Incident Investigation in Google Cloud with Audit Logs and Security Command Center

Incident investigation in Google Cloud requires connecting Identity, Audit Logs, API actions, resources, Regions, and Sessions. Start by preserving evidence and building a Timeline, then perform documented Containment.
Cloud investigation requires connecting identities, Control Plane, resources, keys, Sessions, and security services. Since activity is distributed across services and regions, a Timeline and understanding permissions are critical. This article focuses on incident investigation in Google Cloud and is intended for Cloud and SOC analysts. The goal is to provide a methodology that can be applied in practice, in a professional interview, and in a work environment, without being limited to a dictionary definition.
The main challenge is that data is almost always partial. Cloud Audit Logs, principalEmail, methodName can point in a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigative question, required evidence, and a clear criterion for completion.
The practical scenario in the article is: Timeline of IAM change and access to a simulated resource. All examples are laboratory data or process descriptions. When it comes to Penetration Testing, Web, or Cloud, work only with explicit authorization, defined Scope, and the ability to stop the test.




