GCP-IAM-Privilege-Escalation

Privilege Escalation Tools

A collection of GCP IAM privilege escalation methods and their associated tools

A collection of GCP IAM privilege escalation methods documented by the Rhino Security Labs team.

GitHub

351 stars
9 watching
74 forks
Language: Python
last commit: over 2 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
rhinosecuritylabs/aws-iam-privilege-escalationA collection of research and documentation on methods for exploiting weaknesses in AWS IAM to gain unauthorized access901
marcin-kolda/gcp-iam-collectorA tool that collects and visualizes IAM permissions from Google Cloud Platform projects.50
rhinosecuritylabs/security-researchExploits and security research written by a team of experts1,064
carlospolop/purplepandaA tool that identifies privilege escalation paths in cloud and saas applications by analyzing permissions across multiple platforms.673
ayoul3/privescTools for exploiting privilege escalation vulnerabilities on z/OS systems79
rhinosecuritylabs/cloud-security-researchPublishing research findings on cloud security vulnerabilities and exploitation techniques358
rhinosecuritylabs/gcpbucketbruteScripts to enumerate and analyze Google Storage bucket permissions494
arthepsy/cve-2021-4034A proof-of-concept demonstrating local privilege escalation in a specific vulnerability1,060
andresriancho/enumerate-iamA tool to automatically enumerate permissions associated with AWS credentials1,105
sagishahar/lpeworkshopA workshop providing a comprehensive guide to local privilege escalation on Linux and Windows operating systems.1,893
spencerdodd/kernelpopAutomated framework for discovering and exploiting kernel vulnerabilities on Linux and macOS.687
nullarray/roothelperA collection of scripts for aiding in privilege escalation on Linux systems485
sleventyeleven/linuxprivcheckerA tool for identifying potential vulnerability points in Linux systems1,590
ccob/sweetpotatoProvides tools and techniques for exploiting Windows privilege escalation vulnerabilities from service accounts to SYSTEM.1,638
atalii/adageA simple and secure alternative to sudo and doas for running commands with elevated privileges.6