Skip to content
OPS // KITitspentest.sh

E-GSU

gsutil

Google's official CLI for interacting with Cloud Storage — enumerate and inspect GCS buckets and object ACLs the way aws-cli or az are used for their own clouds.

Official siteInstallBack to catalog

OVERVIEW

gsutil (cloud.google.com/storage/docs/gsutil) is Google's official command-line tool for Cloud Storage, shipped as part of the Google Cloud SDK. It plays the same role in GCP assessments that the AWS CLI and `az` play in their respective clouds: `gsutil ls`, `gsutil iam get`, and `gsutil acl get` turn a project's buckets and their access policies into scriptable output instead of clicking through the console bucket by bucket.

It authenticates through the same Application Default Credentials as the rest of the Cloud SDK, so an assessment can reuse a client-provisioned service-account key or a `gcloud auth login` session without extra setup. Its `-m` flag parallelizes listing and object operations across many buckets, which matters when a target project has dozens or hundreds of them.

USE CASES

Practical use cases

  • 01

    Enumerating every GCS bucket reachable by a set of assessment credentials with `gsutil ls`.

  • 02

    Checking bucket-level IAM policies and legacy ACLs for public or overly broad access with `gsutil iam get` / `gsutil acl get`.

  • 03

    Reviewing object-level ACLs inside a bucket to find individually over-shared files.

  • 04

    Bulk-downloading in-scope objects for evidence once exposure has been confirmed, with `-m` for speed on large buckets.

QUICK START

Once GCP assessment credentials are provisioned, for scripted enumeration of accessible GCS buckets, their IAM/ACL policies, and object-level access.

  1. Install the Google Cloud SDK (which bundles gsutil) and run `gcloud auth login` or activate a client-provided service-account key.
  2. Confirm the active project with `gcloud config get-value project` before running anything.
  3. List reachable buckets with `gsutil ls`, then check IAM/ACLs on any that look interesting with `gsutil iam get gs://<bucket>`.
  4. Drill into object-level ACLs with `gsutil acl get gs://<bucket>/<object>` only once a bucket is confirmed in scope.
gsutil — bash
gsutil ls -L gs://<bucket> && gsutil iam get gs://<bucket>

BEFORE YOU RUN IT

What to check before running it

Every `gsutil` call is recorded in Cloud Audit Logs under the identity used — agree with the client on expected call volume and timing beforehand.

gsutil is being gradually superseded by `gcloud storage` in Google's own documentation — confirm it is still installed and current on the assessment machine before relying on it.

Never reuse a personal Google account for assessment work; always use a client-provisioned, scoped service-account key with a defined lifetime.

KEEP EXPLORING

View the whole phase →