vamp-gcp-audit
VampSecure Labs · VampSecure Studios
Auditor de seguridad no-destructivo para entornos Google Cloud Platform. Detecta misconfiguraciones
críticas en IAM, GCS, GKE, Cloud Functions, Firewall y configuración de proyecto usando únicamente
la API REST de GCP (sin SDKs de google-cloud-*).
Instalación
pip install -r requirements.txt
cryptographysolo es necesaria si usas--credentialscon un fichero JSON de service account.
Uso
# Con credenciales de gcloud ADC (gcloud auth application-default login)
python vamp_gcp_audit.py --project my-project-id
# Con fichero de service account
python vamp_gcp_audit.py --project my-project-id --credentials sa-key.json
# Guardar informe JSON y HTML
python vamp_gcp_audit.py --project my-project-id --json findings.json --html report.html
# Ejecutar solo módulos concretos
python vamp_gcp_audit.py --project my-project-id --modules iam firewall
# Modo silencioso (sin tabla resumen en consola)
python vamp_gcp_audit.py --project my-project-id --quiet --json out.json
Módulos de auditoría
| Módulo | Descripción |
|---|---|
iam |
Service accounts con roles excesivos, keys antiguas |
gcs |
Buckets públicos, ACLs legacy, logging/versioning |
gke |
RBAC legacy, auth estática, Network Policy, endpoints |
functions |
HTTPS, autenticación, secretos en env vars, SA por defecto |
firewall |
Puertos sensibles expuestos, allow-all, logging |
project |
APIs peligrosas, audit logging, org policy |
Permisos GCP necesarios
La cuenta o service account usada necesita los siguientes roles mínimos de solo lectura:
roles/viewer(base)roles/iam.securityReviewerroles/container.viewerroles/cloudfunctions.viewer
Exit codes
| Código | Significado |
|---|---|
0 |
Sin hallazgos CRITICAL ni HIGH |
1 |
Se encontraron hallazgos CRITICAL o HIGH |
2 |
Error de autenticación o ejecución |
Autenticación
gcloud ADC (recomendado para uso local)
gcloud auth application-default login
python vamp_gcp_audit.py --project PROJECT_ID
Service Account JSON
python vamp_gcp_audit.py --project PROJECT_ID --credentials /ruta/a/sa-key.json
© VampSecure Studios — VampSecure Labs Security Research Division. Uso exclusivo en entornos autorizados.
Metadata
Release files for vamp-gcp-audit 1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_gcp_audit-1.0.tar.gz | 22.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_gcp_audit-1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 44.8 kB
Release files / vamp_gcp_audit-1.0.tar.gz
| Download URL | vamp_gcp_audit-1.0.tar.gz |
|---|---|
| Size | 22.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
954a7e368786aaccb0e82f3524201b46ebe52d371b59e49865521768a2a7cad4
|
|
BLAKE2b-256 checksum How to use checksums |
58a55ff58943a53f4cee97abe10b38e39eafb2deeda635cd9e05216476701ef5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_gcp_audit-1.0-py3-none-any.whl
| Download URL | vamp_gcp_audit-1.0-py3-none-any.whl |
|---|---|
| Size | 22.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
30497edac9c82c854fd0a6fec63dccf9b4c3a7ed11ae00e41990e1baea1bddaf
|
|
BLAKE2b-256 checksum How to use checksums |
78fd55e87878b8d1bc42f0156a44cd3c12039f662813219b662f53f9b135a356
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|