Multi-part deep dives, meant to be read in order. Each series builds a full attack path from first principles to the tradecraft behind it.
Attacking Google Cloud
In the cloud you don’t hunt hosts — you hunt identities. A 7-part path from the attacker mindset through recon, escalation, and service abuse to staying in.
- 1/7
In the cloud you don't hunt hosts, you hunt identities. The mental model, the loop, the vocabulary, and the very first moves the rest of the series builds on.
- 2/7
The plumbing everyone assumes you already know — reverse shells, tunnels and exfil — tied to the cloud reality where the real prize is the workload's metadata token.
- 3/7
Turn a foothold into a map. Establish position, read IAM in three layers, then hunt the credentials that let you become someone more powerful.
- 4/7
The heart of GCP offense. Four structural traits make privilege escalation more fluid here than in AWS — and the last is a bridge straight into Workspace.
- 5/7
An AIza… string isn't a principal — but with the right questions it's the loose thread that unravels into an organization's infrastructure. Including the Firebase corner most write-ups skip.
- 6/7
Just a terminal ships a container, an open Docker socket, a user token, and a logless shell in one package — one of the least-watched, most-trusted places on the platform.
- 7/7
Getting access is easy; keeping it past a key revocation and an IR team is the craft. GCP's best persistence abuses intended behavior — invisible to a CVE scan.