Skip to main content

Remove unwanted service account key using remote agent

  • July 12, 2024
  • 1 reply
  • 14 views

Forum|alt.badge.img

Hello,

I have a playbook to monitor unauthorized creation of GCP service account keys, I need to automate the removal of the service account key step once the key is deemed suspicious. Is there any feature from Chronicle that allows for such automation? Or is remote agent needed, if so what is the most efficient way to use remote agent to do so?

Thanks in advance

1 reply

SoarAndy
Staff
Forum|alt.badge.img+12
  • Staff
  • July 17, 2024

'Remote Agent' is required if you want SOAR to talk to an on-prem technology that is behind a firewall, as GCP is in the cloud this is unlikely. 

You either need to find the appropriate Action from the marketplace, or if this does not exist engage with a partner or look at the inbuild IDE to build the appropiate code. 

HTH