GCP Service Account key creation
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Hours
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation: Additional Cloud Credentials (T1098.001)
Severity
Informational
Description
A GCP service account key was created. An attacker might use this technique to evade detection.
Attacker's Goals
Persistence using the created key.
Investigative actions
Check what actions were taken using the newly created service account key.
Check what other actions were taken by the identity that created the key.
Was this helpful?
