
2/12/2020 · Chris Moberly
What this post added
This post details the research and tooling developed by GitLab's Red Team to simulate malicious activity in Google Cloud Platform (GCP). It outlines manual post-exploitation tactics for privilege escalation, lateral movement, and data exfiltration starting from a compromised Linux VM. It also introduces several new utilities: gcp_firewall_enum, gcp_enum, and gcp_misc, for attacking GCP environments. The post covers GCP security concepts like resource hierarchy, service accounts, access scopes, and IAM permissions from an attacker's perspective.