Skip to content

google.iam.admin.v1.CreateServiceAccountKey

GCP

google.iam.admin.v1.CreateServiceAccountKey

service: GCP - IAM
techniques:

Event

Creates a key for a service account. The illustrated privateKeyType requests a Google credentials file; key creation is an IAM Admin Activity operation, not an alternate Data Access format of the create permission.

Security Context

An unauthorized extra credential can support T1098.001. Access depends on key validity, account state, and permissions. A key is not inherently permanent or immune to revocation; inspect organization policy and configured expiry.

Log Source

Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.CreateServiceAccountKey. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Verify target account, key ID, creator, approval, and applicable key-creation constraints.
  3. Inspect key type/origin, validity, disabled state, and the account’s effective permissions.
  4. Correlate key-specific usage where available; investigate exposure and subsequent activity separately from creation.

Sample Event

Synthetic scenario. The sample illustrates a USER_MANAGED, GOOGLE_PROVIDED key for occamy-pipeline. Private key material is intentionally absent and must not be used as a detection field.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud",
"principalSubject": "user:draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.keys.create invocation-id/90000000000000000000000000000001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T13:42:11.123456789Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "google.iam.admin.v1.CreateServiceAccountKey",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000001",
"permission": "iam.serviceAccountKeys.create",
"granted": true,
"resourceAttributes": {
"name": "projects/-/serviceAccounts/100000000000000000001",
"service": "iam.googleapis.com",
"type": "iam.googleapis.com/ServiceAccountKey"
}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000001",
"request": {
"@type": "type.googleapis.com/google.iam.admin.v1.CreateServiceAccountKeyRequest",
"name": "projects/fantasticlogs-prod/serviceAccounts/occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"privateKeyType": "TYPE_GOOGLE_CREDENTIALS_FILE",
"keyAlgorithm": "KEY_ALG_RSA_2048"
},
"response": {
"@type": "type.googleapis.com/google.iam.admin.v1.ServiceAccountKey",
"name": "projects/fantasticlogs-prod/serviceAccounts/occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com/keys/60000000000000000000000000000001",
"validAfterTime": "2026-04-15T13:42:11Z",
"validBeforeTime": "9999-12-31T23:59:59Z",
"keyAlgorithm": "KEY_ALG_RSA_2048",
"keyOrigin": "GOOGLE_PROVIDED",
"keyType": "USER_MANAGED"
}
},
"insertId": "evt0000000001",
"resource": {
"type": "service_account",
"labels": {
"email_id": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000001"
}
},
"timestamp": "2026-04-15T13:42:11.323456Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T13:42:11.723456Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.