storage.objects.delete
storage.objects.delete
Event
Object deletion behavior depends on the selected generation, Object Versioning, and soft-delete policy. Retention requirements and holds can prevent deletion; lack of versioning alone does not establish irrecoverable loss.
Security Context
Unauthorized deletion can cause T1485 impact. Determine whether a noncurrent version, soft-deleted object, or independent copy survives. An archive-like object name does not establish contents, retention guarantees, or prior exfiltration.
Log Source
Cloud Audit Logs: storage.googleapis.com, method storage.objects.delete. Data Access (DATA_WRITE). Enable the relevant service/category at project, folder, or organization scope and check exemptions, routing, retention, and viewer access. Optional request/response detail depends on logging configuration; the minimal sample is not the only supported shape.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Effective caller, delegation where present, and request context. |
protoPayload.methodName, resourceName | Operation and exact target; distinguish versions/generations and resource scope. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, serviceData | Settings, returned state, or policy deltas where present; compare old state separately. |
timestamp, logName | Timing, owning resource, and audit stream. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Resolve bucket, object, generation where available, preconditions, actor, approval, and outcome.
- Inspect versioning, soft-delete policy at deletion time, retention/holds, and surviving generations or copies.
- Correlate actual archive gaps and application failures; distinguish one object deletion from destruction of the entire evidence trail.
Sample Event
Synthetic scenario. The example targets one archive-like object path. It contains no generation, bucket protection configuration, seven-year retention proof, or evidence of permanent loss.
Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.storage.rm invocation-id/90000000000000000000010000001000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T18:01:14.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "storage.googleapis.com", "methodName": "storage.objects.delete", "authorizationInfo": [ { "resource": "projects/_/buckets/fantasticlogs-niffler-archive/objects/events/iam/2026-04-15/draco-actions.json.gz", "permission": "storage.objects.delete", "granted": true, "resourceAttributes": { "service": "storage.googleapis.com", "name": "projects/_/buckets/fantasticlogs-niffler-archive/objects/events/iam/2026-04-15/draco-actions.json.gz", "type": "storage.googleapis.com/Object" } } ], "resourceName": "projects/_/buckets/fantasticlogs-niffler-archive/objects/events/iam/2026-04-15/draco-actions.json.gz", "resourceLocation": { "currentLocations": [ "us-central1" ] } }, "insertId": "evt010000001000", "resource": { "type": "gcs_bucket", "labels": { "project_id": "fantasticlogs-prod", "bucket_name": "fantasticlogs-niffler-archive", "location": "us-central1" } }, "timestamp": "2026-04-15T18:01:14.421987Z", "severity": "INFO", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "receiveTimestamp": "2026-04-15T18:01:14.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...