DataDog / stratus-red-team

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
https://stratus-red-team.cloud
Apache License 2.0
1.78k stars 208 forks source link

feat(GCP): Exfiltrates a Compute Image by sharing it #440

Closed vthiery closed 10 months ago

vthiery commented 10 months ago

What does this PR do?

Introduces gcp.exfiltration.share-compute-image where data is exfiltrated by sharing a Compute Image.

Motivation

Inspired by https://www.mitiga.io/blog/google-cloud-platform-exfiltration-a-threat-hunting-guide mentionned in

To answer before getting out of draft

christophetd commented 10 months ago

Thanks for the PR! Looks great overall, left a few comments

christophetd commented 10 months ago

will be released as part of v2.12.0 shortly