GCP Pentesting
Basic Information
Before start pentesting a GCP environment, there are a few basics things you need to know about how it works to help you understand what you need to do, how to find misconfigurations and how to exploit them.
Concepts such as organization hierarchy, permissions and other basic concepts are explained in:
Labs to learn
- https://gcpgoat.joshuajebaraj.com/
- https://github.com/ine-labs/GCPGoat
- https://github.com/lacioffi/GCP-pentest-lab/
- https://github.com/carlospolop/gcp_privesc_scripts
GCP Pentester/Red Team Methodology
In order to audit a GCP environment it's very important to know: which services are being used, what is being exposed, who has access to what, and how are internal GCP services an external services connected.[1]
From a Red Team point of view, the first step to compromise a GCP environment is to manage to obtain some credentials. Here you have some ideas on how to do that:
- Leaks in github (or similar) - OSINT
- Social Engineering (Check the page Workspace Security)
- Password reuse (password leaks)
- Vulnerabilities in GCP-Hosted Applications
- Server Side Request Forgery with access to metadata endpoint[3]
- Local File Read
/home/USERNAME/.config/gcloud/*C:\Users\USERNAME\.config\gcloud\*
- 3rd parties breached
- Internal Employee
Or by compromising an unauthenticated service exposed:
GCP - Unauthenticated Enum & Access
Or if you are doing a review you could just ask for credentials with these roles:
GCP - Permissions for a Pentest
[!NOTE] After you have managed to obtain credentials, you need to know to who do those creds belong, and what they have access to, so you need to perform some basic enumeration:
Basic Enumeration
SSRF
For more information about how to enumerate GCP metadata check the following hacktricks page:[3]
https://book.hacktricks.wiki/en/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf.html
Whoami
In GCP you can try several options to try to guess who you are. The examples combine gcloud's account and token commands with Google's tokeninfo endpoint for access-token diagnostics.[4][6][7][8]
#If you are inside a compromise machine
gcloud auth list
curl "https://oauth2.googleapis.com/tokeninfo?access_token=$(gcloud auth print-access-token)"
gcloud auth print-identity-token # Print an identity token for a target audience
#If you compromised a metadata token or somehow found an OAuth token
curl "https://oauth2.googleapis.com/tokeninfo?access_token=<token>"
An identity token is distinct from an OAuth access token and is normally minted for a target audience, so use gcloud auth print-identity-token for an identity-token flow rather than passing its output to the access-token diagnostics above.[4][8]
You can also use the API endpoint /userinfo to get more info about the user:[5]
curl -H "Authorization: Bearer $(gcloud auth print-access-token)" https://openidconnect.googleapis.com/v1/userinfo
curl -H "Authorization: Bearer <access_token>" https://openidconnect.googleapis.com/v1/userinfo
Retrieve the current UserInfo URL from Google's OpenID Connect discovery document and send the access token as a Bearer credential.[5]
Org Enumeration
# Get organizations
gcloud organizations list #The DIRECTORY_CUSTOMER_ID is the Workspace ID
gcloud resource-manager folders list --organization <org_number> # Get folders
gcloud projects list # Get projects
These commands list organizations, folders, and projects visible to the active account; folder listing requires an organization or folder parent, and project results depend on the account's permissions.[2][9][10][11]
Principals & IAM Enumeration
If you have enough permissions, checking the privileges of each entity inside the GCP account will help you understand what you and other identities can do and how to escalate privileges.[1]
If you don't have enough permissions to enumerate IAM, you can steal brute-force them to figure them out.
Check how to do the numeration and brute-forcing in:
GCP - IAM, Principals & Org Policies Enum
[!NOTE] Now that you have some information about your credentials (and if you are a red team hopefully you haven't been detected). It's time to figure out which services are being used in the environment.
In the following section you can check some ways to enumerate some common services.
Services Enumeration
GCP has an astonishing amount of services, in the following page you will find basic information, enumeration cheatsheets, how to avoid detection, obtain persistence, and other post-exploitation tricks about some of them:
Note that you don't need to perform all the work manually, below in this post you can find a section about automatic tools.
Moreover, in this stage you might discovered more services exposed to unauthenticated users, you might be able to exploit them:
GCP - Unauthenticated Enum & Access
Privilege Escalation, Post Exploitation & Persistence
The most common way once you have obtained some cloud credentials or have compromised some service running inside a cloud is to abuse misconfigured privileges the compromised account may have. So, the first thing you should do is to enumerate your privileges.
Moreover, during this enumeration, remember that permissions can be set at the highest level of "Organization" as well.[2][1]
Publicly Exposed Services
While enumerating GCP services you might have found some of them exposing elements to the Internet (VM/Containers ports, databases or queue services, snapshots or buckets...).
As pentester/red teamer you should always check if you can find sensitive information / vulnerabilities on them as they might provide you further access into the GCP account.
In this book you should find information about how to find exposed GCP services and how to check them. About how to find vulnerabilities in exposed network services I would recommend you to search for the specific service in:
GCP <--> Workspace Pivoting
Compromising principals in one platform might allow an attacker to compromise the other one, check it in:
Automatic Tools
- In the GCloud console, in https://console.cloud.google.com/iam-admin/asset-inventory/dashboard you can see resources and IAMs being used by project.[12]
- Here you can see the assets supported by this API: https://cloud.google.com/asset-inventory/docs/supported-asset-types[13]
- Check tools that can be used in several clouds here.
- gcp_scanner: This is a GCP resource scanner that can help determine what level of access certain credentials posses on GCP.[14]
# Install
python3 -m pip install gcp_scanner
# Execute with gcloud creds
python3 -m gcp_scanner -o /tmp/output/ -g "$HOME/.config/gcloud"
- gcp_enum: Bash script to enumerate a GCP environment using gcloud cli and saving the results in a file.[15]
- GCP-IAM-Privilege-Escalation: Scripts to enumerate high IAM privileges and to escalate privileges in GCP abusing them (I couldn’t make run the enumerate script).[16]
- BF My GCP Permissions: Script to bruteforce your permissions.[17]
gcloud config & debug
# Login so gcloud can use your credentials
gcloud auth login
gcloud config set project security-devbox
gcloud auth print-access-token
# Login so SDKs can use your user credentials
gcloud auth application-default login
gcloud auth application-default set-quota-project security-devbox
gcloud auth application-default print-access-token
# Update gcloud
gcloud components update
The regular gcloud account and Application Default Credentials (ADC) stores are separate; ADC login writes credentials for client libraries, and its print command emits an access token for manual API testing.[21][22]
Capture gcloud, gsutil... network
Remember that you can use the parameter --log-http with the gcloud cli to print the requests the tool is performing. If you don't want the logs to redact the token value use gcloud config set log_http_redact_token false.[1][18]
The token-redaction property is release-dependent; confirm it is supported by the installed gcloud version before disabling it, and keep any resulting logs private.
Moreover, to intercept the communication:
gcloud config set proxy/address 127.0.0.1
gcloud config set proxy/port 8080
gcloud config set proxy/type http
gcloud config set auth/disable_ssl_validation True
# If you don't want to completely disable ssl_validation use:
gcloud config set core/custom_ca_certs_file cert.pem
# Back to normal
gcloud config unset proxy/address
gcloud config unset proxy/port
gcloud config unset proxy/type
gcloud config unset auth/disable_ssl_validation
gcloud config unset core/custom_ca_certs_file
Use a custom CA when possible; disabling TLS validation removes certificate checks and should be limited to an isolated test proxy. Property names can vary by gcloud release, so inspect gcloud topic configurations if a setting is rejected.[20]
OAuth token configure in gcloud
To use an exfiltrated service account OAuth token from the metadata endpoint, use the following commands. Google documents metadata-server OAuth access tokens for code running on a VM, and gcloud's auth/access_token_file property reads a file containing only the token while ignoring the active account.[3][19]
# Via env vars
export CLOUDSDK_AUTH_ACCESS_TOKEN=<token>
gcloud projects list
# Via setup
echo "<token>" > /some/path/to/token
gcloud config set auth/access_token_file /some/path/to/token
gcloud projects list
gcloud config unset auth/access_token_file
The CLOUDSDK_AUTH_ACCESS_TOKEN form is gcloud's documented direct access-token environment variable; treat both the environment value and token file as bearer credentials and remove them after testing.[4][19][23]
References
- [1] Google Cloud privilege escalation & post-exploitation tactics
- [2] About resource hierarchy | Resource Manager | Google Cloud
- [3] View and query VM metadata | Compute Engine | Google Cloud
- [4] Token types | Authentication | Google Cloud
- [5] Google OpenID Connect API Reference
- [6] gcloud auth list | Google Cloud SDK
- [7] gcloud auth print-access-token | Google Cloud SDK
- [8] gcloud auth print-identity-token | Google Cloud SDK
- [9] gcloud organizations list | Google Cloud SDK
- [10] gcloud resource-manager folders list | Google Cloud SDK
- [11] gcloud projects list | Google Cloud SDK
- [12] Cloud Asset Inventory overview | Google Cloud
- [13] Asset types | Cloud Asset Inventory | Google Cloud
- [14] gcp_scanner
- [15] gcp_enum
- [16] GCP IAM Privilege Escalation
- [17] Bruteforce-GCP-Permissions
- [18] gcloud | Google Cloud SDK
- [19] gcloud config | Google Cloud SDK
- [20] Configuring the gcloud CLI for use behind a proxy/firewall
- [21] gcloud auth application-default login | Google Cloud SDK
- [22] gcloud auth application-default print-access-token | Google Cloud SDK
- [23] Authenticate for the gcloud CLI | Google Cloud
[!TIP] Learn & practice AWS Hacking:
HackTricks Training AWS Red Team Expert (ARTE)
Learn & practice GCP Hacking:HackTricks Training GCP Red Team Expert (GRTE)
Learn & practice Az Hacking:HackTricks Training Azure Red Team Expert (AzRTE)
Browse the full HackTricks Training catalog.Support HackTricks
- Check the subscription plans!
- Join the 💬 Discord group or the telegram group or follow us on Twitter 🐦 @hacktricks_live.
- Share hacking tricks by submitting PRs to the HackTricks and HackTricks Cloud github repos.


