id: gcp_security name: Google Cloud version: 1.0.0 description: "Google Cloud Platform (Compute Engine + Security Command Center) — cloud containment: list/create/delete VPC firewall rules (deny to isolate), list and stop Compute Engine instances, and list Security Command Center findings. Authenticates with a Google service account (RS256 JWT bearer flow). Runs on a remote engine. Requires the Python 'PyJWT' and 'cryptography' libraries on the engine host (pip install pyjwt cryptography)." changelog: "1.0.0 — Initial release: list/create/delete firewall rules, list/stop instances, list Security Command Center findings." category: cloud # Per-instance configuration. The scripts build a signed RS256 assertion from the # service account's private_key/client_email and exchange it for an access token # (scope cloud-platform). The service account needs Compute and Security Center # roles. organization_id is only used by gcp-list-scc-findings. config_schema: properties: service_account_json: type: string description: "Full service account key JSON (must contain client_email and private_key)" x-soar-sensitive: true project_id: type: string description: "GCP project ID" organization_id: type: string description: "GCP organization ID (only required for Security Command Center findings)" required: - service_account_json - project_id commands: - id: list_firewalls name: gcp-list-firewalls description: "List VPC firewall rules in the project." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} } - id: create_firewall name: gcp-create-firewall description: "Create a VPC firewall rule (e.g. a deny rule to isolate targets)." inputs_schema: properties: name: { type: string, description: "Firewall rule name" } network: { type: string, description: "Network name (default 'default')" } direction: { type: string, description: "INGRESS or EGRESS (default INGRESS)" } action: { type: string, description: "allow or deny (default deny)" } protocol: { type: string, description: "Protocol (tcp, udp, all — default all)" } ports: { type: string, description: "Comma-separated ports (optional; omit for all)" } ranges: { type: string, description: "Comma-separated source/destination CIDR ranges (default 0.0.0.0/0)" } priority: { type: number, description: "Rule priority 0-65535 (default 1000)" } target_tags: { type: string, description: "Comma-separated target network tags (optional)" } required: [name] outputs_schema: { properties: {} } - id: delete_firewall name: gcp-delete-firewall description: "Delete a VPC firewall rule by name." inputs_schema: properties: name: { type: string, description: "Firewall rule name" } required: [name] outputs_schema: { properties: {} } - id: list_instances name: gcp-list-instances description: "List Compute Engine instances in a zone." risk: read inputs_schema: properties: zone: { type: string, description: "Zone (e.g. europe-west1-b)" } required: [zone] outputs_schema: { properties: {} } - id: stop_instance name: gcp-stop-instance description: "Stop a Compute Engine instance (containment)." inputs_schema: properties: zone: { type: string, description: "Zone of the instance" } instance: { type: string, description: "Instance name" } required: [zone, instance] outputs_schema: { properties: {} } - id: list_scc_findings name: gcp-list-scc-findings description: "List Security Command Center findings for the organization." risk: read inputs_schema: properties: filter: { type: string, description: "Optional SCC filter (e.g. state=\"ACTIVE\")" } page_size: { type: number, description: "Max findings (default 100)" } required: [] outputs_schema: { properties: {} } - id: test_connection name: gcp-test-connection description: "Verify the service-account token exchange and project access (used by the Test button)." risk: read inputs_schema: properties: {} required: [] outputs_schema: { properties: {} }