compute.firewalls.delete
compute.firewalls.delete
Event
Deletes the named VPC firewall rule. Removing an allow rule can reduce connectivity; removing a deny rule can permit traffic if the remaining effective rules allow it. The rule name alone does not establish its action or security effect.
Security Context
Unauthorized removal of a protective rule can impair firewall defenses (T1686.001). Confirm the deleted definition, applicable firewall policies, priorities, targets, and resulting traffic decisions. Deletion neither erases historical audit records nor proves a prior malicious patch.
Log Source
Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.firewalls.delete. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Principal, delegation where present, caller context, and request timing. |
protoPayload.methodName, resourceName | Exact service method and target resource. |
protoPayload.authorizationInfo | Recorded permission checks; granted does not establish operation completion. |
protoPayload.request, response, metadata | Requested settings and available operation/delta details; presence and serialization vary. |
operation.id, first, last; protoPayload.status | Correlate start/completion records and inspect errors. |
protoPayload.response.status, error | RUNNING is incomplete; DONE must still be checked for operation errors. |
What to Investigate
- Confirm the actor, target, timing, and outcome against the approved change.
- Recover the previous rule definition, including allow/deny action, disabled state, direction, priority, source/destination ranges, and targets.
- Evaluate remaining VPC rules and applicable firewall policies for the affected workloads; determine whether access widened, narrowed, or stayed unchanged.
- Correlate the operation with final status/errors and relevant connection telemetry before asserting successful deletion or exposure.
Sample Event
Synthetic scenario. The sample starts deletion of billywig-public-ingress. Its former definition is absent, so neither exposure nor an earlier configuration change is established.
Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.firewall-rules.delete invocation-id/90000000000000000000000000000010 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T14:17:33.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "compute.googleapis.com", "methodName": "v1.compute.firewalls.delete", "authorizationInfo": [ { "permission": "compute.firewalls.delete", "granted": true, "resourceAttributes": { "service": "compute", "name": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress", "type": "compute.firewalls" } } ], "resourceName": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress", "request": { "@type": "type.googleapis.com/compute.firewalls.delete" }, "response": { "@type": "type.googleapis.com/operation", "id": "8200000000000000020", "name": "operation-1776265053000-62fa1f3a4f001-ab000010-cd000010", "operationType": "delete", "targetId": "6100000000000000010", "targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress", "selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/operations/operation-1776265053000-62fa1f3a4f001-ab000010-cd000010", "user": "draco@fantasticlogs.cloud", "status": "RUNNING", "progress": 0, "insertTime": "2026-04-15T07:17:33.301-07:00", "startTime": "2026-04-15T07:17:33.318-07:00" }, "resourceLocation": { "currentLocations": [ "global" ] } }, "insertId": "evt0000000010", "resource": { "type": "gce_firewall_rule", "labels": { "project_id": "fantasticlogs-prod", "firewall_rule_id": "6100000000000000010" } }, "timestamp": "2026-04-15T14:17:33.550000000Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "operation": { "id": "operation-1776265053000-62fa1f3a4f001-ab000010-cd000010", "producer": "compute.googleapis.com", "first": true }, "receiveTimestamp": "2026-04-15T14:17:33.567890123Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.