For the complete documentation index, see llms.txt. This page is also available as Markdown.

Remote usage of VM Service Account token

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Application Access Token (T1528), Unsecured Credentials (T1552)

Severity

Informational

Description

A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment.

Attacker's Goals

Exfiltrate token and abuse it remotely.

Investigative actions

  • Check if the service account was attached to a specific VM.

  • Check if the service account was used by a user.

  • Check if the relevant VM is compromised.

Variations

Suspicious usage of VM Service Account token

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Steal Application Access Token (T1528), Unsecured Credentials (T1552)

Severity

High

Description

A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment.

Attacker's Goals

Exfiltrate token and abuse it remotely.

Investigative actions

  • Check if the service account was attached to a specific VM.

  • Check if the service account was used by a user.

  • Check if the relevant VM is compromised.

Was this helpful?