Skip to content

generateAccessToken

GCP

generateAccessToken

service: GCP - IAM
techniques:

Event

GenerateAccessToken issues service-account credentials under authorized impersonation. Requested scopes and lifetime constrain the token; the target account’s effective permissions determine accessible resources.

Security Context

Unauthorized token issuance can support temporary elevated cloud access (T1548.005) if the target has greater authority. Issuance is not evidence of stealing an existing token or using it against another service. Actor/target differences also occur in approved automation.

Log Source

Cloud Audit Logs: iamcredentials.googleapis.com, method GenerateAccessToken. Data Access; enable the relevant IAM Credentials audit logging and check exemptions, routing, retention, and viewer access.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Verify the initiating principal, target account, delegation, and authority to generate tokens.
  3. Review requested scopes and lifetime against the target’s effective permissions and approved workflow.
  4. Correlate issuance with downstream API logs and delegation attribution; establish actual privilege gain and use separately.

Sample Event

Synthetic scenario. The sample requests a one-hour token for occamy-pipeline. Token material is omitted; neither theft nor downstream activity is shown. The unverified identityDelegationChain field was removed.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud",
"principalSubject": "user:draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.auth.print-access-token invocation-id/90000000000000000000000000000101 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T16:24:57.998877665Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iamcredentials.googleapis.com",
"methodName": "GenerateAccessToken",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000001",
"permission": "iam.serviceAccounts.getAccessToken",
"granted": true,
"resourceAttributes": {}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000001",
"request": {
"@type": "type.googleapis.com/google.iam.credentials.v1.GenerateAccessTokenRequest",
"name": "projects/-/serviceAccounts/occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"scope": [
"https://www.googleapis.com/auth/cloud-platform"
],
"lifetime": "3600s"
},
"response": {
"@type": "type.googleapis.com/google.iam.credentials.v1.GenerateAccessTokenResponse",
"expireTime": "2026-04-15T17:24:57.998877Z"
}
},
"insertId": "evt0000000101",
"resource": {
"type": "service_account",
"labels": {
"email_id": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000001"
}
},
"timestamp": "2026-04-15T16:24:58.198877Z",
"severity": "INFO",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
"receiveTimestamp": "2026-04-15T16:24:58.598877Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1548.005 — Temporary Elevated Cloud Access — Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto re...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.