Skip to content

Add third-party block: GCP Storage Compliance Audit - #1192

Open
salvatoreasammito wants to merge 1 commit into
chronicle:mainfrom
salvatoreasammito:playbook/gcp_storage_compliance_audit
Open

Add third-party block: GCP Storage Compliance Audit#1192
salvatoreasammito wants to merge 1 commit into
chronicle:mainfrom
salvatoreasammito:playbook/gcp_storage_compliance_audit

Conversation

@salvatoreasammito

Copy link
Copy Markdown
Contributor

Summary

Adds a new third-party block for GCP Storage Compliance Audit.

Description

Audits GCP buckets via GoogleCloudApi Execute HTTP Request (buckets.list, buckets.get, buckets.getIamPolicy). Evaluates public ACLs, CMEK encryption, versioning, access logging, and retention/Bucket Lock. Posts structured compliance report to case wall. Covers Attack Surface Management and compliance gaps not addressed by existing Content Hub blocks.

Type of Contribution

  • Block

Validation

  • mp validate passed

Notes

  • No sensitive or internal data included.
  • Block tested in SOAR environment before submission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant