Skip to content

GCP IAMGraph v0.2.0 — Explainable Authorization Engine

Latest

Choose a tag to compare

@Parakh-Shinde Parakh-Shinde released this 30 Aug 18:13
· 3 commits to main since this release
e1abb17

Highlights

GCP IAMGraph v0.2.0 introduces an explainable authorization engine for more accurate GCP IAM attack-path analysis.

Added

  • Explicit ALLOW, DENY, and UNKNOWN authorization decisions
  • Inherited IAM deny-policy evaluation
  • Deny-rule principal and permission exceptions
  • Structured and deterministic decision evidence
  • Conservative handling of unsupported IAM Conditions
  • Authorization-aware project IAM escalation detection
  • Authorization-aware service-account key paths
  • Authorization-aware actAs and Compute Engine paths
  • Authorization-aware multi-hop service-account impersonation
  • End-to-end deny-policy CLI integration tests
  • Reproducible deny-policy example environment

Security impact

Applicable deny policies now prevent blocked permissions from generating confirmed attack paths. Unsupported or conditional authorization semantics remain visible as UNKNOWN instead of being assumed allowed.

Validation

  • 74 automated tests passed
  • 91.33% test coverage
  • Python 3.10, 3.11, and 3.12 CI validation
  • Ruff formatting and lint checks passed
  • Wheel validated in an isolated environment
  • JSON, Markdown, SARIF, and attack-graph reporting

See CHANGELOG.md for full details.