Skip to content

storage.setIamPermissions

GCP

storage.setIamPermissions

service: GCP - Cloud Storage
techniques:

Event

The sample uses storage.setIamPermissions with storage.buckets.setIamPolicy to change bucket access. The added roles/storage.objectViewer binding to allUsers can grant public object read/list access when applicable controls permit it. Object ACL changes are a separate access-control surface.

Security Context

Unauthorized role grants can support T1098.003. Public access prevention can reject new public grants or override existing ones, so a public member string alone is not proof of exposure. The change does not demonstrate collection; T1530 was removed.

Log Source

Cloud Audit Logs: storage.googleapis.com, method storage.setIamPermissions. Admin Activity. Inspect status and resulting state; a granted permission alone does not establish success. Optional request/response detail depends on logging configuration; the minimal sample is not the only supported shape.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataEffective caller, delegation where present, and request context.
protoPayload.methodName, resourceNameOperation and exact target; distinguish versions/generations and resource scope.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, serviceDataSettings, returned state, or policy deltas where present; compare old state separately.
timestamp, logNameTiming, owning resource, and audit stream.

What to Investigate

  1. Confirm the observed change and compare it with the approved workflow.
  2. Inspect the complete resulting policy, delta, caller, outcome, conditions, and approved purpose.
  3. Check effective bucket/inherited public access prevention and other applicable access restrictions.
  4. Assess actual exposure and access evidence. Cloud Audit Logs does not track public-object access; consider configured Cloud Storage usage logs and other telemetry.

Sample Event

Synthetic scenario. The synthetic ADD delta grants Object Viewer to allUsers on fantasticlogs-demiguise-models. No object contents or anonymous download is shown. Absence of request/response in this illustration is not a universal Storage audit schema rule.

Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.storage.buckets.add-iam-policy-binding invocation-id/90000000000000000000010000001001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T17:25:47.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "storage.googleapis.com",
"methodName": "storage.setIamPermissions",
"authorizationInfo": [
{
"resource": "projects/_/buckets/fantasticlogs-demiguise-models",
"permission": "storage.buckets.setIamPolicy",
"granted": true,
"resourceAttributes": {
"service": "storage.googleapis.com",
"name": "projects/_/buckets/fantasticlogs-demiguise-models",
"type": "storage.googleapis.com/Bucket"
}
}
],
"resourceName": "projects/_/buckets/fantasticlogs-demiguise-models",
"serviceData": {
"@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
"policyDelta": {
"bindingDeltas": [
{
"action": "ADD",
"role": "roles/storage.objectViewer",
"member": "allUsers"
}
]
}
},
"resourceLocation": {
"currentLocations": [
"us-central1"
]
}
},
"insertId": "evt010000001001",
"resource": {
"type": "gcs_bucket",
"labels": {
"project_id": "fantasticlogs-prod",
"bucket_name": "fantasticlogs-demiguise-models",
"location": "us-central1"
}
},
"timestamp": "2026-04-15T17:25:47.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T17:25:47.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.