compute.instances.setServiceAccount
compute.instances.setServiceAccount
Event
Changes the attached service account and requested access scopes on a stopped VM. The caller needs authority to update the instance and act as the selected service account. A prior stop event may be absent if the VM was already stopped.
Security Context
An unauthorized change to a more privileged identity can support account manipulation (T1098). Compare actual effective permissions: the cloud-platform OAuth scope does not grant IAM roles, and default service accounts are not inherently Editor. Access scopes can further constrain OAuth API access; they are not a universal boundary for all authentication protocols. Workload control and subsequent credential use require separate evidence.
Log Source
Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.instances.setServiceAccount. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Principal, delegation where present, caller context, and request timing. |
protoPayload.methodName, resourceName | Exact service method and target resource. |
protoPayload.authorizationInfo | Recorded permission checks; granted does not establish operation completion. |
protoPayload.request, response, metadata | Requested settings and available operation/delta details; presence and serialization vary. |
operation.id, first, last; protoPayload.status | Correlate start/completion records and inspect errors. |
protoPayload.response.status, error | RUNNING is incomplete; DONE must still be checked for operation errors. |
What to Investigate
- Confirm the actor, target, timing, and outcome against the approved change.
- Verify caller authority, including compute.instances.setServiceAccount and iam.serviceAccounts.actAs, plus the approved target identity.
- Compare old/new attached accounts, effective IAM permissions and scopes; establish whether permissions increased rather than inferring privilege from a name.
- Confirm the VM was stopped, inspect operation completion and any restart, then correlate later workload/API activity under the attached identity.
Sample Event
Synthetic scenario. The sample requests phoenix-backup with cloud-platform scope on i-sandbox-decoy-001. It does not show the previous account, either account’s IAM roles, completed replacement, token retrieval, or later data access.
Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.instances.set-service-account invocation-id/90000000000000000000001111101101 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T14:48:27.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "compute.googleapis.com", "methodName": "v1.compute.instances.setServiceAccount", "authorizationInfo": [ { "permission": "compute.instances.setServiceAccount", "granted": true, "resourceAttributes": { "service": "compute", "name": "projects/fantasticlogs-prod/zones/us-central1-a/instances/i-sandbox-decoy-001", "type": "compute.instances" } }, { "permission": "iam.serviceAccounts.actAs", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/-/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com", "type": "iam.googleapis.com/ServiceAccount" } } ], "resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/instances/i-sandbox-decoy-001", "request": { "@type": "type.googleapis.com/compute.instances.setServiceAccount", "email": "phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com", "scopes": [ "https://www.googleapis.com/auth/cloud-platform" ] }, "response": { "@type": "type.googleapis.com/operation", "id": "8200000000000000024", "name": "operation-1776268107000-62fa2ad07a201-ab001101-cd001101", "operationType": "setServiceAccount", "targetId": "6100000000000000012", "targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/instances/i-sandbox-decoy-001", "selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/operations/operation-1776268107000-62fa2ad07a201-ab001101-cd001101", "zone": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a", "user": "draco@fantasticlogs.cloud", "status": "RUNNING", "progress": 0, "insertTime": "2026-04-15T07:48:27.301-07:00", "startTime": "2026-04-15T07:48:27.318-07:00" }, "resourceLocation": { "currentLocations": [ "us-central1-a" ] } }, "insertId": "evt001111101101", "resource": { "type": "gce_instance", "labels": { "project_id": "fantasticlogs-prod", "zone": "us-central1-a", "instance_id": "6100000000000000012" } }, "timestamp": "2026-04-15T14:48:27.550000000Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "operation": { "id": "operation-1776268107000-62fa2ad07a201-ab001101-cd001101", "producer": "compute.googleapis.com", "first": true }, "receiveTimestamp": "2026-04-15T14:48:27.567890123Z"}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...