GCP IAM权限审计

原名:auditing-gcp-iam-permissions

审计 Google Cloud Platform IAM 权限,识别权限过大的配置。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-21
TRACE 评分
3.4 / 5

内容概览

- When performing security assessments of GCP organization or project IAM configurations - When identifying service accounts with excessive permissions or unused access - When compliance requirements mandate review of access controls and role assignments - When investigating potential lateral movement through IAM misconfigurations - When reducing the blast radius of compromised credentials by scoping down permissions Do not use for VPC firewall rule auditing (use network security tools), for GKE RBAC auditing (use Kubernetes-specific RBAC tools), or for real-time threat detection on IAM actions (use SCC Event Threat Detection). - GCP organization or project with roles/iam.securityReviewer and roles/cloudAsset.viewer - gcloud CLI authenticated with appropriate permissions - Cloud Asset API enabled (gcloud services enable cloudasset.googleapis.com) - IAM Recommender API enabled (gcloud ser…

查看 SKILL 详情