10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Inizia gratis
Google Cloud (GCP) logo

Google Cloud (GCP)

AttivoIdentità e accessi

Connettore Google Cloud (GCP) — sola lettura, senza agenti

Audits your Google Cloud (GCP) project security posture — project IAM (service-account keys, primitive-role sprawl, inactive and external principals, public bindings), enabled APIs and API-key restrictions, Cloud Audit Log coverage and retention, VPC firewall exposure (SSH/RDP open to the internet), and public Cloud Storage buckets. Read-only.

Cosa analizziamo

  • Project IAM policy bindings, service accounts and their key metadata, API keys and their restrictions, and enabled APIs (never resource data or key material)
  • Audit-log configuration and retention, VPC firewall rules, and Cloud Storage bucket IAM policies (never object contents)

Monitoraggio in sola lettura — nulla nei suoi dati Google Cloud (GCP) viene modificato a meno che non attivi la correzione automatica e conceda separatamente l'accesso in scrittura.

Rilevamenti di sicurezza

17 regole di rilevamento vengono eseguite a ogni scansione di Google Cloud (GCP). Ogni rilevamento è accompagnato da una spiegazione in linguaggio semplice, dalle evidenze che lo supportano e dai passaggi di remediation.

  • CRITICALPublic exposure

    GCP IAM binding grants access to all (public) users

  • CRITICALPublic exposure

    GCP Cloud Storage bucket is public

  • HIGHStale access

    GCP service-account key not rotated in over 90 days

  • HIGHOver permission

    GCP service account has a project-level Owner/Editor role

  • HIGHExternal access

    External user has access to the GCP project

  • HIGHMisconfig

    GCP API key has no application (referrer/IP) restriction

  • HIGHPublic exposure

    GCP firewall allows SSH/RDP from the entire internet

  • MEDIUMOver permission

    GCP user has a project-level Owner/Editor primitive role

  • MEDIUMMisconfig

    GCP organization does not enforce MFA (2-Step Verification)

  • MEDIUMMisconfig

    GCP project has an overly-permissive API enabled

  • MEDIUMStale access

    GCP API key not rotated in over 90 days

  • MEDIUMMisconfig

    GCP Cloud Audit Logs are disabled for a service

  • MEDIUMMisconfig

    Vertex AI is enabled with no vertexai.* org policy

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWStale access

    GCP service account has been inactive for over 90 days

  • LOWMisconfig

    GCP log retention is shorter than 30 days

  • LOWMisconfig

    GCP project still has the legacy default network

Come collegare Google Cloud (GCP)

  1. Passaggio 1

    Registrarsi o accedere a 8200.dev

  2. Passaggio 2

    Andare su Connettori → Google Cloud (GCP)

  3. Passaggio 3

    Fare clic su Collega e autorizzare tramite la schermata di consenso di Google Cloud (GCP)

  4. Passaggio 4

    8200.dev esegue la scansione automaticamente — i risultati compaiono in pochi minuti

Connetta la sua prima sorgente in pochi minuti — gratuito, sola lettura, senza chiamata commerciale.