5501297984
Compute Engine + Security Command Center, 7 commands: list/create/delete VPC firewall rules (deny to isolate), list/stop instances, list SCC findings. Service-account RS256 JWT auth (remote engine, PyJWT + cryptography). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
98 lines
4.2 KiB
YAML
98 lines
4.2 KiB
YAML
id: gcp_security
|
|
name: Google Cloud
|
|
version: 1.0.0
|
|
description: "Google Cloud Platform (Compute Engine + Security Command Center) — cloud containment: list/create/delete VPC firewall rules (deny to isolate), list and stop Compute Engine instances, and list Security Command Center findings. Authenticates with a Google service account (RS256 JWT bearer flow). Runs on a remote engine. Requires the Python 'PyJWT' and 'cryptography' libraries on the engine host (pip install pyjwt cryptography)."
|
|
changelog: "1.0.0 — Initial release: list/create/delete firewall rules, list/stop instances, list Security Command Center findings."
|
|
category: cloud
|
|
|
|
# Per-instance configuration. The scripts build a signed RS256 assertion from the
|
|
# service account's private_key/client_email and exchange it for an access token
|
|
# (scope cloud-platform). The service account needs Compute and Security Center
|
|
# roles. organization_id is only used by gcp-list-scc-findings.
|
|
config_schema:
|
|
properties:
|
|
service_account_json:
|
|
type: string
|
|
description: "Full service account key JSON (must contain client_email and private_key)"
|
|
x-soar-sensitive: true
|
|
project_id:
|
|
type: string
|
|
description: "GCP project ID"
|
|
organization_id:
|
|
type: string
|
|
description: "GCP organization ID (only required for Security Command Center findings)"
|
|
required:
|
|
- service_account_json
|
|
- project_id
|
|
|
|
commands:
|
|
- id: list_firewalls
|
|
name: gcp-list-firewalls
|
|
description: "List VPC firewall rules in the project."
|
|
risk: read
|
|
inputs_schema:
|
|
properties: {}
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: create_firewall
|
|
name: gcp-create-firewall
|
|
description: "Create a VPC firewall rule (e.g. a deny rule to isolate targets)."
|
|
inputs_schema:
|
|
properties:
|
|
name: { type: string, description: "Firewall rule name" }
|
|
network: { type: string, description: "Network name (default 'default')" }
|
|
direction: { type: string, description: "INGRESS or EGRESS (default INGRESS)" }
|
|
action: { type: string, description: "allow or deny (default deny)" }
|
|
protocol: { type: string, description: "Protocol (tcp, udp, all — default all)" }
|
|
ports: { type: string, description: "Comma-separated ports (optional; omit for all)" }
|
|
ranges: { type: string, description: "Comma-separated source/destination CIDR ranges (default 0.0.0.0/0)" }
|
|
priority: { type: number, description: "Rule priority 0-65535 (default 1000)" }
|
|
target_tags: { type: string, description: "Comma-separated target network tags (optional)" }
|
|
required: [name]
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_firewall
|
|
name: gcp-delete-firewall
|
|
description: "Delete a VPC firewall rule by name."
|
|
inputs_schema:
|
|
properties:
|
|
name: { type: string, description: "Firewall rule name" }
|
|
required: [name]
|
|
outputs_schema: { properties: {} }
|
|
- id: list_instances
|
|
name: gcp-list-instances
|
|
description: "List Compute Engine instances in a zone."
|
|
risk: read
|
|
inputs_schema:
|
|
properties:
|
|
zone: { type: string, description: "Zone (e.g. europe-west1-b)" }
|
|
required: [zone]
|
|
outputs_schema: { properties: {} }
|
|
- id: stop_instance
|
|
name: gcp-stop-instance
|
|
description: "Stop a Compute Engine instance (containment)."
|
|
inputs_schema:
|
|
properties:
|
|
zone: { type: string, description: "Zone of the instance" }
|
|
instance: { type: string, description: "Instance name" }
|
|
required: [zone, instance]
|
|
outputs_schema: { properties: {} }
|
|
- id: list_scc_findings
|
|
name: gcp-list-scc-findings
|
|
description: "List Security Command Center findings for the organization."
|
|
risk: read
|
|
inputs_schema:
|
|
properties:
|
|
filter: { type: string, description: "Optional SCC filter (e.g. state=\"ACTIVE\")" }
|
|
page_size: { type: number, description: "Max findings (default 100)" }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: test_connection
|
|
name: gcp-test-connection
|
|
description: "Verify the service-account token exchange and project access (used by the Test button)."
|
|
risk: read
|
|
inputs_schema:
|
|
properties: {}
|
|
required: []
|
|
outputs_schema: { properties: {} }
|