Google Cloud (GCP)
서비스 중ID 및 액세스Google Cloud (GCP) 커넥터 — 읽기 전용, 에이전트리스
Audits your Google Cloud (GCP) project security posture — project IAM (service-account keys, primitive-role sprawl, inactive and external principals, public bindings), enabled APIs and API-key restrictions, Cloud Audit Log coverage and retention, VPC firewall exposure (SSH/RDP open to the internet), and public Cloud Storage buckets. Read-only.
스캔 대상
- Project IAM policy bindings, service accounts and their key metadata, API keys and their restrictions, and enabled APIs (never resource data or key material)
- Audit-log configuration and retention, VPC firewall rules, and Cloud Storage bucket IAM policies (never object contents)
읽기 전용 모니터링 — 자동 교정을 활성화하고 쓰기 액세스를 별도로 허용하지 않는 한 Google Cloud (GCP) 데이터는 변경되지 않습니다.
보안 탐지 항목
17개의 탐지 규칙이 모든 Google Cloud (GCP) 스캔 시 실행됩니다. 각 탐지 항목에는 쉬운 언어로 된 설명, 이를 뒷받침하는 증거, 그리고 조치 단계가 함께 제공됩니다.
- CRITICALPublic exposure
GCP IAM binding grants access to all (public) users
- CRITICALPublic exposure
GCP Cloud Storage bucket is public
- HIGHStale access
GCP service-account key not rotated in over 90 days
- HIGHOver permission
GCP service account has a project-level Owner/Editor role
- HIGHExternal access
External user has access to the GCP project
- HIGHMisconfig
GCP API key has no application (referrer/IP) restriction
- HIGHPublic exposure
GCP firewall allows SSH/RDP from the entire internet
- MEDIUMOver permission
GCP user has a project-level Owner/Editor primitive role
- MEDIUMMisconfig
GCP organization does not enforce MFA (2-Step Verification)
- MEDIUMMisconfig
GCP project has an overly-permissive API enabled
- MEDIUMStale access
GCP API key not rotated in over 90 days
- MEDIUMMisconfig
GCP Cloud Audit Logs are disabled for a service
- MEDIUMMisconfig
Vertex AI is enabled with no vertexai.* org policy
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
- LOWStale access
GCP service account has been inactive for over 90 days
- LOWMisconfig
GCP log retention is shorter than 30 days
- LOWMisconfig
GCP project still has the legacy default network
Google Cloud (GCP) 연결 방법
1단계
8200.dev에 가입하거나 로그인하십시오
2단계
커넥터 → Google Cloud (GCP)(으)로 이동하십시오
3단계
연결을 클릭하고 Google Cloud (GCP)의 동의 화면을 통해 인증하십시오
4단계
8200.dev가 자동으로 스캔합니다 — 결과는 몇 분 내에 표시됩니다
몇 분 안에 첫 번째 소스를 연결하십시오 — 무료, 읽기 전용, 영업 상담 불필요.