gcp-cloudasset-exported-asset-content

Exported asset inventory can include resource metadata, IAM policies, and service-specific sensitive fields in Cloud Storage.

gcpcritical service: gcp:cloudasset emits CanReadData

Where it sits

locationcloudasset.exportAssets.outputConfig.gcsDestination.uri -> exported asset JSON
location kinddata_record
data kindscredential pii customer_data sensitive_data
emits edgeCanReadData
serviceCloud Asset Inventory (gcp:cloudasset)

Collection recipe

access modeindirect_destination
operationcloudasset.exportAssets
response pathoutputConfig.gcsDestination.uri -> exported asset JSON
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

cloudasset.assets.exportAssets
storage.objects.get

References

move · open · esc close