Create an Admin GCP Service Account
Platform: GCP
Mappings
- MITRE ATT&CK
- Persistence
- Privilege Escalation
Description
Establishes persistence by creating a new service account and assigning it
owner permissions inside the current GCP project.
Warm-up: None
Detonation:
- Create a service account
- Update the current GCP project's IAM policy to bind the service account to the
ownerrole'
References:
Instructions
Detection
Using the following GCP Admin Activity audit logs events:
google.iam.admin.v1.CreateServiceAccountSetIamPolicywithresource.type=project