RhinoSecurityLabs/GCP-IAM-Privilege-Escalation

Required permissions for enumerating permissions

Techbrunch opened this issue · 0 comments

What are the required permissions to use the enumerate_member_permissions.py script ?

It looks like you need at least:

  • resourcemanager.projects.get to use projects.getAncestry
  • resourcemanager.projects.getIamPolicy to use projects.getIamPolicy
  • resourcemanager.folders.getIamPolicy to use folders().getIamPolicy
  • resourcemanager.organizations.getIamPolicy to use organizations.getIamPolicy