The managed data stores are where a GCP engagement pays off, and reaching them splits into two moves that recur across every service here. Either the data plane is exposed directly (a public IP, an authorized network that is too wide, an over-broad roles/*.dataViewer binding), or a service runs under an attached service account that you can drive, so the job becomes both compute and a path to that account's token. The analytics and ML services in particular double as compute and are cross-referenced into identity where the service account is the prize.
What folds in here#
- Cloud SQL: the SQL Auth Proxy, public IP and authorized networks, and built-in database users.
- BigQuery: reading datasets, query and export exfiltration, and dataset IAM.
- Vertex AI: notebook and training-job service accounts, and model and dataset theft.
- Dataproc: the cluster service account, job submission, and staged data.
- Dataflow: the worker service account and pipeline source and sink data.
- Firestore: collections through broad database IAM or security-rule gaps.
- Spanner: databases through
spanner.databasesaccess. - Bigtable: tables through
bigtable.tablesaccess.