Covert Data Exfil with GCP and Go

Dennis Chow
System Weakness
Published in
11 min readMar 28, 2023

--

Learn how to bypass Data Loss Prevention (DLP) solutions steaming binary files to GCP Cloud Logging using Go.

Imagine that you’re a penetration tester, and you have successfully infiltrated an environment where you have staged files ready for exfiltration. The end client has a fairly mature network security program complete with DLP. How do you transfer your files without being caught?

If the client uses Google Cloud Platform (GCP), maybe using any number of trusted Application Programming Interfaces (API) that is not focused on blob storage, and…

--

--

Security Practitioner and Veteran | GSE #288, GXPN, GREM *Opinions are my own