R-GCP
GCPBucketBrute
Enumerate Google Cloud Storage buckets, test permission levels, and identify privilege escalation paths.
OVERVIEW
GCPBucketBrute (github.com/RhinoSecurityLabs/GCPBucketBrute) is an open-source Python tool designed to discover Google Cloud Storage (GCS) buckets by generating keyword permutations and verifying their existence against Google APIs.
Beyond discovery, it tests privilege levels on discovered buckets — unauthenticated or authenticated via user credentials or service account keys — using the Google Storage TestIamPermissions API to detect overly permissive access or privilege escalation opportunities.
USE CASES
Practical use cases
- 01
Discovering public or misconfigured Google Cloud Storage buckets associated with a target organization.
- 02
Testing discovered buckets for unauthenticated read, write, or permission-modification privileges.
- 03
Checking authenticated permissions with provided service account credentials to uncover privilege escalation paths.
- 04
Auditing storage bucket access policies during cloud penetration tests and red team engagements.
QUICK START
During GCP security assessments or external recon to discover exposed Google Cloud Storage buckets and verify access permissions.
- Clone the repository and install dependencies from requirements.txt using pip.
- Choose your authentication mode: unauthenticated (-u) or authenticated with a service account key (-f) or access token.
- Run the script specifying a target keyword to generate permutations and scan for buckets.
- Review the output for discovered buckets and their evaluated permission sets.
python3 gcpbucketbrute.py -k targetcompany -uBEFORE YOU RUN IT
What to check before running it
Generating many requests across bucket name permutations can trigger rate limits or alert Google Cloud monitoring controls.
Only target organization keywords and assets within the authorized penetration testing scope.
Writing or modifying permissions on discovered buckets should only be done with explicit client authorization.