You are performing proactive threat hunting in your company’s Google Cloud environment. You suspect an attacker has compromised a developer’s credentials and is trying to move laterally from a development Google Kubernetes Engine (GKE) cluster to critical production systems. You need to identify IOCs and prioritize investigative actions with Google Cloud security tools before analyzing raw logs in detail. What should you do next?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion