Identify GCP Instances with Full API Access

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies Google Cloud Platform Compute Engine instances that are configured with the "Allow full access to all Cloud APIs" scope using Security Command Center FULL_API_ACCESS findings.

Attribute Value
Type Hunting Query
Solution Google Cloud Platform Security Command Center
ID 0cbdd537-b31b-41b7-a3f2-8a421ea89a43
Tactics PrivilegeEscalation
Techniques T1068, T1098
Required Connectors GoogleSCCDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
GoogleCloudSCC ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Google Cloud Platform Security Command Center