
0x650 - Teknik - The Overlooked Playground - An Attacker’s Journey Through GCP
Keywords
Summary
177 words
Critical Evaluation
Value of the Information & Strength of the Argument
The value of the information is high for security professionals, as it addresses a gap in GCP security knowledge. The speaker provides practical insights into IAM misconfigurations and attack paths, backed by real-world examples and a custom tool. The argumentation is solid, logically progressing from foundational concepts to advanced attack techniques. However, the talk is primarily based on personal experience and lacks formal citations, which somewhat weakens the scientific rigor.
Scientific Rigor, Source Quality, Title Accuracy
The scientific rigor is moderate; the speaker demonstrates expertise but does not provide formal references. The sources cited are limited to a GitHub repository for the attack matrix and the speaker’s own tool, which are relevant but not peer-reviewed. The title accurately reflects the content, and the talk is well-structured. No comments were provided for analysis.
141 words
Title / Content Match
The title accurately reflects the content, which focuses on exploring GCP attack surfaces from an attacker's perspective.
Quality & Reliability
7/10
The speaker demonstrates deep practical knowledge of GCP security, with concrete examples and references to community tools. However, the talk is largely based on personal experience and lacks formal citations or peer-reviewed sources, which limits its academic rigor.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction: Why GCP is less documented than AWS and Azure.
- Explanation of GCP's hierarchical structure: organization, folders, projects.
- Deep dive into IAM: principals, roles, and resource-centric permissions.
- Discussion on primitive roles (owner, editor, viewer) and their dangers.
- Introduction to domain wide delegation and its attack potential.
- Presentation of the 'Delegate' tool for exploiting domain wide delegation.
- Proposal of a GCP attack matrix for purple teaming.
- Conclusion: Importance of community research and understanding GCP for security.
Cited Sources
- GCP attack matrix — Mentioned as a community-driven kill chain for GCP.
Concurring Sources
- Google Cloud IAM documentation — Official documentation on IAM, which aligns with the talk's emphasis on IAM as the core of cloud security.
Contribution & Novelties
The talk provides a valuable contribution by focusing on GCP security, which is often neglected compared to AWS and Azure. It introduces the concept of domain wide delegation as an exfiltration vector and presents a custom tool ‘Delegate’ to demonstrate it. The proposed GCP attack matrix is a practical resource for security teams.
Pour aller plus loin :
- Google Cloud IAM documentation — Official documentation on IAM concepts and best practices.
- Domain-wide delegation — Google’s official guide on domain-wide delegation.
- GCP attack matrix — The community-driven attack matrix mentioned in the talk.
92 words
Radar Profile
The radar profile shows high scores in technical depth and information quality, reflecting the speaker's expertise. The lower score in source reliability indicates a lack of formal citations, but the practical insights compensate.