Providers
Native resource types mapped to the RAGE taxonomy, their collection recipes, and the fact recipes that back edges. Switch cloud:
What's modeled
42 services · 53 resource types · 10 clustersWhat RAGE covers for GCP today, grouped by the kind of thing each service is.
Compute
8Resources that execute attacker-influenceable code and usually run AS an identity.
Data
8Structured data services - relational/NoSQL databases, warehouses, caches, search and analytics stores holding queryable data.
Messaging
7Integration primitives that can trigger execution or carry credentials.
ManagementService
5Control-plane & security services whose abuse enables execution, persistence, or evasion.
Network
4Connectivity and reachability primitives (networks, subnets, firewalls, routes, endpoints) that gate whether one resource can reach another.
Secret
4Credential and cryptographic material - terminal targets and pivots.
Storage
4Durable data-at-rest stores - objects, files, blocks, snapshots, backups, and artifact/image repositories an attacker reads, writes, or exfiltrates.
Identity
2Any principal that can hold permissions or be authenticated as.
Policy
2Authorization & governance artifacts. Nodes so their mutation is an edge target.
AdministrativeBoundary
1Containers that scope permissions, policy inheritance, and control.
Resource types 53
| resource | maps to | scope | enumerate | permissions |
|---|---|---|---|---|
gcp:accesscontextmanager:access-policy |
ConditionalPolicy |
global | accesscontextmanager.accessPolicies.list |
accesscontextmanager.accessPolicies.list |
gcp:aiplatform:notebook |
Notebook |
regional | notebooks.projects.locations.instances.list |
notebooks.instances.list |
gcp:appengine:service |
ApplicationPlatform |
global | appengine.apps.services.list |
appengine.services.list |
gcp:artifactregistry:repository |
ContainerRegistry |
regional | artifactregistry.projects.locations.repositories.list |
artifactregistry.repositories.list |
gcp:batch:job |
BatchJob |
regional | batch.projects.locations.jobs.list |
batch.jobs.list |
gcp:bigquery:dataset |
DataWarehouse |
global | bigquery.datasets.list |
bigquery.datasets.get |
gcp:bigtableadmin:instance |
NoSQLDatabase |
global | bigtableadmin.projects.instances.list |
bigtable.instances.list |
gcp:certificatemanager:certificate |
Certificate |
regional | certificatemanager.projects.locations.certificates.list |
certificatemanager.certs.list |
gcp:cloudbuild:build |
BuildWorker |
global | cloudbuild.projects.builds.list |
cloudbuild.builds.list |
gcp:clouddeploy:delivery-pipeline |
AutomationService |
regional | clouddeploy.projects.locations.deliveryPipelines.list |
clouddeploy.deliveryPipelines.list |
gcp:cloudfunctions:function |
ServerlessFunction |
global | cloudfunctions.projects.locations.functions.list |
cloudfunctions.functions.list |
gcp:cloudidentity:group |
Group |
global | cloudidentity.groups.list |
cloudidentity.groups.list |
gcp:cloudkms:key-ring |
EncryptionKey |
regional | cloudkms.projects.locations.keyRings.list |
cloudkms.keyRings.list |
gcp:cloudscheduler:job |
Scheduler |
regional | cloudscheduler.projects.locations.jobs.list |
cloudscheduler.jobs.list |
gcp:cloudtasks:queue |
Queue |
regional | cloudtasks.projects.locations.queues.list |
cloudtasks.queues.list |
gcp:composer:environment |
Workflow |
regional | composer.projects.locations.environments.list |
composer.environments.list |
gcp:compute:disk |
BlockStorage |
global | compute.disks.aggregatedList |
compute.disks.list |
gcp:compute:firewall |
Firewall |
global | compute.firewalls.list |
compute.firewalls.list |
gcp:compute:forwarding-rule |
LoadBalancer |
global | compute.forwardingRules.aggregatedList |
compute.forwardingRules.list |
gcp:compute:instance |
VirtualMachine |
global | compute.instances.aggregatedList |
compute.instances.list |
gcp:compute:network |
VirtualNetwork |
global | compute.networks.list |
compute.networks.list |
gcp:compute:security-policy |
Firewall |
global | compute.securityPolicies.list |
compute.securityPolicies.list |
gcp:compute:subnetwork |
Subnet |
region | compute.subnetworks.aggregatedList |
compute.subnetworks.list |
gcp:container:cluster |
KubernetesCluster |
global | container.projects.locations.clusters.list |
container.clusters.list |
gcp:dataflow:job |
AnalyticsService |
global | dataflow.projects.jobs.aggregated |
dataflow.jobs.list |
gcp:dataproc:cluster |
AnalyticsService |
regional | dataproc.projects.regions.clusters.list |
dataproc.clusters.list |
gcp:datastream:stream |
Workflow |
regional | datastream.projects.locations.streams.list |
datastream.streams.list |
gcp:deploymentmanager:deployment |
AutomationService |
global | deploymentmanager.deployments.list |
deploymentmanager.deployments.list |
gcp:dns:managed-zone |
DNS |
global | dns.managedZones.list |
dns.managedZones.list |
gcp:eventarc:trigger |
EventRule |
regional | eventarc.projects.locations.triggers.list |
eventarc.triggers.list |
gcp:file:instance |
FileStorage |
global | file.projects.locations.instances.list |
file.instances.list |
gcp:firestore:database |
NoSQLDatabase |
global | firestore.projects.databases.list |
datastore.databases.list |
gcp:iam:role |
Role |
global | iam.projects.roles.list |
iam.roles.list |
gcp:iam:service-account |
ServiceAccount |
global | iam.projects.serviceAccounts.list |
iam.serviceAccounts.list |
gcp:iam:service-account-key |
AccessKey |
project | iam.projects.serviceAccounts.keys.list |
iam.serviceAccountKeys.list |
gcp:iam:workload-identity-pool |
FederatedIdentity |
global | iam.projects.locations.workloadIdentityPools.list |
iam.workloadIdentityPools.list |
gcp:iap:tunnel |
PrivateEndpoint |
global | iap.projects.iap_tunnel.locations.destGroups.list |
iap.tunnelDestGroups.list |
gcp:logging:sink |
LoggingService |
global | logging.projects.sinks.list |
logging.sinks.list |
gcp:monitoring:notification-channel |
LoggingService |
global | monitoring.projects.notificationChannels.list |
monitoring.notificationChannels.list |
gcp:networkconnectivity:hub |
TransitGateway |
global | networkconnectivity.projects.locations.global.hubs.list |
networkconnectivity.hubs.list |
gcp:orgpolicy:policy |
OrganizationPolicy |
global | orgpolicy.projects.policies.list |
orgpolicy.policies.list |
gcp:pubsub:topic |
Topic |
global | pubsub.projects.topics.list |
pubsub.topics.list |
gcp:redis:instance |
Cache |
regional | redis.projects.locations.instances.list |
redis.instances.list |
gcp:resourcemanager:folder |
Folder |
global | cloudresourcemanager.folders.list |
resourcemanager.folders.list |
gcp:resourcemanager:organization |
Organization |
global | cloudresourcemanager.organizations.search |
resourcemanager.organizations.get |
gcp:resourcemanager:project |
Project |
global | cloudresourcemanager.projects.get |
resourcemanager.projects.list |
gcp:run:service |
ContainerService |
regional | run.projects.locations.services.list |
run.services.list |
gcp:secretmanager:secret |
Secret |
global | secretmanager.projects.secrets.list |
secretmanager.secrets.list |
gcp:securitycenter:source |
SecurityService |
global | securitycenter.projects.sources.list |
securitycenter.sources.list |
gcp:spanner:instance |
RelationalDatabase |
global | spanner.projects.instances.list |
spanner.instances.list |
gcp:sqladmin:instance |
RelationalDatabase |
global | sql.instances.list |
cloudsql.instances.list |
gcp:storage:bucket |
ObjectStorage |
global | storage.buckets.list |
storage.buckets.list |
gcp:workflows:workflow |
Workflow |
regional | workflows.projects.locations.workflows.list |
workflows.workflows.list |
Fact recipes 5
Facts are the relationship data (policies, bindings, trust, network, credentials) that back edges.
| fact kind | collect | backs edges | permissions |
|---|---|---|---|
iam_binding |
getIamPolicy (resourcemanager.{projects,folders,organizations}.getIamPolicy)over gcp:resourcemanager:project, gcp:resourcemanager:folder, gcp:resourcemanager:organization |
HasRole HasPermission CanImpersonate |
resourcemanager.projects.getIamPolicy resourcemanager.folders.getIamPolicy resourcemanager.organizations.getIamPolicy |
resource_policy |
<service>.getIamPolicy on the resourceover gcp:storage:bucket, gcp:cloudkms:key-ring, gcp:secretmanager:secret, gcp:iam:service-account |
HasPolicy CanReadData CanDecrypt CanReadSecret CanImpersonate |
storage.buckets.getIamPolicy cloudkms.cryptoKeys.getIamPolicy secretmanager.secrets.getIamPolicy iam.serviceAccounts.getIamPolicy |
public |
allUsers / allAuthenticatedUsers bindings in a getIamPolicy resultover gcp:storage:bucket, gcp:run:service |
ExposedToInternet ExposedToTenant |
storage.buckets.getIamPolicy run.services.getIamPolicy |
membership |
cloudidentity.groups.memberships.listover gcp:cloudidentity:group |
MemberOf |
cloudidentity.groups.memberships.list |
workload_identity |
iam.serviceAccounts.getIamPolicy (WIF pool bindings) / getOpenIdTokenover gcp:iam:workload-identity-pool, gcp:iam:service-account |
CanFederateAs FederatesTo |
iam.workloadIdentityPools.get iam.serviceAccounts.getIamPolicy |
Least-privilege permission set
Every enumerate permission this cloud's resource recipes require - copy as a single collector policy.
accesscontextmanager.accessPolicies.list appengine.services.list artifactregistry.repositories.list batch.jobs.list bigquery.datasets.get bigtable.instances.list certificatemanager.certs.list cloudbuild.builds.list clouddeploy.deliveryPipelines.list cloudfunctions.functions.list cloudidentity.groups.list cloudkms.keyRings.list cloudscheduler.jobs.list cloudsql.instances.list cloudtasks.queues.list composer.environments.list compute.disks.list compute.firewalls.list compute.forwardingRules.list compute.instances.list compute.networks.list compute.securityPolicies.list compute.subnetworks.list container.clusters.list dataflow.jobs.list dataproc.clusters.list datastore.databases.list datastream.streams.list deploymentmanager.deployments.list dns.managedZones.list eventarc.triggers.list file.instances.list iam.roles.list iam.serviceAccountKeys.list iam.serviceAccounts.list iam.workloadIdentityPools.list iap.tunnelDestGroups.list logging.sinks.list monitoring.notificationChannels.list networkconnectivity.hubs.list notebooks.instances.list orgpolicy.policies.list pubsub.topics.list redis.instances.list resourcemanager.folders.list resourcemanager.organizations.get resourcemanager.projects.list run.services.list secretmanager.secrets.list securitycenter.sources.list spanner.instances.list storage.buckets.list workflows.workflows.list