Google Cloud is driven through the Cloud APIs, authorized by Cloud IAM bindings and reached with a user token, a service-account key, or a resource's attached service account. Almost every attack is an IAM question: which members hold which roles at which scope (organization, folder, project, or resource), which permission lets you impersonate or actAs a more privileged service account, and which resource you can deploy to run as one. The surfaces below follow that shape, with privilege escalation living inside identity.
Enumeration#
Enumeration folds into each surface, but the project- and organization-wide inventory is run first: gcloud projects list and gcloud asset search-all-resources for the resource graph, gcloud projects get-iam-policy for the bindings, and GCPBucketBrute, gcloud, and the IAM graph tooling to resolve who can reach which service account. Those feed every surface below.
Surfaces#
- Identity: Cloud IAM
setIamPolicy, theactAsdeploy-as-service-account catalog, metadata, service-account impersonation, and workload identity federation. - Credentials: the metadata server, Secret Manager, service-account keys, gcloud and ADC tokens, Cloud KMS, HMAC keys, and API keys.
- Compute: Compute Engine metadata, SSH, and service-account scopes, and GKE cluster access and node identity.
- Storage: Cloud Storage bucket enumeration and access, disk snapshots, and Filestore.
- Serverless: Cloud Functions, Cloud Run, and Cloud Build service-account and trigger abuse.
- Data: Cloud SQL, BigQuery, Vertex AI, Dataproc, Dataflow, Firestore, Spanner, and Bigtable.
- Networking: firewall-rule exposure, VPC reach, Cloud DNS and subdomain takeover, and load balancing.
- Logging and detection: tampering with Cloud Logging sinks, disabling data-access audit logs, and weakening Security Command Center.
- Messaging: Pub/Sub topics and subscriptions, and Cloud Tasks queues.