vamp-gcp-audit
VampSecure Labs · VampSecure Studios
Auditor de seguridad no-destructivo para entornos Google Cloud Platform. Detecta misconfiguraciones
críticas en IAM, GCS, GKE, Cloud Functions, Firewall y configuración de proyecto usando únicamente
la API REST de GCP (sin SDKs de google-cloud-*).
Instalación
pip install -r requirements.txt
cryptographysolo es necesaria si usas--credentialscon un fichero JSON de service account.
Uso
# Con credenciales de gcloud ADC (gcloud auth application-default login)
python vamp_gcp_audit.py --project my-project-id
# Con fichero de service account
python vamp_gcp_audit.py --project my-project-id --credentials sa-key.json
# Guardar informe JSON y HTML
python vamp_gcp_audit.py --project my-project-id --json findings.json --html report.html
# Ejecutar solo módulos concretos
python vamp_gcp_audit.py --project my-project-id --modules iam firewall
# Modo silencioso (sin tabla resumen en consola)
python vamp_gcp_audit.py --project my-project-id --quiet --json out.json
Módulos de auditoría
| Módulo | Descripción |
|---|---|
iam |
Service accounts con roles excesivos, keys antiguas |
gcs |
Buckets públicos, ACLs legacy, logging/versioning |
gke |
RBAC legacy, auth estática, Network Policy, endpoints |
functions |
HTTPS, autenticación, secretos en env vars, SA por defecto |
firewall |
Puertos sensibles expuestos, allow-all, logging |
project |
APIs peligrosas, audit logging, org policy |
Permisos GCP necesarios
La cuenta o service account usada necesita los siguientes roles mínimos de solo lectura:
roles/viewer(base)roles/iam.securityReviewerroles/container.viewerroles/cloudfunctions.viewer
Exit codes
| Código | Significado |
|---|---|
0 |
Sin hallazgos CRITICAL ni HIGH |
1 |
Se encontraron hallazgos CRITICAL o HIGH |
2 |
Error de autenticación o ejecución |
Autenticación
gcloud ADC (recomendado para uso local)
gcloud auth application-default login
python vamp_gcp_audit.py --project PROJECT_ID
Service Account JSON
python vamp_gcp_audit.py --project PROJECT_ID --credentials /ruta/a/sa-key.json
© VampSecure Studios — VampSecure Labs Security Research Division. Uso exclusivo en entornos autorizados.
Metadata
Release files for vamp-gcp-audit 1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_gcp_audit-1.1.tar.gz | 25.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_gcp_audit-1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 51.2 kB
Release files / vamp_gcp_audit-1.1.tar.gz
| Download URL | vamp_gcp_audit-1.1.tar.gz |
|---|---|
| Size | 25.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6de13f8e31cf173246b5355ff9132abb8af14336c56ab27dcfe1f531bed4696b
|
|
BLAKE2b-256 checksum How to use checksums |
d3efe454795dd5592920b1eb9ec056e171734218b9400f7ae615ce8d7aa58f63
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_gcp_audit-1.1-py3-none-any.whl
| Download URL | vamp_gcp_audit-1.1-py3-none-any.whl |
|---|---|
| Size | 26.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
74b0d99e56fd34bae44e8494fe179d2456da55d88846115275f75aa53d243819
|
|
BLAKE2b-256 checksum How to use checksums |
04cfcea410cf2b9705a7c7319c6d06a1ce4d7da076a70c188c79f6f1ee9ff3de
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|