GCP Service Account JSON Key

Detects GCP service-account JSON key files, distinguishing bare type=service_account record markers (discovery only) from complete keys whose object also carries an escaped PEM private_key and a .iam.gserviceaccount.com client_email (enforcing), with project_id/private_key_id as additional high-confidence evidence.

Type
regex
Engine
universal
Confidence
low
Confidence justification
Low confidence: generic pattern format that may match unrelated data. Corroborative evidence keywords are essential for reliable detection. Added context gating and exclusion rules improve precision and reduce incidental matches.
Detection quality
Partial
Jurisdictions
global
Regulations
Criminal Code Act 1995 (Cth)
Frameworks
CIS Controls, ISO 27001, NIST CSF, PCI-DSS, SOC 2
Data categories
credentials, security
Scope
specific
Risk rating
8
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Compatible

Pattern

"type"\s*:\s*"service_account"

Corroborative evidence keywords

api key, api_key, apikey, access key, secret key, private key, auth token, authorization, access token, bearer, conn str, connection string, connectionstring, cookie, credential, database, host, [object Object], oauth, passphrase (+33 more)

Proximity: 300 characters

Should match

Should not match

Known false positives

Collections