Skip to content

google.iam.admin.v1.DeleteServiceAccountKey

GCP

google.iam.admin.v1.DeleteServiceAccountKey

service: GCP - IAM
tactics:
techniques:

Event

Removes a selected key from the service account. Deleting a key does not revoke short-lived credentials already issued using that key.

Security Context

Unauthorized key removal may disrupt workloads or remove an attacker credential from current inventory. Historical creation and usage logs are not erased by this API. T1070 is contextual to evidenced cleanup intent, not every legitimate key rotation.

Log Source

Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.DeleteServiceAccountKey. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Resolve the full key resource, account, creator history, approval, and deletion result.
  3. Search retained audit/usage evidence and distinguish current inventory removal from historical evidence loss.
  4. Assess dependent workloads and outstanding short-lived credentials; do not assume deleting the key terminated all access.

Sample Event

Synthetic scenario. The example deletes one key on occamy-pipeline. It does not prove the caller created that key, obtained another token, or established alternate persistence.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.keys.delete invocation-id/90000000000000000000001111110010 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T17:33:21.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iam.googleapis.com",
"methodName": "google.iam.admin.v1.DeleteServiceAccountKey",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000001/keys/60000000000000000000000000000001",
"permission": "iam.serviceAccountKeys.delete",
"granted": true,
"resourceAttributes": {
"service": "iam.googleapis.com",
"name": "projects/-/serviceAccounts/100000000000000000001/keys/60000000000000000000000000000001",
"type": "iam.googleapis.com/ServiceAccountKey"
}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000001/keys/60000000000000000000000000000001",
"request": {
"@type": "type.googleapis.com/google.iam.admin.v1.DeleteServiceAccountKeyRequest",
"name": "projects/fantasticlogs-prod/serviceAccounts/occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com/keys/60000000000000000000000000000001"
},
"response": {
"@type": "type.googleapis.com/google.protobuf.Empty"
}
},
"insertId": "evt001111110010",
"resource": {
"type": "service_account",
"labels": {
"email_id": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000001"
}
},
"timestamp": "2026-04-15T17:33:21.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T17:33:21.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Stealth

Techniques:
  • T1070 — Indicator Removal — Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving suff...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.