SetIamPolicy appears 847 times in this sample window versus 3–4/day in the scenario history. One service account granted Owner access to 12 fictional projects between 02:00–03:15 UTC. This pattern warrants verification as a possible privilege-escalation sequence; it does not establish compromise.
91
#2CriticalFirst seen
httpRequest.remoteIp→185.220.101.47
This example source IP is first-seen in the available 30-day scenario context. All 23 API calls from it succeeded. That combination warrants source-system and identity verification; Flare has not independently established the IP reputation or credential owner.
76
#3High
protoPayload.status.code→PERMISSION_DENIED
PERMISSION_DENIED errors reached 340 in 15 minutes, 98× the scenario’s daily average of 3.5. Dense access failures followed by permission changes can fit a scanning hypothesis, but the sequence requires source-system verification.
The available 30-day scenario context contains only read-only storage operations for this service account. SetIamPolicy and CreateServiceAccountKey are first-seen actions in that context and should be verified with the identity owner before treating them as unauthorized.
A service account key was created for pipeline-sa minutes after the first SetIamPolicy calls. If unauthorized, a long-lived key could preserve access, so verify its creator and intended use before following the organization’s containment procedure.
44
#6Medium
resource.labels.project_id→acme-prod-dr-backup
The disaster-recovery backup project received 34 API calls in this window, unusually high for a project that typically sees 0–2 calls/day. Combined with the escalation activity in the main project, this may indicate lateral movement.
14,832 logs·Last 24 hours·6 anomaliesDec 14, 3:15 AM UTCacme-prod-339201
✦AI Summary
This sample analysis surfaces a privilege-escalation hypothesis worth investigating. A service account with previously read-only activity executed 847 SetIamPolicy calls and granted Owner access in the simulated record. A first-seen source IP and a PERMISSION_DENIED spike add context, but they do not confirm compromise. Verify the identity, IAM changes, and source activity in the source system before taking containment action.
Flare Intelligence
Ask Flare about these findings and their saved source evidence.