Skip to content
OPS // KITitspentest.sh

PE-GCP

gcp_scanner

Enumerates exactly which GCP resources and permissions a leaked service-account key or OAuth token actually grants — post-compromise privilege and scope discovery.

Official siteBack to catalog

OVERVIEW

gcp_scanner (github.com/google/gcp_scanner) is a resource enumeration tool, originally released by members of Google's own security team, built for exactly one post-compromise question: given a GCP service-account key, an OAuth2 refresh token, or access to a compromised VM/container/pod, what does this credential actually let you touch? Rather than relying on `gcloud` or any other SDK — which may not even be installed on a compromised host — it talks to Google Cloud APIs directly, so it can run as a standalone binary from a minimal foothold.

It systematically walks the projects, buckets, compute instances, Kubernetes clusters, Cloud SQL instances, and IAM permissions reachable by the supplied credential and reports what it found, giving an assessor a concrete picture of blast radius instead of having to manually query each GCP API by hand. The project explicitly disclaims official Google support — it is community/security-research tooling published from a Google-affiliated account, not a supported Google Cloud product.

USE CASES

Practical use cases

  • 01

    Determining the full blast radius of a leaked or found GCP service-account JSON key.

  • 02

    Enumerating what a stolen OAuth2 refresh token can actually access across projects.

  • 03

    Assessing the reach of the metadata-server credential available from a compromised GCE VM or GKE pod.

  • 04

    Feeding a concrete list of accessible projects/buckets/instances into further exploitation or reporting.

QUICK START

After obtaining a compromised GCP service-account key, OAuth refresh token, or access from a compromised VM/container, to determine exactly what that credential can actually reach.

  1. Clone the repository and install dependencies with `pip install -r requirements.txt`.
  2. Confirm the compromised credential (service-account JSON key, OAuth token, or metadata-server access) is in scope for the engagement.
  3. Run the scanner pointing it at the credential file, e.g. `python3 scanner.py -k /path/to/key.json`.
  4. Review the generated report of reachable projects, buckets, and IAM permissions before deciding what to validate manually.
python3 — bash
python3 scanner.py -k /path/to/compromised-key.json

BEFORE YOU RUN IT

What to check before running it

Treat its output as a starting point for exploitability, not proof of impact by itself — confirm any high-value finding manually before reporting it as exploitable.

Every enumeration call is a real API request against the credential's home project(s) and is recorded in Cloud Audit Logs — document expected call volume with the client beforehand.

The tool is unofficial and unsupported by Google despite its origin — review the current source before relying on it, since API coverage and behavior can lag GCP service changes.

KEEP EXPLORING

View the whole phase →