Skip to content

iam.serviceAccounts.signJwt

GCP

iam.serviceAccounts.signJwt

service: GCP - IAM
techniques:

Event

SignJwt signs a supplied JWT payload after authorization. A suitably formed signed assertion can be exchanged for an OAuth token, but signing and token exchange are distinct operations.

Security Context

Abusing signing authority can support T1548.005. This is a documented credential capability, not proof that IAM was bypassed or an existing token was stolen. Effective target permissions and successful subsequent use determine impact.

Log Source

Cloud Audit Logs: iamcredentials.googleapis.com, method SignJwt. Data Access; enable the relevant IAM Credentials audit logging and check exemptions, routing, retention, and viewer access.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Confirm caller, target, signing authority, delegation, and approved purpose.
  3. Inspect issuer, audience, requested scopes, and iat/exp where logged; payload availability must be validated.
  4. Correlate token exchange or downstream resource access without assuming every SignJwt call yields a usable OAuth token.

Sample Event

Synthetic scenario. The sample contains an inert JSON claim set with corrected issuance/expiry timestamps and no signed JWT. It does not show token exchange, missing getAccessToken authority, or downstream access.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud",
"principalSubject": "user:draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.sign-jwt invocation-id/90000000000000000000001111111101 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T17:01:18.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iamcredentials.googleapis.com",
"methodName": "SignJwt",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000100",
"permission": "iam.serviceAccounts.signJwt",
"granted": true,
"resourceAttributes": {}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000100",
"request": {
"@type": "type.googleapis.com/google.iam.credentials.v1.SignJwtRequest",
"name": "projects/-/serviceAccounts/demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com",
"payload": "{\"iss\":\"demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com\",\"aud\":\"https://oauth2.googleapis.com/token\",\"scope\":\"https://www.googleapis.com/auth/cloud-platform\",\"iat\":1776272478,\"exp\":1776276078}"
},
"response": {
"@type": "type.googleapis.com/google.iam.credentials.v1.SignJwtResponse",
"keyId": "60000000000000000000000000000111"
}
},
"insertId": "evt001111111101",
"resource": {
"type": "service_account",
"labels": {
"email_id": "demiguise-inference@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000100"
}
},
"timestamp": "2026-04-15T17:01:18.421987Z",
"severity": "INFO",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
"receiveTimestamp": "2026-04-15T17:01:18.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1548.005 — Temporary Elevated Cloud Access — Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto re...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.