Integration · Cloud

HailBytes + Google Cloud

Asset discovery, SecOps forwarding, Workspace SSO, and VirusTotal enrichment.

Asset discovery

HailBytes ASM enumerates internet-reachable assets from your GCP projects: Cloud DNS zones, Compute NAT IPs, Cloud Run services, Cloud Storage buckets, and global forwarding rules.

Authentication is service-account JSON or — preferably — workload identity federation, which means no long-lived key material to store or rotate from supported environments. Discovered assets back-link to the scan-target model so the rest of the pipeline runs unchanged.

Google SecOps (Chronicle)

Findings and campaign events forward to the Chronicle ingestion API using the standard ASM finding schema, in a shape compatible with YARA-L detection authoring — so exposure data is something you can write rules against, not just archive.

Google Workspace

OIDC single sign-on on both HailBytes SAT and ASM, via the Google identity provider. For phishing simulations, we document SMTP relay configuration plus the admin-console allowlist rules that stop Gmail's filtering from silently dropping simulation mail — see the SMTP setup guide.

VirusTotal

Domain, URL, and file-hash reputation enrichment on discovered assets, annotating findings with detections, related campaigns, and submission history inline.

Every integration point is bring-your-own-credential: Google Cloud API usage stays on your own project, and Workspace and VirusTotal usage on your own tenant and plan.

All cloud integrations → SSO recipe → All integrations →