Skip to content

iam.serviceAccounts.actAs

GCP

iam.serviceAccounts.actAs

service: GCP - IAM
techniques:

Event

An actAs audit record reports a service-account attachment authorization check. actAs alone does not grant direct short-lived token generation; resource deployment/update permissions are also needed for an attached workload.

Security Context

Unauthorized attachment to a controllable workload can enable T1548.005 when its service account provides greater authority. A successful check does not establish deployment completion, execution, token retrieval, or exfiltration.

Log Source

Cloud Audit Logs: iam.googleapis.com, method iam.serviceAccounts.actAs. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Verify the caller, target service account, actAs result, and approved deployment.
  3. Correlate the separate resource create/update operation and its final runtime identity.
  4. Assess workload control, account permissions, and subsequent activity rather than inferring a malicious function from user-agent text.

Sample Event

Synthetic scenario. The documented CanActAsServiceAccountRequest/Response shape illustrates a successful check. The function-deployment user agent is context only; no function code, runtime token, or data transfer is shown.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.functions.deploy invocation-id/90000000000000000000001111111011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T16:51:08.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "iam.serviceAccounts.actAs",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com",
"permission": "iam.serviceAccounts.actAs",
"granted": true,
"permissionType": "ADMIN_WRITE"
}
],
"resourceName": "projects/-/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com",
"request": {
"@type": "type.googleapis.com/CanActAsServiceAccountRequest",
"name": "phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com",
"project_number": "555123456789"
},
"response": {
"@type": "type.googleapis.com/CanActAsServiceAccountResponse",
"success": true
}
},
"insertId": "evt001111111011",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "fantasticlogs-prod",
"method": "iam.serviceAccounts.actAs",
"service": "iam.googleapis.com"
}
},
"timestamp": "2026-04-15T16:51:08.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T16:51:08.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1548.005 — Temporary Elevated Cloud Access — Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto re...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.