storage.setIamPermissions
storage.setIamPermissions
Event
The sample uses storage.setIamPermissions with storage.buckets.setIamPolicy to change bucket access. The added roles/storage.objectViewer binding to allUsers can grant public object read/list access when applicable controls permit it. Object ACL changes are a separate access-control surface.
Security Context
Unauthorized role grants can support T1098.003. Public access prevention can reject new public grants or override existing ones, so a public member string alone is not proof of exposure. The change does not demonstrate collection; T1530 was removed.
Log Source
Cloud Audit Logs: storage.googleapis.com, method storage.setIamPermissions. Admin Activity. Inspect status and resulting state; a granted permission alone does not establish success. Optional request/response detail depends on logging configuration; the minimal sample is not the only supported shape.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Effective caller, delegation where present, and request context. |
protoPayload.methodName, resourceName | Operation and exact target; distinguish versions/generations and resource scope. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, serviceData | Settings, returned state, or policy deltas where present; compare old state separately. |
timestamp, logName | Timing, owning resource, and audit stream. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Inspect the complete resulting policy, delta, caller, outcome, conditions, and approved purpose.
- Check effective bucket/inherited public access prevention and other applicable access restrictions.
- Assess actual exposure and access evidence. Cloud Audit Logs does not track public-object access; consider configured Cloud Storage usage logs and other telemetry.
Sample Event
Synthetic scenario. The synthetic ADD delta grants Object Viewer to allUsers on fantasticlogs-demiguise-models. No object contents or anonymous download is shown. Absence of request/response in this illustration is not a universal Storage audit schema rule.
Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.storage.buckets.add-iam-policy-binding invocation-id/90000000000000000000010000001001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:25:47.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "storage.googleapis.com", "methodName": "storage.setIamPermissions", "authorizationInfo": [ { "resource": "projects/_/buckets/fantasticlogs-demiguise-models", "permission": "storage.buckets.setIamPolicy", "granted": true, "resourceAttributes": { "service": "storage.googleapis.com", "name": "projects/_/buckets/fantasticlogs-demiguise-models", "type": "storage.googleapis.com/Bucket" } } ], "resourceName": "projects/_/buckets/fantasticlogs-demiguise-models", "serviceData": { "@type": "type.googleapis.com/google.iam.v1.logging.AuditData", "policyDelta": { "bindingDeltas": [ { "action": "ADD", "role": "roles/storage.objectViewer", "member": "allUsers" } ] } }, "resourceLocation": { "currentLocations": [ "us-central1" ] } }, "insertId": "evt010000001001", "resource": { "type": "gcs_bucket", "labels": { "project_id": "fantasticlogs-prod", "bucket_name": "fantasticlogs-demiguise-models", "location": "us-central1" } }, "timestamp": "2026-04-15T17:25:47.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T17:25:47.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...