{ "iam": { "CredentialExposure": [ "bigquery.connections.get", "cloudfunctions.functions.sourceCodeSet", "compute.instances.osAdminLogin", "iam.serviceAccountKeys.create", "compute.instances.create", "cloudfunctions.functions.update", "cloudfunctions.functions.create" ], "DataAccess": [ "container.pods.create", "container.replicaSets.create", "compute.instances.osLogin", "bigquery.tables.export", "bigquery.rowAccessPolicies.getFilteredData", "container.deployments.create", "compute.images.create", "pubsub.topics.attachSubscription", "container.statefulSets.create", "bigquery.connections.use", "appengine.memcache.get", "compute.instances.getGuestAttributes", "container.deployments.update", "cloudfunctions.functions.create", "cloudfunctions.functions.invoke", "bigquery.models.getData", "bigquery.tables.getData", "appengine.memcache.getKey", "pubsub.snapshots.seek", "container.services.proxy", "datastore.entities.get", "container.statefulSets.update", "compute.instances.getScreenshot", "compute.instances.getSerialPortOutput", "cloudfunctions.functions.call", "compute.instances.osAdminLogin", "appengine.instances.enableDebug", "container.jobs.update", "bigquery.rowAccessPolicies.overrideTimeTravelRestrictions", "pubsub.subscriptions.consume", "cloudfunctions.functions.sourceCodeSet", "appengine.memcache.list", "bigquery.models.export", "cloudfunctions.functions.update", "storage.objects.get", "container.jobs.create", "container.replicaSets.update" ], "PrivEsc": [ "bigquery.datasets.createTagBinding", "container.roleBindings.update", "domains.registrations.setIamPolicy", "container.secrets.list", "compute.backendServices.setIamPolicy", "storage.objects.setIamPolicy", "bigquery.tables.setIamPolicy", "pubsub.topics.setIamPolicy", "secretmanager.secrets.setIamPolicy", "iam.serviceAccounts.signJwt", "pubsub.topics.updateTag", "cloudbuild.connections.setIamPolicy", "iam.serviceAccountKeys.enable", "container.clusterRoleBindings.update", "bigquery.rowAccessPolicies.setIamPolicy", "compute.disks.setIamPolicy", "pubsub.snapshots.setIamPolicy", "resourcemanager.tagkeys.setIamPolicy", "dns.policies.setIamPolicy", "bigquery.tables.setCategory", "bigquery.datasets.updateTag", "container.clusterRoleBindings.create", "compute.backendServices.addSignedUrlKey", "domains.registrations.createTagBinding", "iam.serviceAccounts.getAccessToken", "iam.serviceAccounts.implicitDelegation", "bigquery.connections.setIamPolicy", "compute.images.setIamPolicy", "dns.managedZones.setIamPolicy", "compute.instances.updateAccessConfig", "domains.registrations.deleteTagBinding", "iam.serviceAccounts.setIamPolicy", "compute.networkEndpointGroups.setIamPolicy", "cloudfunctions.functions.setIamPolicy", "resourcemanager.projects.setIamPolicy", "container.clusterRoles.update", "container.secrets.get", "compute.instances.updateNetworkInterface", "compute.instances.addAccessConfig", "container.clusters.deleteTagBinding", "compute.backendServices.update", "storage.buckets.deleteTagBinding", "compute.backendBuckets.addSignedUrlKey", "cloudbuild.builds.create", "compute.disks.deleteTagBinding", "pubsub.schemas.setIamPolicy", "container.roles.bind", "container.roles.escalate", "container.serviceAccounts.createToken", "bigquery.tables.updateTag", "billing.accounts.setIamPolicy", "compute.globalNetworkEndpointGroups.setIamPolicy", "compute.backendBuckets.update", "container.clusterRoles.escalate", "compute.instances.useReadOnly", "compute.backendBuckets.setSecurityPolicy", "compute.instances.use", "compute.backendServices.setSecurityPolicy", "iam.roles.update", "container.clusters.createTagBinding", "compute.backendBuckets.setIamPolicy", "bigquery.datasets.setIamPolicy", "container.nodes.proxy", "container.clusterRoles.bind", "bigquery.datasets.deleteTagBinding", "storage.buckets.createTagBinding", "iam.serviceAccounts.actAs", "compute.disks.createTagBinding", "compute.instances.setIamPolicy", "iam.serviceAccounts.getOpenIdToken", "compute.images.createTagBinding", "storage.buckets.setIamPolicy", "resourcemanager.tagvalues.setIamPolicy", "iam.serviceAccounts.signBlob", "container.roleBindings.create", "bigquery.dataPolicies.setIamPolicy", "compute.instances.createTagBinding", "compute.instances.deleteTagBinding", "compute.firewallPolicies.setIamPolicy", "compute.images.deleteTagBinding", "container.roles.update", "pubsub.subscriptions.setIamPolicy", "container.pods.exec" ] } }