Remote usage of VM Service Account token
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Steal Application Access Token (T1528), Unsecured Credentials (T1552)
Severity
Informational
Description
A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment.
Attacker's Goals
Exfiltrate token and abuse it remotely.
Investigative actions
Check if the service account was attached to a specific VM.
Check if the service account was used by a user.
Check if the relevant VM is compromised.
Variations
Was this helpful?
