GCP IAM权限审计
原名:auditing-gcp-iam-permissions
审计 Google Cloud Platform IAM 权限,识别权限过大的配置。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-21
- TRACE 评分
- 3.4 / 5
内容概览
- When performing security assessments of GCP organization or project IAM configurations - When identifying service accounts with excessive permissions or unused access - When compliance requirements mandate review of access controls and role assignments - When investigating potential lateral movement through IAM misconfigurations - When reducing the blast radius of compromised credentials by scoping down permissions Do not use for VPC firewall rule auditing (use network security tools), for GKE RBAC auditing (use Kubernetes-specific RBAC tools), or for real-time threat detection on IAM actions (use SCC Event Threat Detection). - GCP organization or project with roles/iam.securityReviewer and roles/cloudAsset.viewer - gcloud CLI authenticated with appropriate permissions - Cloud Asset API enabled (gcloud services enable cloudasset.googleapis.com) - IAM Recommender API enabled (gcloud ser…