Skip to content

EnableServiceAccount

GCP

EnableServiceAccount

service: GCP - IAM
techniques:

Event

Re-enables a service account so it can be used again subject to its current credentials, permissions, and applicable controls. This is not recovery of a deleted account.

Security Context

Unauthorized reactivation can support account manipulation (T1098). Enabling the account does not recreate deleted keys or restore revoked IAM grants; independently disabled or expired credentials require separate inspection.

Log Source

Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.EnableServiceAccount. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Establish why and when the account was disabled and whether reactivation was approved.
  3. Inspect current keys, impersonation grants, attached workloads, and effective permissions.
  4. Confirm enabled state and subsequent authentication/API use; do not infer a specific prior incident or immediate workload recovery.

Sample Event

Synthetic scenario. The example enables phoenix-backup. Its earlier disablement reason, key state, role history, and later use are not shown.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.enable invocation-id/90000000000000000000001111110000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T15:41:33.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "google.iam.admin.v1.EnableServiceAccount",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000010",
"permission": "iam.serviceAccounts.enable",
"granted": true,
"resourceAttributes": {
"service": "iam.googleapis.com",
"name": "projects/-/serviceAccounts/100000000000000000010",
"type": "iam.googleapis.com/ServiceAccount"
}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000010",
"request": {
"@type": "type.googleapis.com/google.iam.admin.v1.EnableServiceAccountRequest",
"name": "projects/fantasticlogs-prod/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com"
},
"response": {
"@type": "type.googleapis.com/google.protobuf.Empty"
}
},
"insertId": "evt001111110000",
"resource": {
"type": "service_account",
"labels": {
"email_id": "phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000010"
}
},
"timestamp": "2026-04-15T15:41:33.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T15:41:33.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.