Skip to content

Conversation

@tsmithv11
Copy link
Contributor

Adds a GCP avoid-detection page documenting Apps Script project impersonation and persistence (based on research by Bleon Proko and Jakub Pavlik). Includes attack steps, detection checks using billing & enabled services, and mitigations.

@tsmithv11 tsmithv11 marked this pull request as ready for review October 8, 2025 18:42
Copy link
Contributor

@Frichetten Frichetten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you so much for your submission! Efforts like yours make Hacking the Cloud possible! I left a few comments, feel free to make some changes or double check those. Whenever you're ready I'm happy to merge it in!

@Frichetten
Copy link
Contributor

Looks great! Thank you so much for this! I'll let CI/CD run and as long as it passes I'll merge it.

@Frichetten Frichetten merged commit 115f831 into Hacking-the-Cloud:main Oct 9, 2025
1 check passed
@Frichetten
Copy link
Contributor

I should ask, do you have a preferred social media platform? I'd love to give you a shoutout when I post it

@tsmithv11
Copy link
Contributor Author

Thanks, @Frichetten! I'm a big fan of HtC! This is me on X: https://x.com/ifoundanifty

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants