A GCP compromise walkthrough (fictional case study)
A fictional Google Cloud incident investigated end to end: leaked CI key, Owner for a Gmail account, startup-script backdoor, public bucket, deleted log sink.
This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.
A fictional Google Cloud incident investigated end to end: leaked CI key, Owner for a Gmail account, startup-script backdoor, public bucket, deleted log sink.
Trace service account impersonation in Google Cloud audit logs: GenerateAccessToken, SignBlob, serviceAccountDelegationInfo, actAs and Token Creator grants.
A service account key leaked in a repo or CI log? Find its key ID, every IP that used it and what it did via serviceAccountKeyName, then contain it in order.
This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.