M ManySignal
MS
GC
Integration

Google Cloud Platform Integration

Cloud audit and threat signals across your entire GCP organisation.

What this integration does

Google Cloud Platform meets agentic SOC

Google Cloud Platform audit logs — Cloud Audit Logs, Security Command Center findings, and VPC Flow Logs — provide deep visibility into your GCP estate. ManySignal ingests these via Pub/Sub subscriptions and Cloud Storage exports, normalises events to OCSF, and correlates GCP signals with Workspace, Kubernetes, and identity data.

Cloud Audit Log ingestion (Admin Activity, Data Access, System Events)

Security Command Center finding ingestion

VPC Flow Log analysis for network threat detection

Data collected

  • Cloud Audit Logs (all log types)
  • Security Command Center findings
  • VPC Flow Logs
  • GKE audit logs
  • Cloud Identity and IAM changes

Actions supported

  • Disable service account
  • Revoke service account key
  • Add IAM deny policy
  • Quarantine VM instance (remove from network)
  • Create Security Command Center custom finding

Getting started

Set up in minutes

  1. 1

    Create a GCP service account for ManySignal

  2. 2

    Configure Pub/Sub log export

  3. 3

    Enable Security Command Center

  4. 4

    Connect in ManySignal

Google Cloud Platform Integration: frequently asked questions

Do I need the Security Command Center Premium tier?

Standard tier findings (misconfigurations) are included in GCP. Premium tier is required for Event Threat Detection and Container Threat Detection findings, which provide the highest-value security signals.

How does ManySignal handle multi-project GCP organisations?

Organisation-level log sinks and SCC aggregate signals from all projects automatically. No per-project configuration is required.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.