GCP IAMGraph v0.1.0
GCP IAMGraph v0.1.0
The first public release of GCP IAMGraph—an explainable Google Cloud IAM attack-path and least-privilege analyzer.
Highlights
- Models organization, folder, project, and resource hierarchy.
- Resolves inherited IAM allow-policy bindings.
- Supports predefined and custom role definitions.
- Ingests native IAMGraph JSON and Google Cloud Asset Inventory JSONL.
- Detects direct IAM risks and multi-step privilege-escalation paths.
- Generates explainable evidence and remediation guidance.
- Exports JSON, Markdown, SARIF 2.1.0, graph JSON, and Graphviz DOT.
- Uploads findings automatically to GitHub Code Scanning.
Detection rules
GCP-IAM-001— Broad primitive Owner or Editor roleGCP-IAM-002— Public or globally authenticated accessGCP-IAM-003— Project IAM policy modificationGCP-IAM-004— Service-account key creationGCP-IAM-005— Impersonation path to a privileged service accountGCP-IAM-006— VM creation with privileged service-accountactAsGCP-IAM-007— IAM policy modification leading to project OwnerGCP-IAM-008— Key creation for a privileged service account
Security integrations
- SARIF 2.1.0 output
- GitHub Code Scanning workflow
- Configurable CI failure thresholds
- Downloadable SARIF workflow artifacts
- JSON and Graphviz attack-graph export
Quality
- Python 3.10, 3.11, and 3.12 CI coverage
- 25 automated tests
- Ruff formatting and lint validation
- Vulnerable and hardened demonstration environments
- Read-only analysis with no automatic IAM modification
Quick start
python -m venv .venv
source .venv/bin/activate
pip install -e .
gcp-iamgraph examples/vulnerable-environment.json \
--format markdown \
--output report.md