0x650 - Teknik - The Overlooked Playground - An Attacker’s Journey Through GCP

0x650 - Teknik - The Overlooked Playground - An Attacker’s Journey Through GCP

🎙 Clément Cruchet 👥 540 📅 October 23, 2025 ⏱ 63 min 👁 16 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

GCPIAMattack surfacedomain wide delegationattack matrix

Summary

In this technical podcast episode, Clément Cruchet discusses the often-overlooked attack surface of Google Cloud Platform (GCP). He begins by explaining why GCP has historically received less security research attention compared to AWS and Azure, attributing this to a lack of documentation and community interest. The core of the talk focuses on IAM (Identity and Access Management) as the foundation of cloud security, highlighting GCP’s resource-centric model where permissions are often bound directly to resources, unlike the more user-centric models of other providers. He details GCP’s hierarchical structure (organization, folders, projects) and the different types of roles (primitive, predefined, custom), warning about the dangers of overly permissive roles. A significant portion is dedicated to the ‘domain wide delegation’ technique, which allows a service account to interact with Google Workspace (Gmail, Drive), and he presents his own tool ‘Delegate’ for demonstrating this. He also introduces a community-driven GCP attack matrix on GitHub, which maps tactics and techniques for penetration testing. The talk concludes by emphasizing the importance of understanding GCP’s unique security challenges and encourages further community research.

177 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for security professionals, as it addresses a gap in GCP security knowledge. The speaker provides practical insights into IAM misconfigurations and attack paths, backed by real-world examples and a custom tool. The argumentation is solid, logically progressing from foundational concepts to advanced attack techniques. However, the talk is primarily based on personal experience and lacks formal citations, which somewhat weakens the scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the speaker demonstrates expertise but does not provide formal references. The sources cited are limited to a GitHub repository for the attack matrix and the speaker’s own tool, which are relevant but not peer-reviewed. The title accurately reflects the content, and the talk is well-structured. No comments were provided for analysis.

141 words

Title / Content Match

The title accurately reflects the content, which focuses on exploring GCP attack surfaces from an attacker's perspective.

Quality & Reliability

7/10

The speaker demonstrates deep practical knowledge of GCP security, with concrete examples and references to community tools. However, the talk is largely based on personal experience and lacks formal citations or peer-reviewed sources, which limits its academic rigor.

Key Moments

Cited Sources

  • GCP attack matrix — Mentioned as a community-driven kill chain for GCP.

Concurring Sources

Contribution & Novelties

The talk provides a valuable contribution by focusing on GCP security, which is often neglected compared to AWS and Azure. It introduces the concept of domain wide delegation as an exfiltration vector and presents a custom tool ‘Delegate’ to demonstrate it. The proposed GCP attack matrix is a practical resource for security teams.

Pour aller plus loin :

92 words

Radar Profile

The radar profile shows high scores in technical depth and information quality, reflecting the speaker's expertise. The lower score in source reliability indicates a lack of formal citations, but the practical insights compensate.

Reliability 7/10