Skip to content
Google Cloud logo

Google Cloud integration

Pulls Google Cloud infrastructure, identity, and organization data to enable real-time incident response and compliance automation across GCP.

What it connects

  • GCP organizations, projects, and folder hierarchies with parent-child relationships
  • Compute Engine VM instances with status, zone, machine type, and resource labels
  • Service accounts with keys, email addresses, and project-level IAM permissions
  • GKE cluster status, node pools, locations, and Kubernetes resource configuration

What it automates

  • Start, stop, reset, suspend, and resume Compute Engine instances for lifecycle management and cost control
  • Disable, enable, or delete service account keys to respond to security compromises in minutes
  • Set instance labels and metadata for governance tagging and operational context without manual updates
  • Create snapshots of VM disks for forensic preservation during security incidents or outages

In practice

An unexpected spike in GCP compute costs triggers an investigation. STLabs surfaces all running instances with their labels and resource usage, automatically stopping test instances to halt billing.
Security team detects suspicious API activity from a service account. STLabs lists all active keys for that account, disables the compromised key, and creates a rotation workflow to redeploy services with new credentials.
A production VM experiences critical errors. STLabs creates a snapshot for forensic analysis, resets the instance to clear hung processes, and tags it with incident metadata for compliance tracking.
Compliance audit requires verification of organization hierarchy and IAM policies. STLabs pulls the full org structure, lists all projects and their assigned IAM roles, and generates a compliance report with permission baselines.

More Cloud & Infrastructure integrations

See how it connects.Every tool, one live map.

All integrations