Google Cloud (GCP)
פעילזהות וגישהמחבר Google Cloud (GCP) — קריאה בלבד, ללא התקנה
Audits your Google Cloud (GCP) project security posture — project IAM (service-account keys, primitive-role sprawl, inactive and external principals, public bindings), enabled APIs and API-key restrictions, Cloud Audit Log coverage and retention, VPC firewall exposure (SSH/RDP open to the internet), and public Cloud Storage buckets. Read-only.
מה אנחנו סורקים
- Project IAM policy bindings, service accounts and their key metadata, API keys and their restrictions, and enabled APIs (never resource data or key material)
- Audit-log configuration and retention, VPC firewall rules, and Cloud Storage bucket IAM policies (never object contents)
ניטור בקריאה בלבד — שום דבר בנתונים שלכם ב-Google Cloud (GCP) לא משתנה אלא אם הפעלתם תיקון אוטומטי והענקתם גישת כתיבה בנפרד.
ממצאי אבטחה
17 חוקי זיהוי רצים בכל סריקת Google Cloud (GCP). כל ממצא מגיע עם הסבר בשפה פשוטה, הראיות שמאחוריו וצעדי תיקון.
- CRITICALPublic exposure
GCP IAM binding grants access to all (public) users
- CRITICALPublic exposure
GCP Cloud Storage bucket is public
- HIGHStale access
GCP service-account key not rotated in over 90 days
- HIGHOver permission
GCP service account has a project-level Owner/Editor role
- HIGHExternal access
External user has access to the GCP project
- HIGHMisconfig
GCP API key has no application (referrer/IP) restriction
- HIGHPublic exposure
GCP firewall allows SSH/RDP from the entire internet
- MEDIUMOver permission
GCP user has a project-level Owner/Editor primitive role
- MEDIUMMisconfig
GCP organization does not enforce MFA (2-Step Verification)
- MEDIUMMisconfig
GCP project has an overly-permissive API enabled
- MEDIUMStale access
GCP API key not rotated in over 90 days
- MEDIUMMisconfig
GCP Cloud Audit Logs are disabled for a service
- MEDIUMMisconfig
Vertex AI is enabled with no vertexai.* org policy
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
- LOWStale access
GCP service account has been inactive for over 90 days
- LOWMisconfig
GCP log retention is shorter than 30 days
- LOWMisconfig
GCP project still has the legacy default network
איך מחברים את Google Cloud (GCP)
שלב 1
נרשמים או מתחברים ל-8200.dev
שלב 2
עוברים אל מחברים ← Google Cloud (GCP)
שלב 3
לוחצים על חיבור ומאשרים במסך ההסכמה של Google Cloud (GCP)
שלב 4
8200.dev סורק אוטומטית — התוצאות מופיעות תוך דקות
חברו את המקור הראשון בתוך דקות — חינם, בקריאה בלבד, בלי שיחת מכירה.