Attacking Google Cloud — Part 7 of 7 · a series by Zeynep Çelik. Getting access is easy; keeping it past a key revocation and an incident-response team is the craft. GCP’s best persistence abu...
secybr // offensive security notes
Field notes and methodologies from real engagements — identities, escalation, persistence, and the tradecraft behind them.
In the cloud you don't hunt hosts — you hunt identities. A 7-part path from mindset to persistence across GCP.
#arsenal
#latest
Attacking Google Cloud — Part 6: The Terminal in the Browser (Cloud Shell as an Attack Tool)
Attacking Google Cloud — Part 6 of 7 · a series by Zeynep Çelik. “Just a terminal” ships a container, an open Docker socket, a user token, and a logless shell in one package — which makes it o...
Attacking Google Cloud — Part 5: What a Single Leaked API Key Gives Away
Attacking Google Cloud — Part 5 of 7 · a series by Zeynep Çelik. An AIza… string isn’t a principal — but with the right questions it’s the loose thread that unravels into an organization’s inf...
Attacking Google Cloud — Part 4: Service Account Impersonation & IAM Privilege Escalation
Attacking Google Cloud — Part 4 of 7 · a series by Zeynep Çelik. The heart of GCP offense. Four structural traits make privilege escalation more fluid here than in AWS — and the last of them i...
Attacking Google Cloud — Part 3: Who Am I? Recon, Enumeration & Credential Hunting
Attacking Google Cloud — Part 3 of 7 · a series by Zeynep Çelik. Turn “I have a foothold” into a map. Establish position, read IAM in three layers, then hunt the credentials that let you becom...
Attacking Google Cloud — Part 2: Getting a Shell Out of the Cloud (Reverse Shells, Tunnels & Exfil)
Attacking Google Cloud — Part 2 of 7 · a series by Zeynep Çelik. The plumbing everyone assumes you already know — and the exact place people freeze in their first cloud labs. Master this and e...
Attacking Google Cloud — Part 1: Think Like the Attacker (A GCP Mindset & Methodology)
Attacking Google Cloud — Part 1 of 7 · a series by Zeynep Çelik. Before a single command, the shift that reorders everything: in the cloud you don’t hunt hosts, you hunt identities. This opene...
HTB Certified Active Directory Pentesting Expert (CAPE) - How to Pass
Those of you who read my “Certified Red Team Professional (CRTP) - How to Pass” article will remember that at the end of it, I set myself a new goal and said, “the next fortress to conquer will be ...
Certified Red Team Professional (CRTP) - How to Pass
I won’t go into detail about what CRTP is or who it’s suitable for. If you’re aiming for this certification, you already know the basics. If you want to get to the most critical information quickly...
Dumping LSASS Without Mimikatz
Mimikatz is a tool for dumping credentials from memory in Windows. It is a great tool for lateral and vertical privilege escalation in Windows Active Directory environments. Due to its popularity, ...