Ikiwa unataka kufanya pentest kwenye mazingira ya GCP unahitaji kuomba vibali vya kutosha ili kuangalia huduma zote au zaidi zinazotumiwa katika GCP. Kwa ideal, unapaswa kuomba mteja aunde:
Unda mradi mpya
UndaAkaunti ya Huduma ndani ya mradi huo (pata vitambulisho vya json) au unda mtumiaji mpya.
ToaAkaunti ya Huduma au mtumiaji vile vya majukumu yaliyotajwa baadaye kwenye ORGANIZATION
WezeshaAPIs zilizotajwa baadaye kwenye chapisho hili kwenye mradi ulioziumba
Seti ya vibali kutumia zana zilizopendekezwa baadaye:
From https://github.com/nccgroup/ScoutSuite/wiki/Google-Cloud-Platform#permissions
roles/Viewer
roles/iam.securityReviewer
roles/stackdriver.accounts.viewer
From https://lyft.github.io/cartography/modules/gcp/config.html
roles/iam.securityReviewer
roles/resourcemanager.organizationViewer
roles/resourcemanager.folderViewer
From https://github.com/JupiterOne/graph-google-cloud/blob/main/docs/development.md
roles/iam.securityReviewer
roles/iam.organizationRoleViewer
roles/bigquery.metadataViewer