google.iam.admin.v1.UploadServiceAccountKey
google.iam.admin.v1.UploadServiceAccountKey
Event
Associates an externally generated RSA public key, packaged as a base64-encoded X.509 v3 certificate, with a service account. The corresponding private key remains with its holder.
Security Context
Unauthorized credential addition can support T1098.001. UploadServiceAccountKey is audited; it is not invisible because key generation occurred elsewhere. Expiry, key/account disablement, deletion, and organization restrictions limit use.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.UploadServiceAccountKey. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Validate approval, target, uploader, key ID, and key-upload organization policy.
- Inspect USER_PROVIDED origin, certificate validity, and disabled state; identify who controls the corresponding private key.
- Correlate later authentication and key-specific usage where available; do not assume rotation of another credential revokes this key.
Sample Event
Synthetic scenario. The sample illustrates a USER_PROVIDED key with a one-year validity interval. Certificate bytes are omitted, so the sample is not a replayable upload request. No detection bypass or subsequent authentication is shown.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.keys.upload invocation-id/90000000000000000000001111110101 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T13:48:17.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.UploadServiceAccountKey", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000100", "permission": "iam.serviceAccountKeys.create", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/-/serviceAccounts/100000000000000000100", "type": "iam.googleapis.com/ServiceAccountKey" } } ], "resourceName": "projects/-/serviceAccounts/100000000000000000100", "request": { "@type": "type.googleapis.com/google.iam.admin.v1.UploadServiceAccountKeyRequest", "name": "projects/fantasticlogs-prod/serviceAccounts/demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com" }, "response": { "@type": "type.googleapis.com/google.iam.admin.v1.ServiceAccountKey", "name": "projects/fantasticlogs-prod/serviceAccounts/demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com/keys/60000000000000000001111110101", "validAfterTime": "2026-04-15T13:48:17Z", "validBeforeTime": "2027-04-15T13:48:17Z", "keyAlgorithm": "KEY_ALG_RSA_2048", "keyOrigin": "USER_PROVIDED", "keyType": "USER_MANAGED" } }, "insertId": "evt001111110101", "resource": { "type": "service_account", "labels": { "email_id": "demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000100" } }, "timestamp": "2026-04-15T13:48:17.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T13:48:17.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.