☁️
AutomationTypeScript

GCP Post-Exploitation

by CyberStrikeus

GCP Post-Exploitation is an Automation skill for Claude Code, published by CyberStrikeus in CyberStrike.

1.7K stars269 forkson CyberStrikeus/CyberStrikeAdded 2026/08/12+4% in starsRepository updated 2026/08/12
aiai-agentai-securitybug-bountycybersecuritydevsecopsethical-hackinghackinghacking-toolllmmcpmcp-servermitre-attackoffensive-securityowasppenetration-testingpentestred-teamsecuritysecurity-tools
Install in seconds
Install GCP Post-Exploitation
Copy GCP Post-Exploitation into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/gcp-postexploit ~/.claude/skills/gcp-postexploit

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/CyberStrikeus/CyberStrike.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
.cyberstrike/skill/gcp-postexploit/SKILL.md in CyberStrikeus/CyberStrike
Installs to
~/.claude/skills/gcp-postexploit
Collection
One of 51 skills cataloged from this repository
Category
Automation1523 skills

What GCP Post-Exploitation does

GCP Post-Exploitation uses gcloud and metadata endpoint access to enumerate IAM, escalate privileges, exfiltrate data, and establish persistence in Google Cloud environments. Use it after compromising GCP credentials or a Compute Engine instance.

GCP Post-Exploitation is cataloged under Automation on DirSkills. GCP Post-Exploitation comes from a repository tagged ai, ai-agent, ai-security, bug-bounty and cybersecurity.

Documentation

README

GCP Post-Exploitation Methodology

GCP post-exploitation uses gcloud CLI and the GCE metadata endpoint (via native fetch) to perform privilege escalation, data exfiltration, and persistence after compromising service account credentials or gaining Compute Engine instance access. No Python dependency — all operations use native TypeScript with gcloud/gsutil CLI calls.

Prerequisites

Before deploying gcphook tools, verify:

  1. Valid GCP credentials — application default credentials, service account key, or metadata endpoint
  2. gcloud CLI installedgcloud version
  3. Current identitygcloud auth list to confirm active account
  4. Project — set via --project or default project

This is the opening of the README. Read the full README on GitHub.

Frequently asked about GCP Post-Exploitation

  • What else does CyberStrikeus publish alongside GCP Post-Exploitation?

    GCP Post-Exploitation is one of 51 skills that DirSkills catalogs from CyberStrikeus/CyberStrike, the repository it ships in. Its siblings there include AMI Age Compliance, AMI Encryption Check and AMI Naming Convention Compliance. Each one is a separate skill with its own page in this directory, installs the same way GCP Post-Exploitation does, and is maintained by CyberStrikeus in that same repository. The rest of the collection is listed on the CyberStrikeus/CyberStrike page.

  • How does GCP Post-Exploitation compare to other Automation skills?

    GCP Post-Exploitation ranks #542 by stars among the 1523 Automation skills in this catalog. The most-starred ones next to it are Autonomous Loops, Autonomous Agent Harness and Automation Audit Ops. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of GCP Post-Exploitation against them. Open each page to compare what they document and how they install.

More from CyberStrikeus/CyberStrike

GCP Post-Exploitation is one of 51 skills cataloged on DirSkills from CyberStrikeus/CyberStrike.

See all 51 skills