GCP
Reminder: Add basic concepts
Attack Vectors
Stealing Service Account Tokens via SSRF
Stealing Service Account Tokens via RCE
Authentication
Enumeration
Organization Enumeration
Project Enumeration
Service Accounts Enumeration
IAM Roles & Service Account Permissions
Services Enumeration
Privilege Escalation & Lateral Movement
Implicit Delegation (iam.serviceAccounts.implicitDelegation)
signJWT (iam.serviceAccounts.signJwt)
Service Account Impersonation (iam.serviceAccountTokenCreator)
Useful Links
Last updated