For the complete documentation index, see llms.txt. This page is also available as Markdown.

Remote usage of an App engine Service Account token

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Application Access Token (T1528), Unsecured Credentials (T1552)

Severity

Informational

Description

A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment.

Attacker's Goals

Exfiltrate token and abuse it remotely.

Investigative actions

  • Check if the Service Account was attached to a specific app engine.

  • Check if the Service Account was used by a user.

  • Check if the relevant app engine is compromised.

Variations

Suspicious usage of App engine Service Account token

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Application Access Token (T1528), Unsecured Credentials (T1552)

Severity

High

Description

A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment.

Attacker's Goals

Exfiltrate token and abuse it remotely.

Investigative actions

  • Check if the Service Account was attached to a specific app engine.

  • Check if the Service Account was used by a user.

  • Check if the relevant app engine is compromised.

Was this helpful?