For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/c19-1d0-3b1.md. A documentation index is available at /llms.txt.

Google Cloud Service Account created

Goal

Detect when a new service account is created.

Strategy

This rule lets you monitor Google Cloud admin activity audit logs to determine when a service account is created.

Triage and response

Contact the user who created the service account and ensure that the account is needed and that the role is scoped properly.