Skip to content

New attack technique: Open Ingress Port 22 on a Firewall Rule (gcp.exfiltration.open-port-22-ingress)#801

Draft
Minosity-VR wants to merge 1 commit intosimon.marechal/gcp-exfiltration-backdoor-gcs-bucketfrom
simon.marechal/gcp-exfiltration-open-port-22-ingress
Draft

New attack technique: Open Ingress Port 22 on a Firewall Rule (gcp.exfiltration.open-port-22-ingress)#801
Minosity-VR wants to merge 1 commit intosimon.marechal/gcp-exfiltration-backdoor-gcs-bucketfrom
simon.marechal/gcp-exfiltration-open-port-22-ingress

Conversation

@Minosity-VR
Copy link
Collaborator

What does this PR do?

New attack technique: gcp.exfiltration.open-port-22-ingress

Motivation

GCP parity with existing AWS attack techniques.

Test results

  • stratus detonate gcp.exfiltration.open-port-22-ingress
  • v1.compute.firewalls.insert appears in GCP Admin Activity audit logs

Checklist

  • The attack technique emulates a single attack step, not a full attack chain
  • We have factual evidence & references that the attack technique was used by real malware, pentesters, or attackers
  • The attack technique makes no assumption about the state of the environment prior to warming it up
…filtration.open-port-22-ingress) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant