Skip to content

storage.objects.delete

GCP

storage.objects.delete

service: GCP - Cloud Storage
tactics:
techniques:

Event

Object deletion behavior depends on the selected generation, Object Versioning, and soft-delete policy. Retention requirements and holds can prevent deletion; lack of versioning alone does not establish irrecoverable loss.

Security Context

Unauthorized deletion can cause T1485 impact. Determine whether a noncurrent version, soft-deleted object, or independent copy survives. An archive-like object name does not establish contents, retention guarantees, or prior exfiltration.

Log Source

Cloud Audit Logs: storage.googleapis.com, method storage.objects.delete. Data Access (DATA_WRITE). Enable the relevant service/category at project, folder, or organization scope and check exemptions, routing, retention, and viewer access. Optional request/response detail depends on logging configuration; the minimal sample is not the only supported shape.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataEffective caller, delegation where present, and request context.
protoPayload.methodName, resourceNameOperation and exact target; distinguish versions/generations and resource scope.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, serviceDataSettings, returned state, or policy deltas where present; compare old state separately.
timestamp, logNameTiming, owning resource, and audit stream.

What to Investigate

  1. Confirm the observed change and compare it with the approved workflow.
  2. Resolve bucket, object, generation where available, preconditions, actor, approval, and outcome.
  3. Inspect versioning, soft-delete policy at deletion time, retention/holds, and surviving generations or copies.
  4. Correlate actual archive gaps and application failures; distinguish one object deletion from destruction of the entire evidence trail.

Sample Event

Synthetic scenario. The example targets one archive-like object path. It contains no generation, bucket protection configuration, seven-year retention proof, or evidence of permanent loss.

Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.storage.rm invocation-id/90000000000000000000010000001000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T18:01:14.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "storage.googleapis.com",
"methodName": "storage.objects.delete",
"authorizationInfo": [
{
"resource": "projects/_/buckets/fantasticlogs-niffler-archive/objects/events/iam/2026-04-15/draco-actions.json.gz",
"permission": "storage.objects.delete",
"granted": true,
"resourceAttributes": {
"service": "storage.googleapis.com",
"name": "projects/_/buckets/fantasticlogs-niffler-archive/objects/events/iam/2026-04-15/draco-actions.json.gz",
"type": "storage.googleapis.com/Object"
}
}
],
"resourceName": "projects/_/buckets/fantasticlogs-niffler-archive/objects/events/iam/2026-04-15/draco-actions.json.gz",
"resourceLocation": {
"currentLocations": [
"us-central1"
]
}
},
"insertId": "evt010000001000",
"resource": {
"type": "gcs_bucket",
"labels": {
"project_id": "fantasticlogs-prod",
"bucket_name": "fantasticlogs-niffler-archive",
"location": "us-central1"
}
},
"timestamp": "2026-04-15T18:01:14.421987Z",
"severity": "INFO",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
"receiveTimestamp": "2026-04-15T18:01:14.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.