SecretManagerService.AccessSecretVersion
SecretManagerService.AccessSecretVersion
Event
AccessSecretVersion retrieves secret payload data, unlike metadata-only GetSecretVersion. The latest alias identifies the most recently created version, not necessarily an enabled version; inspect the resolved version and result.
Security Context
Unauthorized retrieval of stored credentials can support T1555.006. A secret can also contain noncredential data. Caller identity and delegation evidence help attribution, but the record does not prove a particular prior token-generation event or subsequent use of the secret.
Log Source
Cloud Audit Logs: secretmanager.googleapis.com, method google.cloud.secretmanager.v1.SecretManagerService.AccessSecretVersion. Data Access (DATA_READ). Enable the relevant service/category at project, folder, or organization scope and check exemptions, routing, retention, and viewer access.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Effective caller, delegation where present, and request context. |
protoPayload.methodName, resourceName | Operation and exact target; distinguish versions/generations and resource scope. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, serviceData | Settings, returned state, or policy deltas where present; compare old state separately. |
timestamp, logName | Timing, owning resource, and audit stream. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Verify the effective principal, delegation, requested alias/version, resolved resource, and approved application.
- Check the result, version state, and applicable authorization controls; granted permission alone is not payload-return proof.
- Investigate downstream credential use or transfer separately, preserving evidence without copying secret material into reports.
Sample Event
Synthetic scenario. The sample illustrates a request for latest resolving to version 3 under bowtruckle-secrets with delegation context. The payload is intentionally omitted; exact response disclosure and delegation serialization need captured-log validation. The former unsupported mid-2022 redaction claim was removed.
Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "bowtruckle-secrets@fantasticlogs-prod.iam.gserviceaccount.com", "principalSubject": "serviceAccount:bowtruckle-secrets@fantasticlogs-prod.iam.gserviceaccount.com", "serviceAccountDelegationInfo": [ { "firstPartyPrincipal": { "principalEmail": "draco@fantasticlogs.cloud" } } ] }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.secrets.versions.access invocation-id/90000000000000000000010000000010 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:08:33.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "secretmanager.googleapis.com", "methodName": "google.cloud.secretmanager.v1.SecretManagerService.AccessSecretVersion", "authorizationInfo": [ { "resource": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/3", "permission": "secretmanager.versions.access", "granted": true, "resourceAttributes": { "service": "secretmanager.googleapis.com", "name": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/3", "type": "secretmanager.googleapis.com/SecretVersion" } } ], "resourceName": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/3", "request": { "@type": "type.googleapis.com/google.cloud.secretmanager.v1.AccessSecretVersionRequest", "name": "projects/fantasticlogs-prod/secrets/bowtruckle-prod-db-master-pass/versions/latest" }, "response": { "@type": "type.googleapis.com/google.cloud.secretmanager.v1.AccessSecretVersionResponse", "name": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/3" } }, "insertId": "evt010000000010", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "method": "google.cloud.secretmanager.v1.SecretManagerService.AccessSecretVersion", "service": "secretmanager.googleapis.com" } }, "timestamp": "2026-04-15T17:08:33.421987Z", "severity": "INFO", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "receiveTimestamp": "2026-04-15T17:08:33.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1555.006 — Cloud Secrets Management Stores — Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.