Every GCP API call carries a credential, and the fastest way to widen access is to harvest more of them. Credentials arrive as short-lived OAuth access tokens (from the metadata server or gcloud), long-lived service-account JSON keys, and the secrets and keys that services hand back when read. Each has different theft and reuse characteristics, and several services mint fresh credentials for whoever can call them.
What folds in here#
- Instance metadata: the attached service account's token and SSH keys from
metadata.google.internal, including through SSRF. - Secret Manager: reading stored secrets with
secretmanager.versions.access. - Service account keys: exported JSON keys, and creating new ones for durable access.
- Access tokens: looting cached
gcloudand Application Default Credentials from disk. - Cloud KMS: decrypting data and signing as a key.
- HMAC keys: minting a Cloud Storage HMAC key for a service account.
- API keys: creating or listing Google API keys for durable, unscoped access.