Cloud Security Podcast by Google

EP60 Impersonating Service Accounts in GCP and Beyond: Cloud Security Is About IAM?


Listen Later

Guest:

  • Dylan Ayrey, cofounder of Truffle Security

Topics:

  • Could you explain briefly why identity is so important in the cloud?
  • A skeptic on cloud security once told us that "in the cloud, we are one identity mistake from a breach." Is this true?
  • For listeners who aren't familiar with GCP, could you give us the 30 second story on "what is a service account." How is it different from a regular IAM account?
  • What are service account impersonations?
  • How can I see if my service accounts can be impersonated? How do I detect it?
  • How can I better secure my organization from impersonation attacks?

Resources:

  • Truffle Security blog
  • "GCP Lateral Movement And Privileged Escalation Spill Over And Updates From Google" by Dylan Ayrey
  • "Tutorial on privilege escalation and post exploitation tactics in Google Cloud Platform environments" blog
  • "Kat Traxler - Taste the IAM" blogs
...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

39 ratings


More shows like Cloud Security Podcast by Google

View all
WSJ Your Money Briefing by The Wall Street Journal

WSJ Your Money Briefing

1,718 Listeners

WSJ What’s News by The Wall Street Journal

WSJ What’s News

4,423 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,013 Listeners

Risky Business by Risky Business Media

Risky Business

372 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,026 Listeners

NVIDIA AI Podcast by NVIDIA

NVIDIA AI Podcast

345 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,078 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

176 Listeners

Practical AI by Practical AI LLC

Practical AI

209 Listeners

Cloud Security Podcast by TechRiot.io

Cloud Security Podcast

58 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Huberman Lab by Scicomm Media

Huberman Lab

29,274 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

688 Listeners

HBR On Leadership by Harvard Business Review

HBR On Leadership

170 Listeners

AI Security Podcast by TechRiot.io

AI Security Podcast

9 Listeners