stratus-red-team icon indicating copy to clipboard operation
stratus-red-team copied to clipboard

GCP: Granting a project role to a @gmail.com e-mail address

Open christophetd opened this issue 3 years ago • 2 comments

Background: To backdoor a project, an attacker could grant an external e-mail address permissions on the project, i.e.

gcloud projects add-iam-policy-binding [PROJECT] \
    --member user:[email protected] --role roles/editor

In an enterprise context, this is likely to be considered suspicious

christophetd avatar Jul 28 '22 09:07 christophetd

ref https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains, this could probably be expanded to any IAM bindings containing a domain which is not the primary domain of the organization's Google Workspace account

jonpulsifer avatar Aug 15 '22 19:08 jonpulsifer

Good point for the detection part! Thanks for the input

christophetd avatar Aug 17 '22 12:08 christophetd