cloudsql.instances.export
cloudsql.instances.export
Event
The management API starts an asynchronous export. The initiating identity needs export authority, and the Cloud SQL instance’s own service account needs destination-object permissions. MySQL SQL export can select databases; it is not a guarantee of a complete instance backup with every database object.
Security Context
Unauthorized export can collect database contents (T1213.006) and transfer them to another cloud account (T1537) if ownership and completion support that conclusion. This is a separately authorized server-side export path, not an unconditional bypass of IAM or all security controls.
Log Source
Google Cloud Audit Logs with protoPayload.serviceName: cloudsql.googleapis.com and protoPayload.methodName: cloudsql.instances.export. This is a DATA_READ Data Access operation. Enable the applicable Cloud SQL Data Access logging and verify exemptions, routing, and retention. Long-running operation start and completion records must be correlated.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo | Effective principal and delegation information where present. |
protoPayload.methodName, resourceName | Service method and resource scope. |
protoPayload.authorizationInfo, status | Reported authorization and outcome; a granted permission is not completion evidence. |
protoPayload.request, response, metadata, serviceData | Policy or job details and deltas, where logged; field presence varies. |
operation, timestamp, logName | Long-running correlation, timing, and audit stream. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify selected databases/tables, file type, offload setting, approved purpose, and caller authority.
- Resolve the instance service account and destination bucket permissions, owner, and applicable perimeter restrictions.
- Follow the operation to DONE and inspect errors plus destination objects; PENDING or operation.first is not successful completion.
Sample Event
Synthetic scenario. The sample requests customers and billing from a MySQL instance, with offload false and a PENDING response. It does not export an evidenced entire instance or show completed object creation. The unsupported response.user attribution and premature startTime were removed.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "status": {}, "authenticationInfo": { "principalEmail": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com", "principalSubject": "serviceAccount:occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com", "serviceAccountDelegationInfo": [ { "firstPartyPrincipal": { "principalEmail": "draco@fantasticlogs.cloud" } } ] }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.sql.export.sql invocation-id/90000000000000000000001111101001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:09:42.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "cloudsql.googleapis.com", "methodName": "cloudsql.instances.export", "authorizationInfo": [ { "resource": "projects/fantasticlogs-prod/instances/niffler-archive-mysql", "permission": "cloudsql.instances.export", "granted": true, "resourceAttributes": { "service": "cloudsql.googleapis.com", "name": "projects/fantasticlogs-prod/instances/niffler-archive-mysql", "type": "sqladmin.googleapis.com/Instance" } } ], "resourceName": "projects/fantasticlogs-prod/instances/niffler-archive-mysql", "request": { "@type": "type.googleapis.com/google.cloud.sql.v1beta4.SqlInstancesExportRequest", "project": "fantasticlogs-prod", "instance": "niffler-archive-mysql", "body": { "exportContext": { "kind": "sql#exportContext", "fileType": "SQL", "uri": "gs://draco-exfil-bucket-666/cloudsql-dump/niffler-archive-2026-04-15.sql.gz", "databases": [ "customers", "billing" ], "offload": false } } }, "response": { "@type": "type.googleapis.com/google.cloud.sql.v1beta4.Operation", "kind": "sql#operation", "name": "operation-1776278982-export-001111101001", "operationType": "EXPORT", "status": "PENDING", "insertTime": "2026-04-15T17:09:42.300000000Z", "targetId": "niffler-archive-mysql", "targetProject": "fantasticlogs-prod", "targetLink": "https://sqladmin.googleapis.com/sql/v1/projects/fantasticlogs-prod/instances/niffler-archive-mysql", "selfLink": "https://sqladmin.googleapis.com/sql/v1/projects/fantasticlogs-prod/operations/operation-1776278982-export-001111101001" } }, "insertId": "evt001111101001", "resource": { "type": "cloudsql_database", "labels": { "project_id": "fantasticlogs-prod", "database_id": "fantasticlogs-prod:niffler-archive-mysql", "region": "us-central1" } }, "timestamp": "2026-04-15T17:09:42.350000000Z", "severity": "INFO", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "operation": { "id": "operation-1776278982-export-001111101001", "producer": "cloudsql.googleapis.com", "first": true }, "receiveTimestamp": "2026-04-15T17:09:42.567890123Z"}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration Collection
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
- T1213.006 — Databases — Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).