google / gcp_scanner

A comprehensive scanner for Google Cloud

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Explore an option of detecting SA's with DWD

mshudrak opened this issue · comments

[Is your feature request related to a problem? Please describe.
There are GCP SA with DWD capabilities. It would be nice to identify them.

Describe the solution you'd like
GCP SA flag SA with DWD permissions

Additional context
https://www.hunters.security/en/blog/delefriend-a-newly-discovered-design-flaw-in-domain-wide-delegation-could-leave-google-workspace-vulnerable-for-takeover)](https://www.hunters.security/en/blog/delefriend-a-newly-discovered-design-flaw-in-domain-wide-delegation-could-leave-google-workspace-vulnerable-for-takeover