iam.serviceAccounts.signJwt
iam.serviceAccounts.signJwt
Event
SignJwt signs a supplied JWT payload after authorization. A suitably formed signed assertion can be exchanged for an OAuth token, but signing and token exchange are distinct operations.
Security Context
Abusing signing authority can support T1548.005. This is a documented credential capability, not proof that IAM was bypassed or an existing token was stolen. Effective target permissions and successful subsequent use determine impact.
Log Source
Cloud Audit Logs: iamcredentials.googleapis.com, method SignJwt. Data Access; enable the relevant IAM Credentials audit logging and check exemptions, routing, retention, and viewer access.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Confirm caller, target, signing authority, delegation, and approved purpose.
- Inspect issuer, audience, requested scopes, and iat/exp where logged; payload availability must be validated.
- Correlate token exchange or downstream resource access without assuming every SignJwt call yields a usable OAuth token.
Sample Event
Synthetic scenario. The sample contains an inert JSON claim set with corrected issuance/expiry timestamps and no signed JWT. It does not show token exchange, missing getAccessToken authority, or downstream access.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud", "principalSubject": "user:draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.sign-jwt invocation-id/90000000000000000000001111111101 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:01:18.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iamcredentials.googleapis.com", "methodName": "SignJwt", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000100", "permission": "iam.serviceAccounts.signJwt", "granted": true, "resourceAttributes": {} } ], "resourceName": "projects/-/serviceAccounts/100000000000000000100", "request": { "@type": "type.googleapis.com/google.iam.credentials.v1.SignJwtRequest", "name": "projects/-/serviceAccounts/demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com", "payload": "{\"iss\":\"demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com\",\"aud\":\"https://oauth2.googleapis.com/token\",\"scope\":\"https://www.googleapis.com/auth/cloud-platform\",\"iat\":1776272478,\"exp\":1776276078}" }, "response": { "@type": "type.googleapis.com/google.iam.credentials.v1.SignJwtResponse", "keyId": "60000000000000000000000000000111" } }, "insertId": "evt001111111101", "resource": { "type": "service_account", "labels": { "email_id": "demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000100" } }, "timestamp": "2026-04-15T17:01:18.421987Z", "severity": "INFO", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "receiveTimestamp": "2026-04-15T17:01:18.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1548.005 — Temporary Elevated Cloud Access — Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto re...