google.iam.admin.v1.DeleteServiceAccountKey
google.iam.admin.v1.DeleteServiceAccountKey
Event
Removes a selected key from the service account. Deleting a key does not revoke short-lived credentials already issued using that key.
Security Context
Unauthorized key removal may disrupt workloads or remove an attacker credential from current inventory. Historical creation and usage logs are not erased by this API. T1070 is contextual to evidenced cleanup intent, not every legitimate key rotation.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.DeleteServiceAccountKey. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Resolve the full key resource, account, creator history, approval, and deletion result.
- Search retained audit/usage evidence and distinguish current inventory removal from historical evidence loss.
- Assess dependent workloads and outstanding short-lived credentials; do not assume deleting the key terminated all access.
Sample Event
Synthetic scenario. The example deletes one key on occamy-pipeline. It does not prove the caller created that key, obtained another token, or established alternate persistence.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.keys.delete invocation-id/90000000000000000000001111110010 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:33:21.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.DeleteServiceAccountKey", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000001/keys/60000000000000000000000000000001", "permission": "iam.serviceAccountKeys.delete", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/-/serviceAccounts/100000000000000000001/keys/60000000000000000000000000000001", "type": "iam.googleapis.com/ServiceAccountKey" } } ], "resourceName": "projects/-/serviceAccounts/100000000000000000001/keys/60000000000000000000000000000001", "request": { "@type": "type.googleapis.com/google.iam.admin.v1.DeleteServiceAccountKeyRequest", "name": "projects/fantasticlogs-prod/serviceAccounts/occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com/keys/60000000000000000000000000000001" }, "response": { "@type": "type.googleapis.com/google.protobuf.Empty" } }, "insertId": "evt001111110010", "resource": { "type": "service_account", "labels": { "email_id": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000001" } }, "timestamp": "2026-04-15T17:33:21.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T17:33:21.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Stealth
- T1070 — Indicator Removal — Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving suff...