Skip to content

cloudsql.instances.export

GCP

cloudsql.instances.export

service: GCP - Cloud SQL
techniques:

Event

The management API starts an asynchronous export. The initiating identity needs export authority, and the Cloud SQL instance’s own service account needs destination-object permissions. MySQL SQL export can select databases; it is not a guarantee of a complete instance backup with every database object.

Security Context

Unauthorized export can collect database contents (T1213.006) and transfer them to another cloud account (T1537) if ownership and completion support that conclusion. This is a separately authorized server-side export path, not an unconditional bypass of IAM or all security controls.

Log Source

Google Cloud Audit Logs with protoPayload.serviceName: cloudsql.googleapis.com and protoPayload.methodName: cloudsql.instances.export. This is a DATA_READ Data Access operation. Enable the applicable Cloud SQL Data Access logging and verify exemptions, routing, and retention. Long-running operation start and completion records must be correlated.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfoEffective principal and delegation information where present.
protoPayload.methodName, resourceNameService method and resource scope.
protoPayload.authorizationInfo, statusReported authorization and outcome; a granted permission is not completion evidence.
protoPayload.request, response, metadata, serviceDataPolicy or job details and deltas, where logged; field presence varies.
operation, timestamp, logNameLong-running correlation, timing, and audit stream.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify selected databases/tables, file type, offload setting, approved purpose, and caller authority.
  3. Resolve the instance service account and destination bucket permissions, owner, and applicable perimeter restrictions.
  4. Follow the operation to DONE and inspect errors plus destination objects; PENDING or operation.first is not successful completion.

Sample Event

Synthetic scenario. The sample requests customers and billing from a MySQL instance, with offload false and a PENDING response. It does not export an evidenced entire instance or show completed object creation. The unsupported response.user attribution and premature startTime were removed.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"status": {},
"authenticationInfo": {
"principalEmail": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"principalSubject": "serviceAccount:occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"serviceAccountDelegationInfo": [
{
"firstPartyPrincipal": {
"principalEmail": "draco@fantasticlogs.cloud"
}
}
]
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.sql.export.sql invocation-id/90000000000000000000001111101001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T17:09:42.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "cloudsql.googleapis.com",
"methodName": "cloudsql.instances.export",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod/instances/niffler-archive-mysql",
"permission": "cloudsql.instances.export",
"granted": true,
"resourceAttributes": {
"service": "cloudsql.googleapis.com",
"name": "projects/fantasticlogs-prod/instances/niffler-archive-mysql",
"type": "sqladmin.googleapis.com/Instance"
}
}
],
"resourceName": "projects/fantasticlogs-prod/instances/niffler-archive-mysql",
"request": {
"@type": "type.googleapis.com/google.cloud.sql.v1beta4.SqlInstancesExportRequest",
"project": "fantasticlogs-prod",
"instance": "niffler-archive-mysql",
"body": {
"exportContext": {
"kind": "sql#exportContext",
"fileType": "SQL",
"uri": "gs://draco-exfil-bucket-666/cloudsql-dump/niffler-archive-2026-04-15.sql.gz",
"databases": [
"customers",
"billing"
],
"offload": false
}
}
},
"response": {
"@type": "type.googleapis.com/google.cloud.sql.v1beta4.Operation",
"kind": "sql#operation",
"name": "operation-1776278982-export-001111101001",
"operationType": "EXPORT",
"status": "PENDING",
"insertTime": "2026-04-15T17:09:42.300000000Z",
"targetId": "niffler-archive-mysql",
"targetProject": "fantasticlogs-prod",
"targetLink": "https://sqladmin.googleapis.com/sql/v1/projects/fantasticlogs-prod/instances/niffler-archive-mysql",
"selfLink": "https://sqladmin.googleapis.com/sql/v1/projects/fantasticlogs-prod/operations/operation-1776278982-export-001111101001"
}
},
"insertId": "evt001111101001",
"resource": {
"type": "cloudsql_database",
"labels": {
"project_id": "fantasticlogs-prod",
"database_id": "fantasticlogs-prod:niffler-archive-mysql",
"region": "us-central1"
}
},
"timestamp": "2026-04-15T17:09:42.350000000Z",
"severity": "INFO",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
"operation": {
"id": "operation-1776278982-export-001111101001",
"producer": "cloudsql.googleapis.com",
"first": true
},
"receiveTimestamp": "2026-04-15T17:09:42.567890123Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration Collection

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
  • T1213.006 — Databases — Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.