<  Back to rules search

GCP service account created

gcp

Classification:

attack

Tactic:

Technique:

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when a new service account is created.

Strategy

This rule lets you monitor GCP admin activity audit logs to determine when a service account is created.

Triage and response

  1. Contact the user who created the service account and ensure that the account is needed and that the role is scoped properly.