Security Control Framework
Google Cloud privilege escalation & post-exploitation tactics

Google Cloud privilege escalation & post-exploitation tactics

2/12/2020 · Chris Moberly

What this post added

This post details the research and tooling developed by GitLab's Red Team to simulate malicious activity in Google Cloud Platform (GCP). It outlines manual post-exploitation tactics for privilege escalation, lateral movement, and data exfiltration starting from a compromised Linux VM. It also introduces several new utilities: gcp_firewall_enum, gcp_enum, and gcp_misc, for attacking GCP environments. The post covers GCP security concepts like resource hierarchy, service accounts, access scopes, and IAM permissions from an attacker's perspective.

Read the original post ↗