Skip to content

Add GCP rule: Privileged Role Granted - Owner or Editor#2190

Open
developutm wants to merge 1 commit into
release/v11.2.9from
feature/google-rule-gcp_privileged_role_granted
Open

Add GCP rule: Privileged Role Granted - Owner or Editor#2190
developutm wants to merge 1 commit into
release/v11.2.9from
feature/google-rule-gcp_privileged_role_granted

Conversation

@developutm

Copy link
Copy Markdown
  • A detailed explanation of the changes: Adds detection for when a highly privileged GCP IAM role (Owner, Editor, or IAM Admin) is granted to a user or service account via SetIamPolicy.
  • The reasoning behind these changes: These roles provide broad access to all resources and are prime targets for privilege escalation. An attacker gaining Owner or Editor access can effectively control the entire project (Privilege Escalation - T1078).
  • Reference: N/A

@developutm developutm requested a review from a team June 9, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant