Home Series
Series
Cancel

Series

Multi-part deep dives, meant to be read in order. Each series builds a full attack path from first principles to the tradecraft behind it.

Attacking Google Cloud

In the cloud you don’t hunt hosts — you hunt identities. A 7-part path from the attacker mindset through recon, escalation, and service abuse to staying in.

  1. 1/7

    In the cloud you don't hunt hosts, you hunt identities. The mental model, the loop, the vocabulary, and the very first moves the rest of the series builds on.

  2. 2/7

    The plumbing everyone assumes you already know — reverse shells, tunnels and exfil — tied to the cloud reality where the real prize is the workload's metadata token.

  3. 3/7

    Turn a foothold into a map. Establish position, read IAM in three layers, then hunt the credentials that let you become someone more powerful.

  4. 4/7

    The heart of GCP offense. Four structural traits make privilege escalation more fluid here than in AWS — and the last is a bridge straight into Workspace.

  5. 5/7

    An AIza… string isn't a principal — but with the right questions it's the loose thread that unravels into an organization's infrastructure. Including the Firebase corner most write-ups skip.

  6. 6/7

    Just a terminal ships a container, an open Docker socket, a user token, and a logless shell in one package — one of the least-watched, most-trusted places on the platform.

  7. 7/7

    Getting access is easy; keeping it past a key revocation and an IR team is the craft. GCP's best persistence abuses intended behavior — invisible to a CVE scan.

Powered by 0xhav0c © 2022–2026 - Privacy Policy