vamp-gcp-audit
VampSecure Labs · VampSecure Studios
Auditor de seguridad no-destructivo para entornos Google Cloud Platform. Detecta misconfiguraciones
críticas en IAM, GCS, GKE, Cloud Functions, Firewall y configuración de proyecto usando únicamente
la API REST de GCP (sin SDKs de google-cloud-*).
Instalación
pip install -r requirements.txt
cryptographysolo es necesaria si usas--credentialscon un fichero JSON de service account.
Uso
# Con credenciales de gcloud ADC (gcloud auth application-default login)
python vamp_gcp_audit.py --project my-project-id
# Con fichero de service account
python vamp_gcp_audit.py --project my-project-id --credentials sa-key.json
# Guardar informe JSON y HTML
python vamp_gcp_audit.py --project my-project-id --json findings.json --html report.html
# Ejecutar solo módulos concretos
python vamp_gcp_audit.py --project my-project-id --modules iam firewall
# Modo silencioso (sin tabla resumen en consola)
python vamp_gcp_audit.py --project my-project-id --quiet --json out.json
Módulos de auditoría
| Módulo | Descripción |
|---|---|
iam |
Service accounts con roles excesivos, keys antiguas |
gcs |
Buckets públicos, ACLs legacy, logging/versioning |
gke |
RBAC legacy, auth estática, Network Policy, endpoints |
functions |
HTTPS, autenticación, secretos en env vars, SA por defecto |
firewall |
Puertos sensibles expuestos, allow-all, logging |
project |
APIs peligrosas, audit logging, org policy |
Permisos GCP necesarios
La cuenta o service account usada necesita los siguientes roles mínimos de solo lectura:
roles/viewer(base)roles/iam.securityReviewerroles/container.viewerroles/cloudfunctions.viewer
Exit codes
| Código | Significado |
|---|---|
0 |
Sin hallazgos CRITICAL ni HIGH |
1 |
Se encontraron hallazgos CRITICAL o HIGH |
2 |
Error de autenticación o ejecución |
Autenticación
gcloud ADC (recomendado para uso local)
gcloud auth application-default login
python vamp_gcp_audit.py --project PROJECT_ID
Service Account JSON
python vamp_gcp_audit.py --project PROJECT_ID --credentials /ruta/a/sa-key.json
© VampSecure Studios — VampSecure Labs Security Research Division. Uso exclusivo en entornos autorizados.
Metadata
Release files for vamp-gcp-audit 1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_gcp_audit-1.2.tar.gz | 27.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_gcp_audit-1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 55.8 kB
Release files / vamp_gcp_audit-1.2.tar.gz
| Download URL | vamp_gcp_audit-1.2.tar.gz |
|---|---|
| Size | 27.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3db9a495778558a63c1f46a75d896f511423f97f7866f10b1ea4c7288ccc1d69
|
|
BLAKE2b-256 checksum How to use checksums |
a3bb1931ea15b9378fa3049c8e13a106944cae5cd403f8e3a9e0796d53130333
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_gcp_audit-1.2-py3-none-any.whl
| Download URL | vamp_gcp_audit-1.2-py3-none-any.whl |
|---|---|
| Size | 28.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
93d07ccd84376cd99924078873da3a62dd71195b6b2e32de4c508a8349f4f7f2
|
|
BLAKE2b-256 checksum How to use checksums |
3422090d7165a1c0ed82a9b68ad8073e3a98afc7a16c6e4c8f3ba4318d59ca39
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|