GCP's serverless and CI services each run as a service account, so they are both a loot target (read their source, environment, and secrets) and an execution surface (deploy or trigger code that runs as a privileged account). Cloud Build is the standout: its default service account historically carries project Editor, so a single build you control mints a near-admin token.
The deploy-as-service-account privilege-escalation angle (iam.serviceAccounts.actAs plus a create verb) is cataloged under identity privilege escalation; the pages here cover attacking the services themselves and using them for persistence.
Pages#
- Cloud Functions: reading source and environment, unauthenticated invocation, and the runtime service account.
- Cloud Run: unauthenticated services and jobs, revision secrets, and the attached service account.
- Cloud Build: exfiltrating the build service account token and planting build triggers for persistence.