GCP service account impersonation attempt
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Privilege Escalation (TA0004), Initial Access (TA0001)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005), Trusted Relationship (T1199)
Severity
Informational
Description
An attempt to impersonate the GCP service account failed.
Attacker's Goals
Escalate privileges to gain elevated access to cloud resources.
Investigative actions
Review activity on the target service account.
Check which principals have permission to impersonate the service account.
Was this helpful?
