Runbook 01 — Google Cloud Pentest Methodology
Purpose
Section titled “Purpose”This runbook provides the standard GoHackersCloud methodology used by Cloud Penetration Testers when performing authorized Google Cloud security assessments.
Rather than focusing on a specific service, this runbook explains the complete assessment lifecycle—from project planning to final reporting—ensuring every engagement follows a consistent and repeatable process.
Objectives
Section titled “Objectives”After completing this runbook, you will be able to:
- Plan a cloud penetration testing engagement.
- Define assessment scope.
- Perform cloud reconnaissance.
- Assess Google Cloud services.
- Collect evidence.
- Document findings.
- Prioritize business risk.
- Produce executive and technical reports.
Assessment Lifecycle
Section titled “Assessment Lifecycle”Customer Engagement
↓
Scope Definition
↓
Rules of Engagement
↓
Architecture Review
↓
Identity Assessment
↓
Infrastructure Assessment
↓
Application Assessment
↓
Security Operations Review
↓
Risk Analysis
↓
Reporting
↓
Executive Presentation
↓
Remediation SupportPhase 1 — Engagement Planning
Section titled “Phase 1 — Engagement Planning”Activities
Section titled “Activities”- Review customer requirements.
- Define assessment objectives.
- Confirm authorization.
- Identify in-scope Google Cloud Projects.
- Review Rules of Engagement.
- Establish communication channels.
Deliverables
Section titled “Deliverables”- Statement of Work
- Rules of Engagement
- Assessment Plan
Phase 2 — Architecture Review
Section titled “Phase 2 — Architecture Review”Review:
- Organization Structure
- Projects
- Shared VPC
- Landing Zone
- Resource Hierarchy
- Critical Applications
Deliverable:
- Cloud Architecture Diagram
Phase 3 — Identity Assessment
Section titled “Phase 3 — Identity Assessment”Review:
- IAM
- Service Accounts
- Administrative Roles
- Custom Roles
- Groups
- Identity Governance
Deliverable:
- Identity Assessment Report
Phase 4 — Infrastructure Assessment
Section titled “Phase 4 — Infrastructure Assessment”Review:
- Compute Engine
- Networking
- Firewall Rules
- Load Balancers
- VPN
- Hybrid Connectivity
Deliverable:
- Infrastructure Assessment
Phase 5 — Data & Application Assessment
Section titled “Phase 5 — Data & Application Assessment”Review:
- Cloud Storage
- Cloud Functions
- Secret Manager
- Cloud SQL
- BigQuery
Deliverable:
- Application Security Report
Phase 6 — Security Operations Review
Section titled “Phase 6 — Security Operations Review”Review:
- Cloud Logging
- Audit Logs
- Monitoring
- Alerting
- Security Command Center
Deliverable:
- Security Operations Assessment
Phase 7 — Risk Analysis
Section titled “Phase 7 — Risk Analysis”For every finding:
- Description
- Evidence
- Business Impact
- Risk Rating
- Recommendation
- Remediation Priority
Phase 8 — Reporting
Section titled “Phase 8 — Reporting”Produce:
- Executive Report
- Technical Report
- Risk Register
- Remediation Roadmap
- Management Presentation
Best Practices
Section titled “Best Practices”- Always obtain written authorization.
- Minimize operational impact.
- Collect evidence for every finding.
- Follow least privilege.
- Prioritize business risk.
- Maintain professional documentation.
Deliverables
Section titled “Deliverables”- Assessment Methodology
- Assessment Checklist
- Reporting Templates
- Evidence Collection Guide
- Executive Reporting Framework