2026 Critical Cloud Control Plane Detection: GCP Service Account Key Creation on Privileged Service Account

This rule detects the creation of new, potentially long-lived service account keys for GCP service accounts that possess highly privileged roles, such as Project Owner, Project Editor, or broad custom roles. The creation of such keys for privileged accounts can be a technique used by adversaries to establish persistent, stealthy access within a GCP environment.