GCP-IAM-Privilege-Escalation
GCP-IAM-Privilege-Escalation copied to clipboard
Required permissions for enumerating permissions
What are the required permissions to use the enumerate_member_permissions.py script ?
It looks like you need at least:
-
resourcemanager.projects.get
to useprojects.getAncestry
-
resourcemanager.projects.getIamPolicy
to useprojects.getIamPolicy
-
resourcemanager.folders.getIamPolicy
to usefolders().getIamPolicy
-
resourcemanager.organizations.getIamPolicy
to useorganizations.getIamPolicy