Skip to content
OPS // KITitspentest.sh

E-PUR

PurplePanda

Graphs permissions and relationships across GCP, Kubernetes, GitHub, Okta, and Azure to surface privilege-escalation paths.

Official siteBack to catalog

OVERVIEW

PurplePanda (github.com/carlospolop/PurplePanda, from the author of HackTricks and PEASS-ng) fetches identities, permissions, and resources from GCP, Kubernetes, GitHub, Okta, and (more limited) Azure, and loads them into a Neo4j graph to identify privilege-escalation paths both within a single platform and across platform boundaries.

It is explicitly designed for purple teams — able to ingest API keys and tokens uncovered by other PEASS-family tools — and its enumeration output also gets written to CSV files alongside the graph, so a reviewer can skim for anything unexpected before diving into Cypher queries on the more interesting cases.

USE CASES

Practical use cases

  • 01

    Mapping GCP IAM bindings, service account impersonation chains, and Kubernetes RBAC in a single graph.

  • 02

    Finding privilege-escalation paths that cross platform boundaries, e.g. a GitHub Actions secret reaching a GCP service account.

  • 03

    Reviewing Okta application and group assignments alongside the cloud permissions they grant downstream.

  • 04

    Skimming CSV summaries of enumerated permissions to triage which findings are worth a deeper Cypher query.

QUICK START

During purple-team or cloud-security reviews spanning GCP, Kubernetes, GitHub, and Okta to find cross-platform privilege-escalation paths.

  1. Clone the repository, create a virtualenv, and install dependencies with `pip install -r requirements.txt`.
  2. Start a Neo4j instance and set the `PURPLEPANDA_NEO4J_URL` and `PURPLEPANDA_PWD` environment variables.
  3. Configure credentials for the platforms in scope (GCP service account key, GitHub token, kubeconfig, Okta API token).
  4. Run `main.py` in enumerate mode with the target platforms and review the generated CSV files and Neo4j graph.
python3 — bash
python3 main.py -e -p google,github,k8s --github-only-org

BEFORE YOU RUN IT

What to check before running it

Enumeration across GCP, GitHub, Okta, and Kubernetes APIs generates many read calls in a short time — confirm expected volume with the client, since some of these show up in provider audit logs (GCP Cloud Audit Logs, GitHub audit log, Okta system log).

The tool is licensed under a custom GPLv2-based license (same terms as the author's other PEASS-family tools) with extra clauses on derived works — review LICENSE before embedding it in other tooling.

The resulting graph and CSV output enumerate every cross-platform privilege-escalation path found — handle and store them under the engagement's data-handling rules.

KEEP EXPLORING

View the whole phase →