Investigation #154
ReviewedReopen
2024-03-07 16:41:56
Admin Role Added To Member
GCP/PrivilegeEscalation:IAM/AdminRoleAddedToMember — Google Workspace
Executive summary

On February 29, 2024, a high-severity alert titled "Admin Role Added To Member" was generated, indicating a potential privilege escalation within AcmeCorp. The alert was triggered when alice.johnson@acmecorp.com, a user without admin privileges in Google Workspace, assigned an admin role (roles/aiplatform.admin) to bob.smith@acmecorp.com for the "AdvancedResearch" project. This action took place at 08:59:10 UTC from the IP address 203.0.113.45, located in Columbus, Ohio. Bob Smith, whose job title is "R&D Team Lead," does not typically require such elevated privileges, which raises suspicions about the legitimacy of this role assignment. No further administrative actions by either user have been recorded in Google Workspace since the alert. The IP address has not been previously associated with any known malicious activity within the organizations network. The alert remains open with a severity level of 5, and the investigation has classified the incident as suspicious due to the unusual granting of admin rights.

ConclusionBenign
No further action is needed, no malicious or suspicious activity was found.
Alert Summary[+]
Evidence
No Evidence of Compromise in Alert Artifacts[+]
Artifacts
203.0.113.45, Admin Role Added To Member, GCP/PrivilegeEscalation:IAM/AdminRoleAddedToMember, alice.johnson@acmecorp.com, bob.smith@acmecorp.com
Bob Smith's Super Admin Rights Unjustified[+]
Artifact
bob.smith@acmecorp.com
Bob.smith@acmecorp.com Identified as R&D Team Lead
[+]
Bob Smith Lacks Admin Privileges in Google Workspace
[+]
Non-admin User Assigning Admin Rights Raises Concern[+]
Artifact
alice.johnson@acmecorp.com
Admin Role Granted by alice.johnson@acmecorp.com[+]
Artifacts
alice.johnson@acmecorp.com, bob.smith@acmecorp.com
No Administrative Actions Performed by User
[+]
No Administrative Actions Found by User
[+]
Mar 07 2024 at 4:41 pm
Google Workspace created this alert.
Mar 07 2024 at 4:46 pm
Dropzone started investigation of this alert.
Mar 07 2024 at 4:46 pm
Dropzone completed investigation of this alert.
Mar 07 2024 at 4:46 pm
Dropzone set conclusion to Suspicious
Mar 08 2024 at 3:53 pm
admin started editing the report.
Mar 08 2024 at 3:53 pm
admin set conclusion to Benign
Mar 08 2024 at 3:54 pm
admin finished editing the report.