Create and alter managed instance groups.

Allows creation, modification, and destruction of auto-scaling instance groups. Except for resizing, can not critically impact organizational functions.


Can be exploited for cryptojacking purposes, but additionally requires creation of corresponding instance templates. Instances may be accessible via addition to target groups.



This privilege may grant access to confidential data, or its exploit can incur operational cost.


  • https:​/​/​cloud.​google.​com/​compute/​docs/​instance-​groups
  • https:​/​/​cloud.​google.​com/​sdk/​gcloud/​reference/​compute/​instance-​groups/​managed
  • https:​/​/​cloud.​google.​com/​compute/​docs/​reference/​rest/​v1/​instanceGroupManagers
