GCP - User Investigation

This playbook performs an investigation on a specific user in GCP environments, using queries and logs from G Suite Auditor, and GCP Logging to locate the following activities performed by the user: - Failed login attempt - Suspicious API usage by the user - Anomalous network traffic by the user - Unusual and suspicious login attempt - User's password leaked

Pack
GCP-Enrichment-Remediation
Tasks
24

Inputs

Outputs

Commands used