Skip to content

google.iam.admin.v1.UploadServiceAccountKey

GCP

google.iam.admin.v1.UploadServiceAccountKey

service: GCP - IAM
tactics:
techniques:

Event

Associates an externally generated RSA public key, packaged as a base64-encoded X.509 v3 certificate, with a service account. The corresponding private key remains with its holder.

Security Context

Unauthorized credential addition can support T1098.001. UploadServiceAccountKey is audited; it is not invisible because key generation occurred elsewhere. Expiry, key/account disablement, deletion, and organization restrictions limit use.

Log Source

Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.UploadServiceAccountKey. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Validate approval, target, uploader, key ID, and key-upload organization policy.
  3. Inspect USER_PROVIDED origin, certificate validity, and disabled state; identify who controls the corresponding private key.
  4. Correlate later authentication and key-specific usage where available; do not assume rotation of another credential revokes this key.

Sample Event

Synthetic scenario. The sample illustrates a USER_PROVIDED key with a one-year validity interval. Certificate bytes are omitted, so the sample is not a replayable upload request. No detection bypass or subsequent authentication is shown.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.keys.upload invocation-id/90000000000000000000001111110101 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T13:48:17.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "google.iam.admin.v1.UploadServiceAccountKey",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000100",
"permission": "iam.serviceAccountKeys.create",
"granted": true,
"resourceAttributes": {
"service": "iam.googleapis.com",
"name": "projects/-/serviceAccounts/100000000000000000100",
"type": "iam.googleapis.com/ServiceAccountKey"
}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000100",
"request": {
"@type": "type.googleapis.com/google.iam.admin.v1.UploadServiceAccountKeyRequest",
"name": "projects/fantasticlogs-prod/serviceAccounts/demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com"
},
"response": {
"@type": "type.googleapis.com/google.iam.admin.v1.ServiceAccountKey",
"name": "projects/fantasticlogs-prod/serviceAccounts/demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com/keys/60000000000000000001111110101",
"validAfterTime": "2026-04-15T13:48:17Z",
"validBeforeTime": "2027-04-15T13:48:17Z",
"keyAlgorithm": "KEY_ALG_RSA_2048",
"keyOrigin": "USER_PROVIDED",
"keyType": "USER_MANAGED"
}
},
"insertId": "evt001111110101",
"resource": {
"type": "service_account",
"labels": {
"email_id": "demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000100"
}
},
"timestamp": "2026-04-15T13:48:17.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T13:48:17.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.