Serverless

GCP's serverless and CI services each run as a service account, so they are both a loot target (read their source, environment, and secrets) and an execution surface (deploy or trigger code that runs as a privileged account). Cloud Build is the standout: its default service account historically carries project Editor, so a single build you control mints a near-admin token.

The deploy-as-service-account privilege-escalation angle (iam.serviceAccounts.actAs plus a create verb) is cataloged under identity privilege escalation; the pages here cover attacking the services themselves and using them for persistence.

Pages#

  • Cloud Functions: reading source and environment, unauthenticated invocation, and the runtime service account.
  • Cloud Run: unauthenticated services and jobs, revision secrets, and the attached service account.
  • Cloud Build: exfiltrating the build service account token and planting build triggers for persistence.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more