Skip to content

storage.hmacKeys.create

GCP

storage.hmacKeys.create

service: GCP - Cloud Storage
tactics:
techniques:

Event

Creates an access-ID/secret pair for authenticating Cloud Storage XML API requests. HMAC credentials are distinct from IAM-managed RSA service-account keys and cannot mint OAuth tokens. Client compatibility depends on the supported XML API operations.

Security Context

An unauthorized additional credential can support T1098.001. Access is limited by the service account’s permissions, key/account state, and applicable authentication restrictions. Rotating another key does not revoke this one; manage HMAC keys in their own inventory.

Log Source

Cloud Audit Logs: storage.googleapis.com, method storage.hmacKeys.create. Admin Activity. Inspect status and resulting state; a granted permission alone does not establish success. Optional request/response detail depends on logging configuration; the minimal sample is not the only supported shape.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataEffective caller, delegation where present, and request context.
protoPayload.methodName, resourceNameOperation and exact target; distinguish versions/generations and resource scope.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, serviceDataSettings, returned state, or policy deltas where present; compare old state separately.
timestamp, logNameTiming, owning resource, and audit stream.

What to Investigate

  1. Confirm the observed change and compare it with the approved workflow.
  2. Confirm target service account, creator, approval, and HMAC restrictions.
  3. Inspect access ID, ACTIVE/INACTIVE/DELETED state, creation time, and the account’s effective storage permissions.
  4. Correlate observed HMAC usage and later state changes; do not infer read/write access to every bucket or immediate usability.

Sample Event

Synthetic scenario. The sample illustrates metadata for an ACTIVE key. Its synthetic access ID is normalized to the documented 61-character service-account length. The secret is intentionally omitted; native audit response disclosure remains unverified.

Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.storage.hmac.create invocation-id/90000000000000000000010000000111 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T13:58:55.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "storage.googleapis.com",
"methodName": "storage.hmacKeys.create",
"authorizationInfo": [
{
"resource": "projects/fantasticlogs-prod/hmacKeys",
"permission": "storage.hmacKeys.create",
"granted": true,
"resourceAttributes": {
"service": "storage.googleapis.com",
"name": "projects/fantasticlogs-prod/hmacKeys",
"type": "storage.googleapis.com/HmacKey"
}
}
],
"resourceName": "projects/fantasticlogs-prod/hmacKeys/GOOG0000000000000000000000000000000000000000000000000SAMPLE01",
"request": {
"@type": "type.googleapis.com/storage.hmacKeys.create",
"projectId": "fantasticlogs-prod",
"serviceAccountEmail": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com"
},
"response": {
"@type": "type.googleapis.com/storage.hmacKey",
"metadata": {
"accessId": "GOOG0000000000000000000000000000000000000000000000000SAMPLE01",
"id": "fantasticlogs-prod/GOOG0000000000000000000000000000000000000000000000000SAMPLE01",
"projectId": "fantasticlogs-prod",
"serviceAccountEmail": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com",
"state": "ACTIVE",
"timeCreated": "2026-04-15T13:58:55.321987Z",
"updated": "2026-04-15T13:58:55.321987Z",
"etag": "BwSAMPLEetag10111="
}
}
},
"insertId": "evt010000000111",
"resource": {
"type": "audited_resource",
"labels": {
"project_id": "fantasticlogs-prod",
"service": "storage.googleapis.com",
"method": "storage.hmacKeys.create"
}
},
"timestamp": "2026-04-15T13:58:55.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T13:58:55.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.