GCP sensitive Deployment Manager role granted
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation (T1098), Account Manipulation: Additional Cloud Roles (T1098.003)
Severity
Informational
Description
A cloud identity granted itself a sensitive Deployment Manager IAM role.
Attacker's Goals
Maintain persistent access or escalate privileges within the cloud environment.
Investigative actions
Verify which permissions were granted to the identity.
Variations
Was this helpful?
