SecretManagerService.DestroySecretVersion
SecretManagerService.DestroySecretVersion
Event
DestroySecretVersion targets one version. Without a configured delay, its payload is permanently destroyed. With delayed destruction, it is disabled and scheduled for later destruction, with a recovery opportunity before the deadline.
Security Context
Unauthorized destruction can support T1485. The parent secret and version metadata are distinct from its payload; destroying a version does not erase earlier access logs or prove that other versions remain usable.
Log Source
Cloud Audit Logs: secretmanager.googleapis.com, method google.cloud.secretmanager.v1.SecretManagerService.DestroySecretVersion. Admin Activity. Inspect status and resulting state; a granted permission alone does not establish success.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Effective caller, delegation where present, and request context. |
protoPayload.methodName, resourceName | Operation and exact target; distinguish versions/generations and resource scope. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, serviceData | Settings, returned state, or policy deltas where present; compare old state separately. |
timestamp, logName | Timing, owning resource, and audit stream. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Verify version number, actor, etag, approval, and the secret’s destruction-delay setting at the time.
- Inspect state and destroy/scheduled-destroy times; determine whether cancellation/recovery is still available.
- Assess client dependencies, independent copies, and actual failures; preserve earlier access evidence rather than assuming anti-forensic erasure.
Sample Event
Synthetic scenario. The example shows version 2 in DESTROYED state, assuming no destruction delay. It does not show a prior read of that version or the state of versions 1 and 3.
Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.secrets.versions.destroy invocation-id/90000000000000000000010000000011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:36:42.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "secretmanager.googleapis.com", "methodName": "google.cloud.secretmanager.v1.SecretManagerService.DestroySecretVersion", "authorizationInfo": [ { "resource": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/2", "permission": "secretmanager.versions.destroy", "granted": true, "resourceAttributes": { "service": "secretmanager.googleapis.com", "name": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/2", "type": "secretmanager.googleapis.com/SecretVersion" } } ], "resourceName": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/2", "request": { "@type": "type.googleapis.com/google.cloud.secretmanager.v1.DestroySecretVersionRequest", "name": "projects/fantasticlogs-prod/secrets/bowtruckle-prod-db-master-pass/versions/2", "etag": "synthetic-before" }, "response": { "@type": "type.googleapis.com/google.cloud.secretmanager.v1.SecretVersion", "name": "projects/555123456789/secrets/bowtruckle-prod-db-master-pass/versions/2", "state": "DESTROYED", "createTime": "2026-03-12T09:14:32.123456789Z", "destroyTime": "2026-04-15T17:36:42.321987Z", "etag": "synthetic-after" } }, "insertId": "evt010000000011", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "method": "google.cloud.secretmanager.v1.SecretManagerService.DestroySecretVersion", "service": "secretmanager.googleapis.com" } }, "timestamp": "2026-04-15T17:36:42.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T17:36:42.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...