Pre-Requisite: In order to complete the following onboard steps you will need to have privileges to: create a new GCP project, create a service account, and modify your organizations IAM policy.
A video tutorial describing the GCP onboarding process is available here.
Click on https://console.cloud.google.com/projectcreate and create a new project. Ensure that the project gets created in your organization.
Click on each link below and then “Enable API” button near the top of the page. Ensure that the newly created project is currently selected in the project list drop down.
This enables us to enumerate secrets (note that we cannot access secrets value, only secrets metadata)
Cloud Key Management Service API
https://console.cloud.google.com/apis/library/cloudkms.googleapis.com
This enables us to enumerate cryptographic keys (note that we cannot retrieve the key itself, just its metadata)
Go to https://console.cloud.google.com/iam-admin/serviceaccounts/create and then:
Go to https://console.cloud.google.com/iam-admin/iam and then:
Go to https://console.cloud.google.com and then, at the top of the page, click on the project selection drop-down list (the down arrow). On the window that appears, on the right side, click the three vertical dots, then click Settings. Your organization id will appear on the settings page.
Send the JSON file (from Step 3) and organization ID (from step 5) to support@datatheorem.com
https://cloud.google.com/iam/docs/understanding-service-accounts