feat(gcp-security): new Google Cloud cloud-containment integration
Compute Engine + Security Command Center, 7 commands: list/create/delete VPC firewall rules (deny to isolate), list/stop instances, list SCC findings. Service-account RS256 JWT auth (remote engine, PyJWT + cryptography). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,97 @@
|
||||
id: gcp_security
|
||||
name: Google Cloud
|
||||
version: 1.0.0
|
||||
description: "Google Cloud Platform (Compute Engine + Security Command Center) — cloud containment: list/create/delete VPC firewall rules (deny to isolate), list and stop Compute Engine instances, and list Security Command Center findings. Authenticates with a Google service account (RS256 JWT bearer flow). Runs on a remote engine. Requires the Python 'PyJWT' and 'cryptography' libraries on the engine host (pip install pyjwt cryptography)."
|
||||
changelog: "1.0.0 — Initial release: list/create/delete firewall rules, list/stop instances, list Security Command Center findings."
|
||||
category: cloud
|
||||
|
||||
# Per-instance configuration. The scripts build a signed RS256 assertion from the
|
||||
# service account's private_key/client_email and exchange it for an access token
|
||||
# (scope cloud-platform). The service account needs Compute and Security Center
|
||||
# roles. organization_id is only used by gcp-list-scc-findings.
|
||||
config_schema:
|
||||
properties:
|
||||
service_account_json:
|
||||
type: string
|
||||
description: "Full service account key JSON (must contain client_email and private_key)"
|
||||
x-soar-sensitive: true
|
||||
project_id:
|
||||
type: string
|
||||
description: "GCP project ID"
|
||||
organization_id:
|
||||
type: string
|
||||
description: "GCP organization ID (only required for Security Command Center findings)"
|
||||
required:
|
||||
- service_account_json
|
||||
- project_id
|
||||
|
||||
commands:
|
||||
- id: list_firewalls
|
||||
name: gcp-list-firewalls
|
||||
description: "List VPC firewall rules in the project."
|
||||
risk: read
|
||||
inputs_schema:
|
||||
properties: {}
|
||||
required: []
|
||||
outputs_schema: { properties: {} }
|
||||
- id: create_firewall
|
||||
name: gcp-create-firewall
|
||||
description: "Create a VPC firewall rule (e.g. a deny rule to isolate targets)."
|
||||
inputs_schema:
|
||||
properties:
|
||||
name: { type: string, description: "Firewall rule name" }
|
||||
network: { type: string, description: "Network name (default 'default')" }
|
||||
direction: { type: string, description: "INGRESS or EGRESS (default INGRESS)" }
|
||||
action: { type: string, description: "allow or deny (default deny)" }
|
||||
protocol: { type: string, description: "Protocol (tcp, udp, all — default all)" }
|
||||
ports: { type: string, description: "Comma-separated ports (optional; omit for all)" }
|
||||
ranges: { type: string, description: "Comma-separated source/destination CIDR ranges (default 0.0.0.0/0)" }
|
||||
priority: { type: number, description: "Rule priority 0-65535 (default 1000)" }
|
||||
target_tags: { type: string, description: "Comma-separated target network tags (optional)" }
|
||||
required: [name]
|
||||
outputs_schema: { properties: {} }
|
||||
- id: delete_firewall
|
||||
name: gcp-delete-firewall
|
||||
description: "Delete a VPC firewall rule by name."
|
||||
inputs_schema:
|
||||
properties:
|
||||
name: { type: string, description: "Firewall rule name" }
|
||||
required: [name]
|
||||
outputs_schema: { properties: {} }
|
||||
- id: list_instances
|
||||
name: gcp-list-instances
|
||||
description: "List Compute Engine instances in a zone."
|
||||
risk: read
|
||||
inputs_schema:
|
||||
properties:
|
||||
zone: { type: string, description: "Zone (e.g. europe-west1-b)" }
|
||||
required: [zone]
|
||||
outputs_schema: { properties: {} }
|
||||
- id: stop_instance
|
||||
name: gcp-stop-instance
|
||||
description: "Stop a Compute Engine instance (containment)."
|
||||
inputs_schema:
|
||||
properties:
|
||||
zone: { type: string, description: "Zone of the instance" }
|
||||
instance: { type: string, description: "Instance name" }
|
||||
required: [zone, instance]
|
||||
outputs_schema: { properties: {} }
|
||||
- id: list_scc_findings
|
||||
name: gcp-list-scc-findings
|
||||
description: "List Security Command Center findings for the organization."
|
||||
risk: read
|
||||
inputs_schema:
|
||||
properties:
|
||||
filter: { type: string, description: "Optional SCC filter (e.g. state=\"ACTIVE\")" }
|
||||
page_size: { type: number, description: "Max findings (default 100)" }
|
||||
required: []
|
||||
outputs_schema: { properties: {} }
|
||||
|
||||
- id: test_connection
|
||||
name: gcp-test-connection
|
||||
description: "Verify the service-account token exchange and project access (used by the Test button)."
|
||||
risk: read
|
||||
inputs_schema:
|
||||
properties: {}
|
||||
required: []
|
||||
outputs_schema: { properties: {} }
|
||||
Reference in New Issue
Block a user