GCP

Google Cloud is driven through the Cloud APIs, authorized by Cloud IAM bindings and reached with a user token, a service-account key, or a resource's attached service account. Almost every attack is an IAM question: which members hold which roles at which scope (organization, folder, project, or resource), which permission lets you impersonate or actAs a more privileged service account, and which resource you can deploy to run as one. The surfaces below follow that shape, with privilege escalation living inside identity.

Enumeration#

Enumeration folds into each surface, but the project- and organization-wide inventory is run first: gcloud projects list and gcloud asset search-all-resources for the resource graph, gcloud projects get-iam-policy for the bindings, and GCPBucketBrute, gcloud, and the IAM graph tooling to resolve who can reach which service account. Those feed every surface below.

Surfaces#

  • Identity: Cloud IAM setIamPolicy, the actAs deploy-as-service-account catalog, metadata, service-account impersonation, and workload identity federation.
  • Credentials: the metadata server, Secret Manager, service-account keys, gcloud and ADC tokens, Cloud KMS, HMAC keys, and API keys.
  • Compute: Compute Engine metadata, SSH, and service-account scopes, and GKE cluster access and node identity.
  • Storage: Cloud Storage bucket enumeration and access, disk snapshots, and Filestore.
  • Serverless: Cloud Functions, Cloud Run, and Cloud Build service-account and trigger abuse.
  • Data: Cloud SQL, BigQuery, Vertex AI, Dataproc, Dataflow, Firestore, Spanner, and Bigtable.
  • Networking: firewall-rule exposure, VPC reach, Cloud DNS and subdomain takeover, and load balancing.
  • Logging and detection: tampering with Cloud Logging sinks, disabling data-access audit logs, and weakening Security Command Center.
  • Messaging: Pub/Sub topics and subscriptions, and Cloud Tasks queues.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more