iam.roles.update
iam.roles.update
Event
UpdateRole modifies a custom role according to its update mask and etag. A changed includedPermissions list affects principals with effective bindings to that role after propagation.
Security Context
Unauthorized broadening can support T1098. Existing bindings, scope, conditions, and applicable restrictions determine privilege gain. resourcemanager.projects.setIamPolicy is sensitive without needing actAs, but it is not an unrestricted organization-wide wildcard.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.UpdateRole. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Compare complete permission sets, updateMask, stage, and etag; identify actual additions/removals.
- Find effective bindings and their scopes/conditions to determine affected principals.
- Correlate later policy writes and access; do not infer lower detection likelihood or self-grants from role definition alone.
Sample Event
Synthetic scenario. The submitted role includes resourcemanager.projects.setIamPolicy. This record lacks the previous definition and current bindings, so an added permission and successful self-elevation require corroboration.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.roles.update invocation-id/90000000000000000000001111111000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:38:11.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.UpdateRole", "authorizationInfo": [ { "resource": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "permission": "iam.roles.update", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "type": "iam.googleapis.com/Role" } } ], "resourceName": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "request": { "@type": "type.googleapis.com/google.iam.admin.v1.UpdateRoleRequest", "name": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "role": { "name": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "title": "Pipeline break-glass", "description": "Emergency access for OCCAMY pipeline maintenance", "includedPermissions": [ "iam.roles.update", "iam.serviceAccounts.actAs", "iam.serviceAccountKeys.create", "logging.logs.delete", "logging.exclusions.create", "compute.instances.setMetadata", "resourcemanager.projects.setIamPolicy" ], "stage": "GA", "etag": "QndTQU1QTEVldGFnMTExMT0=" }, "updateMask": "includedPermissions" }, "response": { "@type": "type.googleapis.com/google.iam.admin.v1.Role", "name": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "title": "Pipeline break-glass", "description": "Emergency access for OCCAMY pipeline maintenance", "includedPermissions": [ "iam.roles.update", "iam.serviceAccounts.actAs", "iam.serviceAccountKeys.create", "logging.logs.delete", "logging.exclusions.create", "compute.instances.setMetadata", "resourcemanager.projects.setIamPolicy" ], "stage": "GA", "etag": "QndTQU1QTEVldGFnMTEwMDA9" } }, "insertId": "evt001111111000", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "service": "iam.googleapis.com", "method": "google.iam.admin.v1.UpdateRole" } }, "timestamp": "2026-04-15T15:38:11.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T15:38:11.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...