GCP Consultant @googlecloud | Ex-Unit42 | Cloud Security | @noahmcdonald@infosec.exchange

Joined March 2022
1 Photos and videos
Noah McDonald retweeted
I was recently pointed to some #fresh GCP documentation from @TheIceRoot For your reading pleasure is a complete list of P4SAs (per-project-per-product) Service Accounts and their default roles šŸ“Æ cloud.google.com/iam/docs/se…
1
4
8
1,304
Noah McDonald retweeted
2
7
16
2,459
Noah McDonald retweeted
ā˜ļø Google Cloud Incident Response Cheat Sheet * Overview of IR in GCP * Logs for threat hunting and incident response * Log analysis * Service accounts * GCP attack matrix By @TheIceRoot #cybersecurity #infosec medium.com/google-cloud/goog…
9
43
2,882
Noah McDonald retweeted
We've lined up a venue for fwd:cloudsec 2024! Mark your calendars for June 17-18 in Arlington, VA. Ticket sales and CFP will open in early January. For those interested in sponsoring, we'll have a prospectus in the next few weeks. Email sponsorship@fwdcloudsec.org if interested.
20
70
13,377
Noah McDonald retweeted
Ever wonder how attackers breach the cloud? Jay Chen and Noah McDonald will walk through common cloud attack vectors and a real breach incident in this #sectorca presentation, starting at 2:45 in 714AB. buff.ly/3tuDMxt
1
1
120
Noah McDonald retweeted
85% of organizations have hard-coded credentials in VMs, say Jay Chen and Noah MacDonald. Their talk on cloud oversight is ongoing at #sectorca in 714AB. buff.ly/3tuDMxt
1
1
112
Noah McDonald retweeted
We just heard all about how upset gamers compromised the cloud with SIM-Swap, thanks to Jay Chen and Noah McDonald at #sectorca. They're wrapping up now in 714AB. buff.ly/3tuDMxt
1
1
117
If you are at #SecTor today, come check out my talk on real world cloud attacks! #cloud #blackhat blackhat.com/sector/2023/bri…

2
74
Google’s Threat Horizon report, out now! services.google.com/fh/files…

1
6
18
2,590
I am excited to announce that my colleague Jay Chen and I got accepted to @BlackHatEvents SecTor!! blackhat.com/sector/2023/bri…

5
960
Noah McDonald retweeted
Unfortunately @orcasec got their terminology wrong in their report by calling the cloud build SA , a ā€˜Default SA’, then I PERPETUATED it! - apologies. There are only 2 default SAs. The compute and app engine SA. The Cloud Build SA is not a default SA, it is a P4 SA. 1/3
Replying to @NightmareJS
The "bad.build" in question is the Default Cloud Build Service Account (SA), so what is it? It runs build for you, pulls images, injects secrets and "actsas" the SA which any resulting resource (i.e. Cloud Run) ultimately runs as. They are unique per project. 2/8
2
2
12
2,762
Noah McDonald retweeted
We've just released our AWS CloudTrail Cheat sheet, blog post: invictus-ir.medium.com/aws-c… Link to cheat sheet: github.com/invictus-ir/aws-c… In this thread our Top 5 Events from CloudTrail for Incident Response! 🧵
1
29
65
6,747
Noah McDonald retweeted
One final @fwdcloudsec appreciation post: It was legitimately the best con I have ever attended. Hands down. Gathering some of the brightest minds in the cloud security community for two days of AMAZING talks. I had never been in person before and now I will never miss it.
5
14
73
8,689
Noah McDonald retweeted
13 Apr 2023
šŸ“£ Cado Labs researchers recently encountered an emerging Python-based credential harvester and hacktool, named Legion, aimed at exploiting various services for the purpose of email abuse. Full analysis here: cadosecurity.com/legion-an-a… #threatintelligence #threatresearch #cyber
4
7
960
Noah McDonald retweeted
Zoom having an outage due to a misconfigured SCP. ClassicšŸ‘Œ
14
29
184
70,646
Noah McDonald retweeted
New cloud security research! We found a method to bypass CloudTrail logging for both read AND write API actions in AWS Service Catalog! In addition, we also reported an issue with a lack of CloudTrail logging in AWS Control Tower. securitylabs.datadoghq.com/a…
3
59
140
33,197