{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gcp-secret-manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Google Cloud Platform","GCP Secret Manager"],"_cs_severities":["high"],"_cs_tags":["cloud","gcp","reconnaissance","discovery"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eThis detection brief addresses the risk of reconnaissance within Google Cloud Platform environments, specifically targeting the Secret Manager service. Attackers or unauthorized users may perform mass enumeration of secrets across a GCP organization or folder to map the environment and identify high-value targets. While the \u003ccode\u003eListSecrets\u003c/code\u003e API method does not return the actual sensitive secret payload, it serves as a critical discovery step. By identifying which projects contain secrets, an adversary can prioritize subsequent \u003ccode\u003eAccessSecretVersion\u003c/code\u003e or \u003ccode\u003eGetSecret\u003c/code\u003e calls to exfiltrate credentials.\u003c/p\u003e\n\u003cp\u003eDefenders should look for a single identity or source IP performing \u003ccode\u003eListSecrets\u003c/code\u003e across 10 or more distinct project IDs in a short lookback interval. This behavior is rarely seen from human users and is typically reserved for automated CSPM tooling, security scanners, or inventory jobs. Distinguishing malicious enumeration from authorized automation requires correlating the identity, source IP, and user-agent string against known enterprise tooling and change management records.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful reconnaissance via Secret Manager enumeration facilitates targeted attacks against production workloads. If an adversary discovers secrets in specific projects, they may attempt to access sensitive configuration data, database credentials, or API keys, leading to potential data exfiltration or environment-wide compromise. The broad scope of this discovery technique allows attackers to map an entire cloud footprint efficiently.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable \u003ccode\u003eDATA_READ\u003c/code\u003e audit logging for the Google Cloud Secret Manager API to ensure \u003ccode\u003eListSecrets\u003c/code\u003e events are captured in the environment's audit logs.\u003c/li\u003e\n\u003cli\u003eDeploy detection logic to alert on any principal performing \u003ccode\u003eListSecrets\u003c/code\u003e across 10 or more distinct GCP projects within a 5-minute interval.\u003c/li\u003e\n\u003cli\u003eEstablish an allowlist of authorized security scanners, CSPM services, and CI/CD service accounts to reduce noise in the alerting pipeline.\u003c/li\u003e\n\u003cli\u003eAudit IAM policies to enforce the principle of least privilege, ensuring human users and service accounts possess only the permissions required for their specific projects rather than broad, cross-project listing capabilities.\u003c/li\u003e\n\u003cli\u003eInvestigate \u003ccode\u003eevent.outcome\u003c/code\u003e fields to identify failed permission probing, which often precedes successful enumeration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T21:46:46Z","date_published":"2026-08-24T21:46:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gcp-secret-manager-discovery/","summary":"This threat brief details the detection of potential reconnaissance activity where an identity performs high-volume ListSecrets calls across multiple Google Cloud projects, a technique used for cloud service discovery.","title":"GCP Secret Manager Cross-Project Secret Enumeration","url":"https://feed.craftedsignal.io/briefs/2026-08-gcp-secret-manager-discovery/"}],"language":"en","title":"CraftedSignal Threat Feed - GCP Secret Manager","version":"https://jsonfeed.org/version/1.1"}