Skip to content

Runbook 01 — Google Cloud Pentest Methodology

This runbook provides the standard GoHackersCloud methodology used by Cloud Penetration Testers when performing authorized Google Cloud security assessments.

Rather than focusing on a specific service, this runbook explains the complete assessment lifecycle—from project planning to final reporting—ensuring every engagement follows a consistent and repeatable process.


After completing this runbook, you will be able to:

  • Plan a cloud penetration testing engagement.
  • Define assessment scope.
  • Perform cloud reconnaissance.
  • Assess Google Cloud services.
  • Collect evidence.
  • Document findings.
  • Prioritize business risk.
  • Produce executive and technical reports.

Customer Engagement
Scope Definition
Rules of Engagement
Architecture Review
Identity Assessment
Infrastructure Assessment
Application Assessment
Security Operations Review
Risk Analysis
Reporting
Executive Presentation
Remediation Support

  • Review customer requirements.
  • Define assessment objectives.
  • Confirm authorization.
  • Identify in-scope Google Cloud Projects.
  • Review Rules of Engagement.
  • Establish communication channels.
  • Statement of Work
  • Rules of Engagement
  • Assessment Plan

Review:

  • Organization Structure
  • Projects
  • Shared VPC
  • Landing Zone
  • Resource Hierarchy
  • Critical Applications

Deliverable:

  • Cloud Architecture Diagram

Review:

  • IAM
  • Service Accounts
  • Administrative Roles
  • Custom Roles
  • Groups
  • Identity Governance

Deliverable:

  • Identity Assessment Report

Review:

  • Compute Engine
  • Networking
  • Firewall Rules
  • Load Balancers
  • VPN
  • Hybrid Connectivity

Deliverable:

  • Infrastructure Assessment

Review:

  • Cloud Storage
  • Cloud Functions
  • Secret Manager
  • Cloud SQL
  • BigQuery

Deliverable:

  • Application Security Report

Review:

  • Cloud Logging
  • Audit Logs
  • Monitoring
  • Alerting
  • Security Command Center

Deliverable:

  • Security Operations Assessment

For every finding:

  • Description
  • Evidence
  • Business Impact
  • Risk Rating
  • Recommendation
  • Remediation Priority

Produce:

  • Executive Report
  • Technical Report
  • Risk Register
  • Remediation Roadmap
  • Management Presentation

  • Always obtain written authorization.
  • Minimize operational impact.
  • Collect evidence for every finding.
  • Follow least privilege.
  • Prioritize business risk.
  • Maintain professional documentation.

  • Assessment Methodology
  • Assessment Checklist
  • Reporting Templates
  • Evidence Collection Guide
  • Executive Reporting Framework