{ "iam": { "CredentialExposure": [ "compute.instances.osAdminLogin", "cloudfunctions.functions.update", "bigquery.connections.get", "cloudfunctions.functions.create", "cloudfunctions.functions.sourceCodeSet", "iam.serviceAccountKeys.create", "compute.instances.create" ], "DataAccess": [ "bigquery.rowAccessPolicies.getFilteredData", "bigquery.tables.export", "pubsub.snapshots.seek", "bigquery.rowAccessPolicies.overrideTimeTravelRestrictions", "container.statefulSets.create", "compute.instances.getGuestAttributes", "container.jobs.update", "container.pods.create", "compute.instances.osLogin", "container.deployments.create", "datastore.entities.get", "container.jobs.create", "bigquery.models.getData", "pubsub.topics.attachSubscription", "pubsub.subscriptions.consume", "appengine.memcache.get", "container.statefulSets.update", "container.deployments.update", "compute.images.create", "appengine.instances.enableDebug", "storage.objects.get", "cloudfunctions.functions.sourceCodeSet", "container.services.proxy", "compute.instances.getSerialPortOutput", "cloudfunctions.functions.call", "bigquery.tables.getData", "appengine.memcache.getKey", "compute.instances.osAdminLogin", "bigquery.models.export", "cloudfunctions.functions.update", "cloudfunctions.functions.create", "container.replicaSets.create", "container.replicaSets.update", "compute.instances.getScreenshot", "cloudfunctions.functions.invoke", "bigquery.connections.use", "appengine.memcache.list" ], "PrivEsc": [ "iam.serviceAccounts.actAs", "container.roles.bind", "bigquery.datasets.updateTag", "iam.serviceAccounts.setIamPolicy", "compute.instances.setIamPolicy", "bigquery.tables.setCategory", "pubsub.topics.updateTag", "iam.serviceAccounts.signJwt", "compute.images.deleteTagBinding", "container.clusters.createTagBinding", "domains.registrations.createTagBinding", "storage.buckets.deleteTagBinding", "compute.images.setIamPolicy", "compute.images.createTagBinding", "iam.serviceAccounts.implicitDelegation", "compute.backendServices.update", "compute.backendBuckets.update", "bigquery.datasets.createTagBinding", "container.clusterRoles.escalate", "bigquery.datasets.setIamPolicy", "container.clusterRoleBindings.update", "container.clusterRoles.update", "iam.serviceAccounts.getOpenIdToken", "pubsub.schemas.setIamPolicy", "compute.disks.setIamPolicy", "compute.disks.createTagBinding", "bigquery.dataPolicies.setIamPolicy", "storage.objects.setIamPolicy", "bigquery.connections.setIamPolicy", "compute.firewallPolicies.setIamPolicy", "compute.instances.addAccessConfig", "cloudbuild.builds.create", "compute.globalNetworkEndpointGroups.setIamPolicy", "compute.backendBuckets.setIamPolicy", "container.serviceAccounts.createToken", "bigquery.tables.updateTag", "compute.backendBuckets.setSecurityPolicy", "resourcemanager.tagvalues.setIamPolicy", "container.clusterRoleBindings.create", "container.roles.escalate", "storage.buckets.setIamPolicy", "container.pods.exec", "iam.serviceAccounts.getAccessToken", "compute.instances.use", "domains.registrations.deleteTagBinding", "compute.disks.deleteTagBinding", "compute.backendBuckets.addSignedUrlKey", "billing.accounts.setIamPolicy", "container.nodes.proxy", "compute.backendServices.addSignedUrlKey", "pubsub.snapshots.setIamPolicy", "dns.managedZones.setIamPolicy", "resourcemanager.tagkeys.setIamPolicy", "secretmanager.secrets.setIamPolicy", "iam.serviceAccountKeys.enable", "container.roleBindings.create", "compute.instances.updateAccessConfig", "bigquery.tables.setIamPolicy", "cloudfunctions.functions.setIamPolicy", "container.clusterRoles.bind", "storage.buckets.createTagBinding", "compute.instances.updateNetworkInterface", "container.roles.update", "pubsub.subscriptions.setIamPolicy", "dns.policies.setIamPolicy", "resourcemanager.projects.setIamPolicy", "iam.serviceAccounts.signBlob", "compute.instances.createTagBinding", "iam.roles.update", "container.secrets.get", "compute.instances.deleteTagBinding", "container.roleBindings.update", "bigquery.rowAccessPolicies.setIamPolicy", "container.clusters.deleteTagBinding", "bigquery.datasets.deleteTagBinding", "compute.instances.useReadOnly", "pubsub.topics.setIamPolicy", "compute.backendServices.setIamPolicy", "container.secrets.list", "compute.networkEndpointGroups.setIamPolicy", "cloudbuild.connections.setIamPolicy", "compute.backendServices.setSecurityPolicy", "domains.registrations.setIamPolicy" ] } }