Skip to content

compute.firewalls.delete

GCP

compute.firewalls.delete

service: GCP - Compute Engine
techniques:

Event

Deletes the named VPC firewall rule. Removing an allow rule can reduce connectivity; removing a deny rule can permit traffic if the remaining effective rules allow it. The rule name alone does not establish its action or security effect.

Security Context

Unauthorized removal of a protective rule can impair firewall defenses (T1686.001). Confirm the deleted definition, applicable firewall policies, priorities, targets, and resulting traffic decisions. Deletion neither erases historical audit records nor proves a prior malicious patch.

Log Source

Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.firewalls.delete. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataPrincipal, delegation where present, caller context, and request timing.
protoPayload.methodName, resourceNameExact service method and target resource.
protoPayload.authorizationInfoRecorded permission checks; granted does not establish operation completion.
protoPayload.request, response, metadataRequested settings and available operation/delta details; presence and serialization vary.
operation.id, first, last; protoPayload.statusCorrelate start/completion records and inspect errors.
protoPayload.response.status, errorRUNNING is incomplete; DONE must still be checked for operation errors.

What to Investigate

  1. Confirm the actor, target, timing, and outcome against the approved change.
  2. Recover the previous rule definition, including allow/deny action, disabled state, direction, priority, source/destination ranges, and targets.
  3. Evaluate remaining VPC rules and applicable firewall policies for the affected workloads; determine whether access widened, narrowed, or stayed unchanged.
  4. Correlate the operation with final status/errors and relevant connection telemetry before asserting successful deletion or exposure.

Sample Event

Synthetic scenario. The sample starts deletion of billywig-public-ingress. Its former definition is absent, so neither exposure nor an earlier configuration change is established.

Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.firewall-rules.delete invocation-id/90000000000000000000000000000010 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T14:17:33.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.firewalls.delete",
"authorizationInfo": [
{
"permission": "compute.firewalls.delete",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress",
"type": "compute.firewalls"
}
}
],
"resourceName": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress",
"request": {
"@type": "type.googleapis.com/compute.firewalls.delete"
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "8200000000000000020",
"name": "operation-1776265053000-62fa1f3a4f001-ab000010-cd000010",
"operationType": "delete",
"targetId": "6100000000000000010",
"targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress",
"selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/operations/operation-1776265053000-62fa1f3a4f001-ab000010-cd000010",
"user": "draco@fantasticlogs.cloud",
"status": "RUNNING",
"progress": 0,
"insertTime": "2026-04-15T07:17:33.301-07:00",
"startTime": "2026-04-15T07:17:33.318-07:00"
},
"resourceLocation": {
"currentLocations": [
"global"
]
}
},
"insertId": "evt0000000010",
"resource": {
"type": "gce_firewall_rule",
"labels": {
"project_id": "fantasticlogs-prod",
"firewall_rule_id": "6100000000000000010"
}
},
"timestamp": "2026-04-15T14:17:33.550000000Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operation-1776265053000-62fa1f3a4f001-ab000010-cd000010",
"producer": "compute.googleapis.com",
"first": true
},
"receiveTimestamp": "2026-04-15T14:17:33.567890123Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.