Skip to content

compute.disks.setIamPolicy

GCP

compute.disks.setIamPolicy

service: GCP - Compute Engine
techniques:

Event

SetIamPolicy writes the submitted resource policy, subject to etag concurrency control. A disk-level Compute Storage Admin binding applies permissions at that disk’s scope; it does not confer create permissions on an unrelated destination project. Source-disk and destination-resource authority must both be assessed.

Security Context

Unauthorized grants can provide additional cloud roles (T1098.003). This does not prove snapshot/image creation, raw data transfer, or access to every disk. A persistent disk stores blocks; native snapshots are separate resources, not inferred contents of a disk with a backup-like name.

Log Source

Google Cloud Audit Logs with protoPayload.serviceName: compute.googleapis.com and protoPayload.methodName: v1.compute.disks.setIamPolicy. Policy writes are Admin Activity records. The CLI command label is not necessarily the service method name; API versions can change the method’s prefix. Inspect status and target, not just a user-agent string.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfoEffective principal and delegation information where present.
protoPayload.methodName, resourceNameService method and resource scope.
protoPayload.authorizationInfo, statusReported authorization and outcome; a granted permission is not completion evidence.
protoPayload.request, response, metadata, serviceDataPolicy or job details and deltas, where logged; field presence varies.
operation, timestamp, logNameLong-running correlation, timing, and audit stream.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Compare full policy, etag, binding deltas, target disk, and approval; preserve relevant conditions and inherited access.
  3. Resolve the recipient identity and source/destination permissions and restrictions for any proposed snapshot/image operation.
  4. Correlate actual snapshot/image/attach activity and completion before asserting data collection or exfiltration.

Sample Event

Synthetic scenario. The sample adds a disk-scoped role for an illustrative external service account. Its project identifier and numeric disk ID were normalized. No snapshot, image, destination grant, or data transfer is shown.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.disks.add-iam-policy-binding invocation-id/90000000000000000000001111101010 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T17:18:55.778899100Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.disks.setIamPolicy",
"authorizationInfo": [
{
"permission": "compute.disks.setIamPolicy",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/zones/us-central1-a/disks/phoenix-backup-disk-001",
"type": "compute.disks"
}
}
],
"resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/disks/phoenix-backup-disk-001",
"request": {
"policy": {
"version": 1,
"bindings": [
{
"role": "roles/compute.storageAdmin",
"members": [
"serviceAccount:attacker@draco-external-666.iam.gserviceaccount.com"
]
}
],
"etag": "ZGlzay1iZWZvcmU="
}
},
"response": {
"@type": "type.googleapis.com/google.iam.v1.Policy",
"version": 1,
"bindings": [
{
"role": "roles/compute.storageAdmin",
"members": [
"serviceAccount:attacker@draco-external-666.iam.gserviceaccount.com"
]
}
],
"etag": "ZGlzay1hZnRlcg=="
},
"serviceData": {
"@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
"policyDelta": {
"bindingDeltas": [
{
"action": "ADD",
"role": "roles/compute.storageAdmin",
"member": "serviceAccount:attacker@draco-external-666.iam.gserviceaccount.com"
}
]
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
}
},
"insertId": "evt001111101010",
"resource": {
"type": "gce_disk",
"labels": {
"project_id": "fantasticlogs-prod",
"zone": "us-central1-a",
"disk_id": "610000000001111010"
}
},
"timestamp": "2026-04-15T17:18:55.900000000Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T17:18:56.001122334Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.