Policy Analyzer
Given that IAM assignments occur over roles where principals are assigned access permissions to a resource using roles, GCP offers additional tools for troubleshooting and investigating IAM policy configurations. Policy Analyzer allows DFIR teams to analyze excess privileges assigned to users or roles that may have resulted in abuse. Policy Analyzer can also determine whether a user has the necessary permissions to perform specific actions, such as deleting a table, a GCE resource, and so on.
The following is an example of Policy Analyzer’s output. We can see in the query result what roles and permissions were configured for a user under a GCP resource. Note that resources are allocated toward a project, and GCP tags them as resources:
Figure 6.2 – Policy Analyzer query results and list of permissions per role
DFIR use cases for Policy Analyzer
Using a policy analyzer in the context of DFIR within GCP enables organizations...