Mapping Shadows in the Cloud: Exploring Google Cloud Attack Paths with GCP-Hound and OG | SO-CON 26

Mapping Shadows in the Cloud: Exploring Google Cloud Attack Paths with GCP-Hound and OG | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 31:59

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

The speaker introduces a methodology for mapping attack paths in Google Cloud Platform (GCP) using tools like GCP Hound and BloodHound to visualize infrastructure shadows 0:00.

Key Takeaways:
• The presentation focuses on exploring GCP attack paths by leveraging graph-based visualization tools to identify complex relationships and vulnerabilities within cloud environments 0:04.
• The speaker, an offensive security consultant, outlines an agenda that likely includes technical demonstrations of how these tools map cloud infrastructure to enhance threat hunting and adversary simulation capabilities 0:52.

By applying these graphing techniques, security professionals can better understand and mitigate risks associated with cloud misconfigurations and privilege escalation paths.

Sources:

  • 0:00 Introduction to the talk on mapping shadows in the cloud.
  • 0:04 Overview of using GCP Hound and BloodHound for attack path exploration.
  • 0:52 Presentation agenda and structure outline.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome all of you to my talk on mapping the shadows in the cloud exploring Google Cloud attack path with GCP Hound and the Bloodhound and open graph. So, let's start let's start the talk. Little introduction about me so uh I am from India working in Cybers as a senior offensive security consultant. So, I have more than 6 plus year of experience uh working in both side of the security blue and red team and I'm well versed with the adversary simulation, threat hunting uh threat hunting, adversary simulation, and a lot of stuff such as social engineering, wishing, fishing, and all. Uh apart from work, I love to travel and I also love adventure sports, trekking, and all. This is So, this is our agenda for today's talk where we'll start with the idea, motivation, and credits to build this tool…