2026 Critical Cloud Control Plane Detection: GCP Compute Instance Created with Privileged Service Account
Detects the creation of GCP compute instances that are attached to service accounts with broad 'cloud-platform' scope permissions. This activity is monitored to ensure that only authorized automation service accounts (e.g., IaC pipelines) are performing these actions, as creating instances with highly privileged service accounts can be a technique used to escalate privileges or establish persistence.
Cortex XDR

