Remote usage of an App engine Service Account token
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal Application Access Token (T1528), Unsecured Credentials (T1552)
Severity
Informational
Description
A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment.
Attacker's Goals
Exfiltrate token and abuse it remotely.
Investigative actions
Check if the Service Account was attached to a specific app engine.
Check if the Service Account was used by a user.
Check if the relevant app engine is compromised.
Variations
Was this helpful?
