Pentest manual em projeto Google Cloud — IAM bindings, Cloud Storage público, GKE workload identity, Cloud Functions com role excessiva.
Why now
GCP cresce em fintech e SaaS B2B no Brasil — e o modelo de IAM hierárquico (organization → folder → project) confunde quem veio de AWS. Pentest GCP especializado entende project-level IAM, workload identity federation e service account impersonation.
Applicable frameworks
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Bindings em todos níveis, service account impersonation, key generation, workload identity federation.
Buckets públicos, signed URL eterna, IAM herdado, fine-grained vs uniform.
Workload identity, RBAC, network policy, binary authorization, GKE Sandbox.
Service account associado, env vars com secret, ingress settings, IAM invoker.
Dataset ACL, query injection, autorização por tabela, Pub/Sub topic público.
Firewall rules permissivas, VPC peering, shared VPC, Cloud Armor bypass.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Projetos GCP multi-org de SaaS B2B e healthtechs com workload regulado.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Sim. Validamos workload identity, RBAC, network policy e binary authorization em ambos. Anthos on-prem também.
Projeto single-org pequeno: R$ 12-25k. Multi-projeto com Anthos: R$ 40-90k. Org enterprise: R$ 80-180k.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.