Skip to content

storage.buckets.delete

GCP

storage.buckets.delete

service: GCP - Cloud Storage
tactics:
techniques:

Event

The JSON API deletes a bucket only when it has no live or noncurrent objects. Soft-deleted objects and incomplete uploads do not prevent this request. A configured soft-delete policy can retain the deleted bucket for recovery; there is no force=true parameter on this API.

Security Context

Unauthorized removal can cause T1485 impact, but deletion is not always immediate permanent loss. Inspect recoverability, name conflicts, independent copies, and actual workload dependencies; a bucket-delete record does not prove earlier object purging.

Log Source

Cloud Audit Logs: storage.googleapis.com, method storage.buckets.delete. Admin Activity. Inspect status and resulting state; a granted permission alone does not establish success. Optional request/response detail depends on logging configuration; the minimal sample is not the only supported shape.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataEffective caller, delegation where present, and request context.
protoPayload.methodName, resourceNameOperation and exact target; distinguish versions/generations and resource scope.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, serviceDataSettings, returned state, or policy deltas where present; compare old state separately.
timestamp, logNameTiming, owning resource, and audit stream.

What to Investigate

  1. Confirm the observed change and compare it with the approved workflow.
  2. Confirm the bucket, deletion result, actor, approval, and any metageneration preconditions.
  3. Inspect soft-delete policy and retention at deletion time, retained resources, and restore eligibility.
  4. Correlate object deletions and workload failures separately; do not assume a fixed seven-day name-reuse prohibition.

Sample Event

Synthetic scenario. The example records a delete request for fantasticlogs-occamy-ingest. It provides no previous contents, retention configuration, purge sequence, or downstream outage evidence.

Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.storage.buckets.delete invocation-id/90000000000000000000010000000110 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T18:09:18.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "storage.googleapis.com",
"methodName": "storage.buckets.delete",
"authorizationInfo": [
{
"resource": "projects/_/buckets/fantasticlogs-occamy-ingest",
"permission": "storage.buckets.delete",
"granted": true,
"resourceAttributes": {
"service": "storage.googleapis.com",
"name": "projects/_/buckets/fantasticlogs-occamy-ingest",
"type": "storage.googleapis.com/Bucket"
}
}
],
"resourceName": "projects/_/buckets/fantasticlogs-occamy-ingest",
"resourceLocation": {
"currentLocations": [
"us-central1"
]
}
},
"insertId": "evt010000000110",
"resource": {
"type": "gcs_bucket",
"labels": {
"project_id": "fantasticlogs-prod",
"bucket_name": "fantasticlogs-occamy-ingest",
"location": "us-central1"
}
},
"timestamp": "2026-04-15T18:09:18.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T18:09:18.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.