Understanding GCP Authentication and Principal Identification Through Cloud Audit Logs
fwd:cloudsec via YouTube
Learn the Skills Netflix, Meta, and Capital One Actually Hire For
The Fastest Way to Become a Backend Developer Online
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Learn to decipher Google Cloud Platform (GCP) authentication mechanisms and audit logs in this 22-minute security conference talk from fwd:cloudsec. Explore how to identify actions performed by Kubernetes pods, AWS role integrations, and various authentication methods within GCP projects. Senior Security Researcher Gavriel Fried draws from extensive experience in UEBA, deception, network analysis, red teaming, and digital forensics to demonstrate practical techniques for uncovering the true identities behind cloud activities. Gain essential knowledge about interpreting getAccessToken events and other critical audit log entries while developing skills to effectively monitor and secure GCP environments through real-world examples and hands-on demonstrations.
Syllabus
Who Touched My GCP Project? Understanding the Principal Part in Cloud Audit Logs - Gabriel Fried
Taught by
fwd:cloudsec