Skip to content

iam.roles.update

GCP

iam.roles.update

service: GCP - IAM
techniques:

Event

UpdateRole modifies a custom role according to its update mask and etag. A changed includedPermissions list affects principals with effective bindings to that role after propagation.

Security Context

Unauthorized broadening can support T1098. Existing bindings, scope, conditions, and applicable restrictions determine privilege gain. resourcemanager.projects.setIamPolicy is sensitive without needing actAs, but it is not an unrestricted organization-wide wildcard.

Log Source

Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.UpdateRole. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Compare complete permission sets, updateMask, stage, and etag; identify actual additions/removals.
  3. Find effective bindings and their scopes/conditions to determine affected principals.
  4. Correlate later policy writes and access; do not infer lower detection likelihood or self-grants from role definition alone.

Sample Event

Synthetic scenario. The submitted role includes resourcemanager.projects.setIamPolicy. This record lacks the previous definition and current bindings, so an added permission and successful self-elevation require corroboration.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.roles.update invocation-id/90000000000000000000001111111000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T15:38:11.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "google.iam.admin.v1.UpdateRole",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"permission": "iam.roles.update",
"granted": true,
"resourceAttributes": {
"service": "iam.googleapis.com",
"name": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"type": "iam.googleapis.com/Role"
}
}
],
"resourceName": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"request": {
"@type": "type.googleapis.com/google.iam.admin.v1.UpdateRoleRequest",
"name": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"role": {
"name": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"title": "Pipeline break-glass",
"description": "Emergency access for OCCAMY pipeline maintenance",
"includedPermissions": [
"iam.roles.update",
"iam.serviceAccounts.actAs",
"iam.serviceAccountKeys.create",
"logging.logs.delete",
"logging.exclusions.create",
"compute.instances.setMetadata",
"resourcemanager.projects.setIamPolicy"
],
"stage": "GA",
"etag": "QndTQU1QTEVldGFnMTExMT0="
},
"updateMask": "includedPermissions"
},
"response": {
"@type": "type.googleapis.com/google.iam.admin.v1.Role",
"name": "projects/fantasticlogs-prod/roles/pipeline_break_glass",
"title": "Pipeline break-glass",
"description": "Emergency access for OCCAMY pipeline maintenance",
"includedPermissions": [
"iam.roles.update",
"iam.serviceAccounts.actAs",
"iam.serviceAccountKeys.create",
"logging.logs.delete",
"logging.exclusions.create",
"compute.instances.setMetadata",
"resourcemanager.projects.setIamPolicy"
],
"stage": "GA",
"etag": "QndTQU1QTEVldGFnMTEwMDA9"
}
},
"insertId": "evt001111111000",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "fantasticlogs-prod",
"service": "iam.googleapis.com",
"method": "google.iam.admin.v1.UpdateRole"
}
},
"timestamp": "2026-04-15T15:38:11.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T15:38:11.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.