Skip to content

add-iam-policy-binding

GCP

add-iam-policy-binding

service: GCP - IAM
techniques:

Event

add-iam-policy-binding is a gcloud command pattern, not an audit method name. The project example uses Resource Manager SetIamPolicy, which applies the submitted policy fields rather than appending a single binding automatically. Preserve intended existing bindings and use etag concurrency control; conditional policies require compatible policy versions.

Security Context

Unauthorized additional roles can support T1098.003. Actual access depends on role, resource scope, conditions, inherited policy, and other applicable restrictions. The actor already needs policy-write authority; self-assignment is not proof of how that authority was obtained.

Log Source

Google Cloud Audit Logs with protoPayload.serviceName: cloudresourcemanager.googleapis.com and protoPayload.methodName: SetIamPolicy. Policy writes are Admin Activity records. The CLI command label is not necessarily the service method name; API versions can change the method’s prefix. Inspect status and target, not just a user-agent string.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfoEffective principal and delegation information where present.
protoPayload.methodName, resourceNameService method and resource scope.
protoPayload.authorizationInfo, statusReported authorization and outcome; a granted permission is not completion evidence.
protoPayload.request, response, metadata, serviceDataPolicy or job details and deltas, where logged; field presence varies.
operation, timestamp, logNameLong-running correlation, timing, and audit stream.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the actual service, method, project/resource, actor, and policy-write authorization.
  3. Compare complete before/after policy or recorded binding deltas, checking unintended removals as well as additions.
  4. Evaluate effective access and subsequent resource use; confirm organizational constraints and legitimate provisioning context.

Sample Event

Synthetic scenario. The corrected sample adds Draco to roles/editor while retaining the existing owner and other bindings. Request and response now contain consistent binding sets. It avoids assuming an unrestricted user Owner grant through the API.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.projects.add-iam-policy-binding invocation-id/90000000000000000000000000000001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws)",
"requestAttributes": {
"time": "2026-04-15T13:42:11.123456789Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "cloudresourcemanager.googleapis.com",
"methodName": "SetIamPolicy",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod",
"permission": "resourcemanager.projects.setIamPolicy",
"granted": true,
"resourceAttributes": {}
}
],
"resourceName": "projects/fantasticlogs-prod",
"request": {
"@type": "type.googleapis.com/google.iam.v1.SetIamPolicyRequest",
"resource": "projects/fantasticlogs-prod",
"policy": {
"bindings": [
{
"role": "roles/owner",
"members": [
"user:hermione@fantasticlogs.cloud"
]
},
{
"role": "roles/editor",
"members": [
"serviceAccount:555123456789-compute@developer.gserviceaccount.com",
"user:draco@fantasticlogs.cloud"
]
},
{
"role": "roles/iam.serviceAccountUser",
"members": [
"serviceAccount:occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com"
]
}
],
"etag": "c3ludGhldGljLWJlZm9yZQ=="
},
"updateMask": "bindings,etag"
},
"response": {
"@type": "type.googleapis.com/google.iam.v1.Policy",
"bindings": [
{
"role": "roles/owner",
"members": [
"user:hermione@fantasticlogs.cloud"
]
},
{
"role": "roles/editor",
"members": [
"serviceAccount:555123456789-compute@developer.gserviceaccount.com",
"user:draco@fantasticlogs.cloud"
]
},
{
"role": "roles/iam.serviceAccountUser",
"members": [
"serviceAccount:occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com"
]
}
],
"etag": "c3ludGhldGljLWFmdGVy"
},
"serviceData": {
"@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
"policyDelta": {
"bindingDeltas": [
{
"action": "ADD",
"role": "roles/editor",
"member": "user:draco@fantasticlogs.cloud"
}
]
}
}
},
"insertId": "evt0000000001",
"resource": {
"type": "project",
"labels": {
"project_id": "fantasticlogs-prod"
}
},
"timestamp": "2026-04-15T13:42:11.123456789Z",
"severity": "NOTICE",
"receiveTimestamp": "2026-04-15T13:42:11.234567890Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.