Skip to content

GCP IAMGraph v0.1.0

Choose a tag to compare

@Parakh-Shinde Parakh-Shinde released this 28 Aug 19:27
· 41 commits to main since this release
3a68137

GCP IAMGraph v0.1.0

The first public release of GCP IAMGraph—an explainable Google Cloud IAM attack-path and least-privilege analyzer.

Highlights

  • Models organization, folder, project, and resource hierarchy.
  • Resolves inherited IAM allow-policy bindings.
  • Supports predefined and custom role definitions.
  • Ingests native IAMGraph JSON and Google Cloud Asset Inventory JSONL.
  • Detects direct IAM risks and multi-step privilege-escalation paths.
  • Generates explainable evidence and remediation guidance.
  • Exports JSON, Markdown, SARIF 2.1.0, graph JSON, and Graphviz DOT.
  • Uploads findings automatically to GitHub Code Scanning.

Detection rules

  • GCP-IAM-001 — Broad primitive Owner or Editor role
  • GCP-IAM-002 — Public or globally authenticated access
  • GCP-IAM-003 — Project IAM policy modification
  • GCP-IAM-004 — Service-account key creation
  • GCP-IAM-005 — Impersonation path to a privileged service account
  • GCP-IAM-006 — VM creation with privileged service-account actAs
  • GCP-IAM-007 — IAM policy modification leading to project Owner
  • GCP-IAM-008 — Key creation for a privileged service account

Security integrations

  • SARIF 2.1.0 output
  • GitHub Code Scanning workflow
  • Configurable CI failure thresholds
  • Downloadable SARIF workflow artifacts
  • JSON and Graphviz attack-graph export

Quality

  • Python 3.10, 3.11, and 3.12 CI coverage
  • 25 automated tests
  • Ruff formatting and lint validation
  • Vulnerable and hardened demonstration environments
  • Read-only analysis with no automatic IAM modification

Quick start

python -m venv .venv
source .venv/bin/activate
pip install -e .

gcp-iamgraph examples/vulnerable-environment.json \
  --format markdown \
  --output report.md