GCP administrative role granted to a cloud identity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation (T1098), Account Manipulation: Additional Cloud Roles (T1098.003)
Severity
Informational
Description
A cloud identity granted an administrative IAM role to another identity.
Attacker's Goals
Maintain persistent access or escalate privileges within cloud environment.
Investigative actions
Verify which permissions were granted to the identity.
PreviousFTP Connection Using an Anonymous Login or Default Credentials
NextGCP data asset shared public
Was this helpful?
