوم 8200.dev بالفحص تلقائيًا — تظهر النتائج خلال دقائق

اربط مصدرك الأول في دقائق — مجاناً، للقراءة فقط، دون الحاجة إلى مكالمة مبيعات.