Skip to main content
GCP Service Account Key Abuse: IAM Privilege Escalation operation cover
COMING SOONIntermediatePRO

GCP Service Account Key Abuse: IAM Privilege Escalation

A developer committed a GCP service account JSON key to a public repository and an attacker found it within hours. Work the GCP Cloud Audit Logs to trace how the leaked credential was turned into a full IAM privilege escalation and a bulk download of the production secrets vault.

45m
7 tasks
50 points
Pro

Launches in 3 days

Sep 1, 2026

Tuesday, September 1, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

CloudSIEM

What you'll investigate

7 objectives unlock when this operation goes live.

1Locate where the credential surfaced
2Confirm the stolen key identifier
3Trace the initial external operator
4Reconstruct the escalation event
5Name the attacker's foothold identity
6Identify the primary data target
7Map the credential access technique

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 1, 2026, you can jump straight in.

Get Started Free