Skip to content

lutzenfried/GCP_ATTACK_Matrix

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

14 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

GCP_ATTACK_Matrix

The Community GCP & Workspace ATT&CK Matrix

License: MIT Contributions Welcome

An open-source, community-driven knowledge base of tactics, techniques, and procedures (TTPs) for attacking and defending Google Cloud Platform (GCP) and Google Workspace environments.

๐ŸŽฏ About The Project

As organizations increasingly rely on Google Cloud, understanding the specific threat landscape becomes critical. What I have found over the years is that GCP is the least covered CSP out there from the big three (AWS, Azure, GCP), but attacks, abuses and misconfigurations exist. So instead of treating it like the forgotten little brother, I think it is important to understand its specific threat landscape. This project aims to be the most comprehensive and up-to-date public resource for security professionals, mapping adversary behaviors to the MITRE ATT&CKยฎ framework.

This matrix is designed for:

  • Red Teamers & Pentesters to discover and simulate attack paths.
  • Blue Teamers & Defenders to build detection and response strategies.
  • Cloud Architects to design more secure infrastructure from the ground up.

MATRIX

The full, detailed matrix is located in a separate file to keep this README clean and focused.

โžก๏ธ View the Full ATT&CK Matrix

๐Ÿค How to Contribute

This is a community-driven project, and we welcome contributions of all kinds! Whether you've discovered a new technique, have a better way of explaining an existing one, or want to fix a typo, your input is valuable.

Our contribution process is simple and managed through GitHub:

  1. Fork the repository.
  2. Create a new Branch for your changes.
  3. Add your technique or procedure to the MATRIX.md file.
  4. Submit a Pull Request with a clear description of your changes.

For more detailed instructions, please see our **Contributing Guide**.

๐Ÿ“œ License

This project is distributed under the MIT License. See the LICENSE file for more information.

๐Ÿ™ Acknowledgements

This project would not be possible without the incredible work of the security researchers, bloggers, and professionals who share their knowledge publicly. A huge thank you to everyone who has contributed, directly or indirectly.

Clรฉment Cruchet - (aka. Lutzenfried)

๐Ÿดโ€โ˜ ๏ธ HackTheWorld

About

No description, website, or topics provided.

Resources

License

Contributing

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published