Panther informational experimental python

GCP Privilege Escalation via TagBinding

Detects a sequence of events that could indicate a privilege escalation attempt via GCP's tag-based access control. The sequence includes: 1. Enumeration of IAM policies and tags 2. Creation of a tag binding 3. Performance of a privileged operation

View Source

Detection Logic

[object Object]

Field Validations

Loading…

Comments (0)

Loading comments...