GCP sensitive storage role granted
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004)
ATT&CK Technique
Account Manipulation (T1098), Account Manipulation: Additional Cloud Roles (T1098.003)
Severity
Informational
Description
A cloud identity granted itself a sensitive storage IAM role.
Attacker's Goals
Maintain persistent access or escalate privileges within cloud environment.
Investigative actions
Verify which permissions were granted to the identity.
Variations
Was this helpful?
