Cloud Storage

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for storage.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNY
storage.anywhereCaches.disableDisables an Anywhere Cache instance.activityNN
storage.anywhereCaches.getReturns the metadata of an Anywhere Cache instance.data_accessNN
storage.anywhereCaches.insertCreates an Anywhere Cache instance.activityNN
storage.anywhereCaches.listReturns a list of Anywhere Cache instances of the bucket matching the criteria.data_accessNN
storage.anywhereCaches.pausePauses an Anywhere Cache instance.activityNN
storage.anywhereCaches.resumeResumes a paused or disabled Anywhere Cache instance.activityNN
storage.anywhereCaches.updateUpdates the config of an Anywhere Cache instance.activityNN
storage.bucketAccessControls.deletePermanently deletes the ACL entry for the specified entity on the specified bucket.activityNN
storage.bucketAccessControls.getReturns the ACL entry for the specified entity on the specified bucket.data_accessNN
storage.bucketAccessControls.insertCreates a new ACL entry on the specified bucket.activityNN
storage.bucketAccessControls.listRetrieves ACL entries on the specified bucket.data_accessNN
storage.bucketAccessControls.patchPatches an ACL entry on the specified bucket.activityNN
storage.bucketAccessControls.updateUpdates an ACL entry on the specified bucket.activityNN
storage.buckets.createCreates a new bucket. IAM audit log methodName (protoPayload.methodName in real Cloud Audit Logs); cf. storage.buckets.insert in the REST discovery doc.activityYN
storage.buckets.deletePermanently deletes an empty bucket.activityYY
storage.buckets.getReturns metadata for the specified bucket.data_accessYN
storage.buckets.getIamPolicyReturns an IAM policy for the specified bucket.data_accessNN
storage.buckets.getStorageLayoutReturns the storage layout configuration for the specified bucket. Note that this operation requires storage.objects.list permission.data_accessYN
storage.buckets.insertCreates a new bucket. Google Cloud Storage uses a flat namespace, so you can't create a bucket with a name that is already in use.activityNY
storage.buckets.listRetrieves a list of buckets for a given project, ordered in the list lexicographically by name.data_accessYY
storage.buckets.listChannelsLists notification channels for the given bucket. Requires ADMIN_READ Data Access logging to be enabled.data_accessNY
storage.buckets.lockRetentionPolicyLocks retention policy on a bucket.activityNN
storage.buckets.operations.advanceRelocateBucketStarts asynchronous advancement of the relocate bucket operation in the case of required write downtime, to allow it to lock the bucket at the source location, and proceed with the bucket location swap. The server makes a best effort to advance the relocate bucket operation, but success is not guaranteed.activityNN
storage.buckets.operations.cancelStarts asynchronous cancellation on a long-running operation. The server makes a best effort to cancel the operation, but success is not guaranteed.activityNN
storage.buckets.operations.getGets the latest state of a long-running operation.data_accessNN
storage.buckets.operations.listLists operations that match the specified filter in the request.data_accessNN
storage.buckets.patchPatches a bucket, changing only the metadata that is specified in the request.activityNY
storage.buckets.relocateInitiates a long-running Relocate Bucket operation on the specified bucket.activityNN
storage.buckets.restoreRestores a soft-deleted bucket.activityNN
storage.buckets.setIamPolicyUpdates an IAM policy for the specified bucket.activityNN
storage.buckets.testIamPermissionsTests a set of permissions on the given bucket to see which, if any, are held by the caller.data_accessYN
storage.buckets.updateUpdates a bucket. Changes to the bucket will be readable immediately after writing, but configuration changes may take time to propagate.activityYY
storage.channels.stopStop watching resources through this channelactivityNN
storage.defaultObjectAccessControls.deletePermanently deletes the default object ACL entry for the specified entity on the specified bucket.activityNN
storage.defaultObjectAccessControls.getReturns the default object ACL entry for the specified entity on the specified bucket.data_accessNN
storage.defaultObjectAccessControls.insertCreates a new default object ACL entry on the specified bucket.activityNN
storage.defaultObjectAccessControls.listRetrieves default object ACL entries on the specified bucket.data_accessNN
storage.defaultObjectAccessControls.patchPatches a default object ACL entry on the specified bucket.activityNN
storage.defaultObjectAccessControls.updateUpdates a default object ACL entry on the specified bucket.activityNN
storage.folders.deletePermanently deletes a folder. Only applicable to buckets with hierarchical namespace enabled.activityNN
storage.folders.deleteRecursiveDeletes a folder recursively. Only applicable to buckets with hierarchical namespace enabled.activityNN
storage.folders.getReturns metadata for the specified folder. Only applicable to buckets with hierarchical namespace enabled.data_accessNN
storage.folders.insertCreates a new folder. Only applicable to buckets with hierarchical namespace enabled.activityNN
storage.folders.listRetrieves a list of folders matching the criteria. Only applicable to buckets with hierarchical namespace enabled.data_accessNN
storage.folders.renameRenames a source folder to a destination folder. Only applicable to buckets with hierarchical namespace enabled.activityNN
storage.hmacKeys.createCreates a new HMAC key for the specified service account.activityYY
storage.hmacKeys.deleteDeletes an HMAC key. The HMAC key must be INACTIVE.activityNY
storage.managedFolders.deletePermanently deletes a managed folder.activityNN
storage.managedFolders.getReturns metadata of the specified managed folder.data_accessNN
storage.managedFolders.getIamPolicyReturns an IAM policy for the specified managed folder.data_accessNN
storage.managedFolders.insertCreates a new managed folder.activityNN
storage.managedFolders.listLists managed folders in the given bucket.data_accessYN
storage.managedFolders.setIamPolicyUpdates an IAM policy for the specified managed folder.activityNN
storage.managedFolders.testIamPermissionsTests a set of permissions on the given managed folder to see which, if any, are held by the caller.data_accessNN
storage.notifications.deletePermanently deletes a notification subscription.activityNN
storage.notifications.getView a notification configuration.data_accessNN
storage.notifications.insertCreates a notification subscription for a given bucket.activityNN
storage.notifications.listRetrieves a list of notification subscriptions for a given bucket.data_accessNN
storage.objectAccessControls.deletePermanently deletes the ACL entry for the specified entity on the specified object.activityNN
storage.objectAccessControls.getReturns the ACL entry for the specified entity on the specified object.data_accessNN
storage.objectAccessControls.insertCreates a new ACL entry on the specified object.activityNN
storage.objectAccessControls.listRetrieves ACL entries on the specified object.data_accessNN
storage.objectAccessControls.patchPatches an ACL entry on the specified object.activityNN
storage.objectAccessControls.updateUpdates an ACL entry on the specified object.activityNN
storage.objects.bulkRestoreInitiates a long-running bulk restore operation on the specified bucket.data_accessNN
storage.objects.composeConcatenates a list of existing objects into a new object in the same bucket.data_accessNN
storage.objects.copyCopies a source object to a destination object. Optionally overrides metadata.data_accessNN
storage.objects.createStores a new object and metadata. IAM audit log methodName (protoPayload.methodName in real Cloud Audit Logs); cf. storage.objects.insert in the REST discovery doc.data_accessYY
storage.objects.deleteDeletes an object and its metadata. Deletions are permanent if versioning is not enabled for the bucket, or if the generation parameter is used.data_accessYY
storage.objects.getRetrieves an object or its metadata.data_accessYY
storage.objects.getIamPolicyReturns an IAM policy for the specified object.data_accessYN
storage.objects.insertStores a new object and metadata.data_accessNN
storage.objects.listRetrieves a list of objects matching the criteria.data_accessYN
storage.objects.moveMoves the source object to the destination object in the same bucket.data_accessNN
storage.objects.patchPatches an object's metadata.data_accessNN
storage.objects.restoreRestores a soft-deleted object.data_accessNN
storage.objects.rewriteRewrites a source object to a destination object. Optionally overrides metadata.data_accessNN
storage.objects.setIamPolicyUpdates an IAM policy for the specified object.activityNN
storage.objects.testIamPermissionsTests a set of permissions on the given object to see which, if any, are held by the caller.data_accessNN
storage.objects.updateUpdates an object's metadata.data_accessNN
storage.objects.watchAllWatch for changes on all objects in a bucket.data_accessNN
storage.projects.hmacKeys.createCreates a new HMAC key for the specified service account.activityNN
storage.projects.hmacKeys.deleteDeletes an HMAC key.activityNN
storage.projects.hmacKeys.getRetrieves an HMAC key's metadatadata_accessNN
storage.projects.hmacKeys.listRetrieves a list of HMAC keys matching the criteria.data_accessNN
storage.projects.hmacKeys.updateUpdates the state of an HMAC key. See the HMAC Key resource descriptor for valid states.activityYN
storage.projects.serviceAccount.getGet the email address of this project's Google Cloud Storage service account.data_accessNN
storage.setIamPermissionsUpdates an IAM policy for the specified bucket. This method appears in Data Access audit logs as an ADMIN_READ entry when the caller reads IAM policies on bucket resources.activityYY
storage.getIamPermissionsTest caller IAM permissions on a Cloud Storage resource.data_accessYN

any: storage.googleapis.com (any method)

#
ServiceName
storage.googleapis.com

Description

Catch-all entry for storage.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • GCP storage hmac keys create source high: There is a feature of Cloud Storage, “interoperability”, that provides a way for Cloud Storage to interact with storage offerings from other cloud providers, like AWS S3. As part of that, there are HMAC keys that can be created for both Service Accounts and regular users. We can escalate Cloud Storage permissions by creating an HMAC key for a higher-privileged Service Account.T1548

storage.anywhereCaches.disable: disable

#
ServiceName
storage.googleapis.com

Description

Disables an Anywhere Cache instance.

storage.anywhereCaches.get: get

#
ServiceName
storage.googleapis.com

Description

Returns the metadata of an Anywhere Cache instance.

Data Access audit logs are disabled by default.

storage.anywhereCaches.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates an Anywhere Cache instance.

storage.anywhereCaches.list: list

#
ServiceName
storage.googleapis.com

Description

Returns a list of Anywhere Cache instances of the bucket matching the criteria.

Data Access audit logs are disabled by default.

storage.anywhereCaches.pause: pause

#
ServiceName
storage.googleapis.com

Description

Pauses an Anywhere Cache instance.

storage.anywhereCaches.resume: resume

#
ServiceName
storage.googleapis.com

Description

Resumes a paused or disabled Anywhere Cache instance.

storage.anywhereCaches.update: update

#
ServiceName
storage.googleapis.com

Description

Updates the config of an Anywhere Cache instance.

storage.bucketAccessControls.delete: delete

#
ServiceName
storage.googleapis.com

Description

Permanently deletes the ACL entry for the specified entity on the specified bucket.

storage.bucketAccessControls.get: get

#
ServiceName
storage.googleapis.com

Description

Returns the ACL entry for the specified entity on the specified bucket.

Data Access audit logs are disabled by default.

storage.bucketAccessControls.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates a new ACL entry on the specified bucket.

storage.bucketAccessControls.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves ACL entries on the specified bucket.

Data Access audit logs are disabled by default.

storage.bucketAccessControls.patch: patch

#
ServiceName
storage.googleapis.com

Description

Patches an ACL entry on the specified bucket.

storage.bucketAccessControls.update: update

#
ServiceName
storage.googleapis.com

Description

Updates an ACL entry on the specified bucket.

storage.buckets.create: Create bucket

#
ServiceName
storage.googleapis.com

Description

Creates a new bucket. IAM audit log methodName (protoPayload.methodName in real Cloud Audit Logs); cf. storage.buckets.insert in the REST discovery doc.

Example Audit Log Entry #

{
  "insertId": "1fq2m5en7xp2",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.create",
        "resource": "projects/_/buckets/dwgen-dw739065",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.buckets.create",
    "request": {
      "defaultObjectAcl": {
        "@type": "type.googleapis.com/google.iam.v1.Policy",
        "bindings": [
          {
            "members": [
              "projectViewer:example-project-id"
            ],
            "role": "roles/storage.legacyObjectReader"
          },
          {
            "members": [
              "projectOwner:example-project-id",
              "projectEditor:example-project-id"
            ],
            "role": "roles/storage.legacyObjectOwner"
          }
        ]
      }
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.buckets.create invocation-id/06996e4c9a3f4d7cae489c4adba1d035 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:37.119225227Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065",
    "serviceData": {
      "@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
      "policyDelta": {
        "bindingDeltas": [
          {
            "action": "ADD",
            "member": "projectEditor:example-project-id",
            "role": "roles/storage.legacyBucketOwner"
          },
          {
            "action": "ADD",
            "member": "projectOwner:example-project-id",
            "role": "roles/storage.legacyBucketOwner"
          },
          {
            "action": "ADD",
            "member": "projectViewer:example-project-id",
            "role": "roles/storage.legacyBucketReader"
          },
          {
            "action": "ADD",
            "member": "projectEditor:example-project-id",
            "role": "roles/storage.legacyObjectOwner"
          },
          {
            "action": "ADD",
            "member": "projectOwner:example-project-id",
            "role": "roles/storage.legacyObjectOwner"
          },
          {
            "action": "ADD",
            "member": "projectViewer:example-project-id",
            "role": "roles/storage.legacyObjectReader"
          }
        ]
      }
    },
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:38.188427788Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:19:37.105685848Z"
}

storage.buckets.delete: Delete bucket

#
ServiceName
storage.googleapis.com

Description

Permanently deletes an empty bucket.

Example Audit Log Entry #

{
  "insertId": "qdhdrveo4f4r",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.delete",
        "resource": "projects/_/buckets/dwbb-dw746783",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.buckets.delete",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.rm invocation-id/2a83a292fc804ae4ac151c538e94b906 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T15:31:49.295616252Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwbb-dw746783",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T15:31:51.056504631Z",
  "resource": {
    "labels": {
      "bucket_name": "dwbb-dw746783",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T15:31:49.282203264Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
severity (panther rule field)neERROR1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • GCP Storage Bucket Deletion source medium: Identifies when a Google Cloud Platform (GCP) storage bucket is deleted. An adversary may delete a storage bucket in order to disrupt their target's business operations.T1485

Panther #

storage.buckets.get: get

#
ServiceName
storage.googleapis.com

Description

Returns metadata for the specified bucket.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "5kkq3ndtxo6",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.get",
        "resource": "projects/_/buckets/dwbk7201353",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.buckets.get",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.buckets.update invocation-id/a60ddbb973f149988990974d6f4ad825 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:25:47.316928986Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwbk7201353",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:25:47.601314520Z",
  "resource": {
    "labels": {
      "bucket_name": "dwbk7201353",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:25:47.304419643Z"
}

storage.buckets.getIamPolicy: getIamPolicy

#
ServiceName
storage.googleapis.com

Description

Returns an IAM policy for the specified bucket.

Data Access audit logs are disabled by default.

storage.buckets.getStorageLayout: getStorageLayout

#
ServiceName
storage.googleapis.com

Description

Returns the storage layout configuration for the specified bucket. Note that this operation requires storage.objects.list permission.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "5afwf7e4s1el",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.objects.list",
        "resource": "projects/_/buckets/dwgen-dw739065",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.buckets.getStorageLayout",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.cp invocation-id/519689db01bc43989c7d3733c4f4a3fa environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:38.988895322Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:39.509751756Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:38.976061163Z"
}

storage.buckets.insert: Insert bucket

#
ServiceName
storage.googleapis.com

Description

Creates a new bucket. Google Cloud Storage uses a flat namespace, so you can't create a bucket with a name that is already in use.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

storage.buckets.list: List buckets

#
ServiceName
storage.googleapis.com

Description

Retrieves a list of buckets for a given project, ordered in the list lexicographically by name.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "m8nnw5e8932z",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.list",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.buckets.list",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.buckets.list invocation-id/b99122866b9342a0a98879bfe01f0225 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:18:03.306892448Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:18:03.849725439Z",
  "resource": {
    "labels": {
      "bucket_name": "",
      "location": "global",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:18:03.297916597Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

storage.buckets.listChannels: List bucket notification channels

#
ServiceName
storage.googleapis.com

Description

Lists notification channels for the given bucket. Requires ADMIN_READ Data Access logging to be enabled.

Data Access audit logs are disabled by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

storage.buckets.lockRetentionPolicy: lockRetentionPolicy

#
ServiceName
storage.googleapis.com

Description

Locks retention policy on a bucket.

storage.buckets.operations.advanceRelocateBucket: advanceRelocateBucket

#
ServiceName
storage.googleapis.com

Description

Starts asynchronous advancement of the relocate bucket operation in the case of required write downtime, to allow it to lock the bucket at the source location, and proceed with the bucket location swap. The server makes a best effort to advance the relocate bucket operation, but success is not guaranteed.

storage.buckets.operations.cancel: cancel

#
ServiceName
storage.googleapis.com

Description

Starts asynchronous cancellation on a long-running operation. The server makes a best effort to cancel the operation, but success is not guaranteed.

storage.buckets.operations.get: get

#
ServiceName
storage.googleapis.com

Description

Gets the latest state of a long-running operation.

Data Access audit logs are disabled by default.

storage.buckets.operations.list: list

#
ServiceName
storage.googleapis.com

Description

Lists operations that match the specified filter in the request.

Data Access audit logs are disabled by default.

storage.buckets.patch: Patch bucket

#
ServiceName
storage.googleapis.com

Description

Patches a bucket, changing only the metadata that is specified in the request.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

storage.buckets.relocate: relocate

#
ServiceName
storage.googleapis.com

Description

Initiates a long-running Relocate Bucket operation on the specified bucket.

storage.buckets.restore: restore

#
ServiceName
storage.googleapis.com

Description

Restores a soft-deleted bucket.

storage.buckets.setIamPolicy: setIamPolicy

#
ServiceName
storage.googleapis.com

Description

Updates an IAM policy for the specified bucket.

storage.buckets.testIamPermissions: testIamPermissions

#
ServiceName
storage.googleapis.com

Description

Tests a set of permissions on the given bucket to see which, if any, are held by the caller.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "status": {},
    "authenticationInfo": {
      "principalEmail": "terraform@anon-terraform-prod.iam.gserviceaccount.com",
      "serviceAccountKeyName": "//iam.googleapis.com/projects/anon-terraform-prod/serviceAccounts/terraform@anon-terraform-prod.iam.gserviceaccount.com/keys/cbf7d9769c83853e97a2dc08240872c54de991f2"
    },
    "requestMetadata": {
      "callerIp": "2600::1",
      "callerSuppliedUserAgent": "apitools Python/3.6.8 gsutil/4.61 (darwin) analytics/enabled interactive/True command/versioning google-cloud-sdk/339.0.0,gzip(gfe)",
      "requestAttributes": {
        "time": "2021-08-19T17:51:31.844550548Z",
        "auth": {}
      },
      "destinationAttributes": {}
    },
    "serviceName": "storage.googleapis.com",
    "methodName": "storage.buckets.update",
    "authorizationInfo": [
      {
        "resource": "projects/_/buckets/s3.anon.net",
        "permission": "storage.buckets.update",
        "granted": true,
        "resourceAttributes": {}
      }
    ],
    "resourceName": "projects/_/buckets/s3.anon.net",
    "request": {
      "bucket": "s3.anon.net",
      "metadata": {
        "versioning": {
          "enabled": true
        },
        "name": "s3.anon.net",
        "id": "s3.anon.net"
      },
      "projection": "NO_ACL"
    },
    "response": {
      "etag": "CAM=",
      "metageneration": "3",
      "storageClass": "STANDARD",
      "updated": "2021-08-19T17:51:31.954Z",
      "timeCreated": "2018-07-20T00:46:43.093Z",
      "id": "s3.anon.net",
      "versioning": {
        "enabled": true
      },
      "iamConfiguration": {
        "uniformBucketLevelAccess": {}
      },
      "projectNumber": "417127842024",
      "name": "s3.anon.net",
      "locationType": "multi-region",
      "location": "US"
    },
    "resourceLocation": {
      "currentLocations": [
        "us"
      ]
    }
  },
  "insertId": "slfn9ddc3sc",
  "resource": {
    "type": "gcs_bucket",
    "labels": {
      "location": "us",
      "bucket_name": "s3.anon.net",
      "project_id": "anon-logs-prod"
    }
  },
  "timestamp": "2021-08-19T17:51:31.834523489Z",
  "severity": "NOTICE",
  "logName": "projects/anon-logs-prod/logs/cloudaudit.googleapis.com%2Factivity",
  "receiveTimestamp": "2021-08-19T17:51:32.286951460Z"
}

References #

storage.buckets.update: Update bucket metadata

#
ServiceName
storage.googleapis.com

Description

Updates a bucket. Changes to the bucket will be readable immediately after writing, but configuration changes may take time to propagate.

Example Audit Log Entry #

{
  "insertId": "k07zn9e7vspr",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.update",
        "resource": "projects/_/buckets/dwg2-dw743447",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.buckets.update",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.buckets.update invocation-id/4a24750fd9ad44c78dccc3cdfca8a382 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:33:58.034563452Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwg2-dw743447",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T14:33:58.853445049Z",
  "resource": {
    "labels": {
      "bucket_name": "dwg2-dw743447",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T14:33:58.020283294Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
severity (panther rule field)neERROR1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Panther #

storage.channels.stop: stop

#
ServiceName
storage.googleapis.com

Description

Stop watching resources through this channel

storage.defaultObjectAccessControls.delete: delete

#
ServiceName
storage.googleapis.com

Description

Permanently deletes the default object ACL entry for the specified entity on the specified bucket.

storage.defaultObjectAccessControls.get: get

#
ServiceName
storage.googleapis.com

Description

Returns the default object ACL entry for the specified entity on the specified bucket.

Data Access audit logs are disabled by default.

storage.defaultObjectAccessControls.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates a new default object ACL entry on the specified bucket.

storage.defaultObjectAccessControls.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves default object ACL entries on the specified bucket.

Data Access audit logs are disabled by default.

storage.defaultObjectAccessControls.patch: patch

#
ServiceName
storage.googleapis.com

Description

Patches a default object ACL entry on the specified bucket.

storage.defaultObjectAccessControls.update: update

#
ServiceName
storage.googleapis.com

Description

Updates a default object ACL entry on the specified bucket.

storage.folders.delete: delete

#
ServiceName
storage.googleapis.com

Description

Permanently deletes a folder. Only applicable to buckets with hierarchical namespace enabled.

storage.folders.deleteRecursive: deleteRecursive

#
ServiceName
storage.googleapis.com

Description

Deletes a folder recursively. Only applicable to buckets with hierarchical namespace enabled.

storage.folders.get: get

#
ServiceName
storage.googleapis.com

Description

Returns metadata for the specified folder. Only applicable to buckets with hierarchical namespace enabled.

Data Access audit logs are disabled by default.

storage.folders.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates a new folder. Only applicable to buckets with hierarchical namespace enabled.

storage.folders.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves a list of folders matching the criteria. Only applicable to buckets with hierarchical namespace enabled.

Data Access audit logs are disabled by default.

storage.folders.rename: rename

#
ServiceName
storage.googleapis.com

Description

Renames a source folder to a destination folder. Only applicable to buckets with hierarchical namespace enabled.

storage.hmacKeys.create: Create HMAC key

#
ServiceName
storage.googleapis.com

Description

Creates a new HMAC key for the specified service account.

Example Audit Log Entry #

{
  "insertId": "hhcr1zcznu",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.hmacKeys.create",
        "resource": "projects/0000004e9ccde496",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.hmacKeys.create",
    "request": {
      "@type": "type.googleapis.com/google.storage.v1.CreateHmacKeyRequest",
      "projectId": "example-project-id",
      "serviceAccountEmail": "dwg2-dw743447@example-project-id.iam.gserviceaccount.com"
    },
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.hmac.create invocation-id/c07d47c22d26463f9405a650dd487217 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T14:34:06.201509721Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "global"
      ]
    },
    "resourceName": "projects/0000004e9ccde496",
    "response": {
      "error": {
        "code": 412,
        "errors": [
          {
            "domain": "global",
            "message": "Request violates constraint 'constraints/iam.disableServiceAccountKeyCreation'",
            "reason": "conditionNotMet"
          }
        ],
        "message": "Request violates constraint 'constraints/iam.disableServiceAccountKeyCreation'"
      }
    },
    "serviceName": "storage.googleapis.com",
    "status": {
      "code": 9
    }
  },
  "receiveTimestamp": "2026-06-29T14:34:06.668010299Z",
  "resource": {
    "labels": {
      "method": "storage.hmacKeys.create",
      "project_id": "example-project-id",
      "service": "storage.googleapis.com"
    },
    "type": "audited_resource"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T14:34:06.192967990Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

storage.hmacKeys.delete: Delete HMAC key

#
ServiceName
storage.googleapis.com

Description

Deletes an HMAC key. The HMAC key must be INACTIVE.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

storage.managedFolders.delete: delete

#
ServiceName
storage.googleapis.com

Description

Permanently deletes a managed folder.

storage.managedFolders.get: get

#
ServiceName
storage.googleapis.com

Description

Returns metadata of the specified managed folder.

Data Access audit logs are disabled by default.

storage.managedFolders.getIamPolicy: getIamPolicy

#
ServiceName
storage.googleapis.com

Description

Returns an IAM policy for the specified managed folder.

Data Access audit logs are disabled by default.

storage.managedFolders.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates a new managed folder.

storage.managedFolders.list: list

#
ServiceName
storage.googleapis.com

Description

Lists managed folders in the given bucket.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "154dnpof1btj1u",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.managedFolders.list",
        "resource": "projects/_/buckets/dwbk7201353",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.managedFolders.list",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.rm invocation-id/1ae75efbd67540c983531af191dfc813 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T16:33:47.385092704Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwbk7201353",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T16:33:47.843796720Z",
  "resource": {
    "labels": {
      "bucket_name": "dwbk7201353",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T16:33:47.371716115Z"
}

storage.managedFolders.setIamPolicy: setIamPolicy

#
ServiceName
storage.googleapis.com

Description

Updates an IAM policy for the specified managed folder.

storage.managedFolders.testIamPermissions: testIamPermissions

#
ServiceName
storage.googleapis.com

Description

Tests a set of permissions on the given managed folder to see which, if any, are held by the caller.

Data Access audit logs are disabled by default.

storage.notifications.delete: delete

#
ServiceName
storage.googleapis.com

Description

Permanently deletes a notification subscription.

storage.notifications.get: get

#
ServiceName
storage.googleapis.com

Description

View a notification configuration.

Data Access audit logs are disabled by default.

storage.notifications.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates a notification subscription for a given bucket.

storage.notifications.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves a list of notification subscriptions for a given bucket.

Data Access audit logs are disabled by default.

storage.objectAccessControls.delete: delete

#
ServiceName
storage.googleapis.com

Description

Permanently deletes the ACL entry for the specified entity on the specified object.

storage.objectAccessControls.get: get

#
ServiceName
storage.googleapis.com

Description

Returns the ACL entry for the specified entity on the specified object.

Data Access audit logs are disabled by default.

storage.objectAccessControls.insert: insert

#
ServiceName
storage.googleapis.com

Description

Creates a new ACL entry on the specified object.

storage.objectAccessControls.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves ACL entries on the specified object.

Data Access audit logs are disabled by default.

storage.objectAccessControls.patch: patch

#
ServiceName
storage.googleapis.com

Description

Patches an ACL entry on the specified object.

storage.objectAccessControls.update: update

#
ServiceName
storage.googleapis.com

Description

Updates an ACL entry on the specified object.

storage.objects.bulkRestore: bulkRestore

#
ServiceName
storage.googleapis.com

Description

Initiates a long-running bulk restore operation on the specified bucket.

Data Access audit logs are disabled by default.

storage.objects.compose: compose

#
ServiceName
storage.googleapis.com

Description

Concatenates a list of existing objects into a new object in the same bucket.

Data Access audit logs are disabled by default.

storage.objects.copy: copy

#
ServiceName
storage.googleapis.com

Description

Copies a source object to a destination object. Optionally overrides metadata.

Data Access audit logs are disabled by default.

storage.objects.create: Create object

#
ServiceName
storage.googleapis.com

Description

Stores a new object and metadata. IAM audit log methodName (protoPayload.methodName in real Cloud Audit Logs); cf. storage.objects.insert in the REST discovery doc.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "jge554eho6ix",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.objects.create",
        "resource": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
        "resourceAttributes": {}
      },
      {
        "granted": true,
        "permission": "storage.objects.delete",
        "resource": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.objects.create",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.cp invocation-id/519689db01bc43989c7d3733c4f4a3fa environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:39.197798952Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
    "serviceData": {
      "@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
      "policyDelta": {}
    },
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:39.893714225Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:39.189281833Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.methodName (panther rule field)eqstorage.objects.create2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • GCP GCS Bulk Object Rewrite Operation source medium: Detects GCS object rewrite operations which may indicate ransomware operations attempting to rewrite data in the same bucket with an attacker-controlled encryption key. Attackers with compromised credentials can use gsutil rewrite commands to replace existing encryption keys on cloud storage objects, effectively encrypting data for ransom. This detection focuses on identifying suspicious re-encryption activity through the 'gsutil rewrite -k' command patterns in user agent strings, with a threshold of 10 events.T1486, T1530, T1537
  • GCP GCS Ransom Note Upload source high: Detects when a file with a name matching common ransomware note patterns is uploaded to a Google Cloud Storage bucket. Ransomware attackers often leave ransom notes with distinctive filenames to provide victims with payment instructions.T1486

References #

storage.objects.delete: delete

#
ServiceName
storage.googleapis.com

Description

Deletes an object and its metadata. Deletions are permanent if versioning is not enabled for the bucket, or if the generation parameter is used.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "103wau4e1497e",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.objects.delete",
        "resource": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.objects.delete",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.rm invocation-id/d1d29b688e534a399fcfc99fa1d6528a environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:44.996837356Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:45.340029100Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:44.985966559Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
severity (panther rule field)neERROR1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • GCP GCS Bulk Object Deletion source medium: Detects bulk deletion of GCS objects. This pattern is indicative of a ransomware attack or data destruction where an adversary deletes storage objects at scale. The threshold of 10+ deletion operations suggests automated bulk deletion rather than normal application behavior. This can be part of a double extortion ransomware attack where data is both encrypted and deleted to increase pressure on victims.T1485

storage.objects.get: get

#
ServiceName
storage.googleapis.com

Description

Retrieves an object or its metadata.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "15cghlge4w876",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.objects.get",
        "resource": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.objects.get",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.cp invocation-id/519689db01bc43989c7d3733c4f4a3fa environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:38.699617694Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065/objects/sample.txt",
    "serviceName": "storage.googleapis.com",
    "status": {
      "code": 5,
      "message": "No such object: dwgen-dw739065/sample.txt"
    }
  },
  "receiveTimestamp": "2026-06-29T13:19:39.916606155Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "ERROR",
  "timestamp": "2026-06-29T13:19:38.687248185Z"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • GCP GCS Object Copied to Different Bucket source medium: Detects when GCS objects are copied from one bucket to a bucket in a different GCP project. Cross-project copies are more suspicious than same-project copies and can indicate data exfiltration where an adversary copies sensitive data to a project they control. The threshold of 50+ copy operations suggests bulk exfiltration rather than normal operations. This is detected by monitoring storage.objects.get operations that include a destination field in the metadata, indicating a copy operation.T1537

storage.objects.getIamPolicy: getIamPolicy

#
ServiceName
storage.googleapis.com

Description

Returns an IAM policy for the specified object.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "status": {},
    "authenticationInfo": {
      "principalEmail": "user@domain.com"
    },
    "requestMetadata": {
      "callerIp": "8.8.8.8",
      "callerSuppliedUserAgent": "apitools Python/3.6.8 gsutil/4.67 (darwin) analytics/enabled interactive/True command/cp google-cloud-sdk/356.0.0,gzip(gfe)",
      "requestAttributes": {
        "time": "2021-09-13T03:03:08.926017323Z",
        "auth": {}
      },
      "destinationAttributes": {}
    },
    "serviceName": "storage.googleapis.com",
    "methodName": "storage.objects.list",
    "authorizationInfo": [
      {
        "resource": "projects/_/buckets/scc-export-sample",
        "permission": "storage.objects.list",
        "granted": true,
        "resourceAttributes": {}
      }
    ],
    "resourceName": "projects/_/buckets/scc-export-sample",
    "resourceLocation": {
      "currentLocations": [
        "us"
      ]
    }
  },
  "insertId": "-kj1h22dqg3c",
  "resource": {
    "type": "gcs_bucket",
    "labels": {
      "bucket_name": "scc-export-sample",
      "project_id": "gsec-monitoring-prod",
      "location": "us"
    }
  },
  "timestamp": "2021-09-13T03:03:08.918318174Z",
  "severity": "INFO",
  "logName": "projects/gsec-monitoring-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
  "receiveTimestamp": "2021-09-13T03:03:09.951986944Z"
}

References #

storage.objects.insert: insert

#
ServiceName
storage.googleapis.com

Description

Stores a new object and metadata.

Data Access audit logs are disabled by default.

storage.objects.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves a list of objects matching the criteria.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "ypn38te16foq",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.objects.list",
        "resource": "projects/_/buckets/dwgen-dw739065",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.objects.list",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.cp invocation-id/519689db01bc43989c7d3733c4f4a3fa environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:38.778444902Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:39.766422812Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:38.767033086Z"
}

storage.objects.move: move

#
ServiceName
storage.googleapis.com

Description

Moves the source object to the destination object in the same bucket.

Data Access audit logs are disabled by default.

storage.objects.patch: patch

#
ServiceName
storage.googleapis.com

Description

Patches an object's metadata.

Data Access audit logs are disabled by default.

storage.objects.restore: restore

#
ServiceName
storage.googleapis.com

Description

Restores a soft-deleted object.

Data Access audit logs are disabled by default.

storage.objects.rewrite: rewrite

#
ServiceName
storage.googleapis.com

Description

Rewrites a source object to a destination object. Optionally overrides metadata.

Data Access audit logs are disabled by default.

storage.objects.setIamPolicy: setIamPolicy

#
ServiceName
storage.googleapis.com

Description

Updates an IAM policy for the specified object.

storage.objects.testIamPermissions: testIamPermissions

#
ServiceName
storage.googleapis.com

Description

Tests a set of permissions on the given object to see which, if any, are held by the caller.

Data Access audit logs are disabled by default.

storage.objects.update: update

#
ServiceName
storage.googleapis.com

Description

Updates an object's metadata.

Data Access audit logs are disabled by default.

storage.objects.watchAll: watchAll

#
ServiceName
storage.googleapis.com

Description

Watch for changes on all objects in a bucket.

Data Access audit logs are disabled by default.

storage.projects.hmacKeys.create: create

#
ServiceName
storage.googleapis.com

Description

Creates a new HMAC key for the specified service account.

storage.projects.hmacKeys.delete: delete

#
ServiceName
storage.googleapis.com

Description

Deletes an HMAC key.

storage.projects.hmacKeys.get: get

#
ServiceName
storage.googleapis.com

Description

Retrieves an HMAC key's metadata

Data Access audit logs are disabled by default.

storage.projects.hmacKeys.list: list

#
ServiceName
storage.googleapis.com

Description

Retrieves a list of HMAC keys matching the criteria.

Data Access audit logs are disabled by default.

storage.projects.hmacKeys.update: update

#
ServiceName
storage.googleapis.com

Description

Updates the state of an HMAC key. See the HMAC Key resource descriptor for valid states.

Example Audit Log Entry #

{
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "status": {},
    "authenticationInfo": {
      "principalEmail": "user@organization.com"
    },
    "requestMetadata": {
      "callerIp": "8.8.8.8",
      "callerSuppliedUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36,gzip(gfe)",
      "requestAttributes": {
        "time": "2021-08-17T17:27:22.981337412Z",
        "auth": {}
      },
      "destinationAttributes": {}
    },
    "serviceName": "storage.googleapis.com",
    "methodName": "storage.setIamPermissions",
    "authorizationInfo": [
      {
        "resource": "projects/_/buckets/sample-logs-org",
        "permission": "storage.buckets.setIamPolicy",
        "granted": true,
        "resourceAttributes": {}
      }
    ],
    "resourceName": "projects/_/buckets/sample-logs-org",
    "serviceData": {
      "@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
      "policyDelta": {
        "bindingDeltas": [
          {
            "action": "ADD",
            "role": "roles/storage.admin",
            "member": "user:user@organization.com"
          }
        ]
      }
    },
    "request": {
      "iamRequest": {
        "resource": "projects/_/buckets/sample-logs-org",
        "policy": {
          "etag": "CAY=",
          "bindings": [
            {
              "role": "roles/storage.admin",
              "members": [
                "serviceAccount:o793924137099-000712@gcp-sa-logging.iam.gserviceaccount.com",
                "user:user@organization.com"
              ]
            },
            {
              "members": [
                "projectEditor:sample-logs-prod",
                "projectOwner:sample-logs-prod"
              ],
              "role": "roles/storage.legacyBucketOwner"
            },
            {
              "members": [
                "projectViewer:sample-logs-prod"
              ],
              "role": "roles/storage.legacyBucketReader"
            },
            {
              "members": [
                "serviceAccount:service-417127842024@cloud-cdn-fill.iam.gserviceaccount.com",
                "user:anon@organization.com"
              ],
              "role": "roles/storage.objectViewer"
            }
          ],
          "version": 3
        }
      }
    },
    "response": {
      "etag": "CAc=",
      "version": 1,
      "bindings": [
        {
          "role": "roles/storage.admin",
          "members": [
            "serviceAccount:o793924137099-000712@gcp-sa-logging.iam.gserviceaccount.com",
            "user:user@organization.com"
          ]
        },
        {
          "role": "roles/storage.legacyBucketOwner",
          "members": [
            "projectEditor:sample-logs-prod",
            "projectOwner:sample-logs-prod"
          ]
        },
        {
          "role": "roles/storage.legacyBucketReader",
          "members": [
            "projectViewer:sample-logs-prod"
          ]
        },
        {
          "members": [
            "serviceAccount:service-417127842024@cloud-cdn-fill.iam.gserviceaccount.com",
            "user:anon@organization.com"
          ],
          "role": "roles/storage.objectViewer"
        }
      ]
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    }
  },
  "insertId": "xl5g0ceapu9i",
  "resource": {
    "type": "gcs_bucket",
    "labels": {
      "project_id": "sample-logs-prod",
      "bucket_name": "sample-logs-org",
      "location": "us-central1"
    }
  },
  "timestamp": "2021-08-17T17:27:22.975758523Z",
  "severity": "NOTICE",
  "logName": "projects/sample-logs-prod/logs/cloudaudit.googleapis.com%2Factivity",
  "receiveTimestamp": "2021-08-17T17:27:23.425872134Z"
}

References #

storage.projects.serviceAccount.get: get

#
ServiceName
storage.googleapis.com

Description

Get the email address of this project's Google Cloud Storage service account.

Data Access audit logs are disabled by default.

storage.setIamPermissions: Set IAM permissions on bucket

#
ServiceName
storage.googleapis.com

Description

Updates an IAM policy for the specified bucket. This method appears in Data Access audit logs as an ADMIN_READ entry when the caller reads IAM policies on bucket resources.

Example Audit Log Entry #

{
  "insertId": "29eei5eeapla",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.setIamPolicy",
        "resource": "projects/_/buckets/dwgen-dw739065",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.setIamPermissions",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.buckets.add-iam-policy-binding invocation-id/9d864b7794df4637a8361d6754dde9c0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:43.216372131Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065",
    "serviceData": {
      "@type": "type.googleapis.com/google.iam.v1.logging.AuditData",
      "policyDelta": {
        "bindingDeltas": [
          {
            "action": "ADD",
            "member": "serviceAccount:dwgen-dw739065@example-project-id.iam.gserviceaccount.com",
            "role": "roles/storage.objectViewer"
          }
        ]
      }
    },
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:44.701728298Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "NOTICE",
  "timestamp": "2026-06-29T13:19:43.204756132Z"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.methodName (panther rule field)eqstorage.setIamPermissions2 rulespanther
action (splunk rule field)eqadd1 rulesplunk
protoPayload.serviceData (panther rule field)is_not_null1 rulepanther
protoPayload.serviceData.policyDelta.bindingDeltas (panther rule field)is_not_null1 rulepanther
target.resource.attribute.labels["ser_binding_deltas_action"] (Chronicle)eqADD1 rulechronicle

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • GCP Storage Bucket Permissions Modification source medium: Identifies when the Identity and Access Management (IAM) permissions are modified for a Google Cloud Platform (GCP) storage bucket. An adversary may modify the permissions on a storage bucket to weaken their target's security controls or an administrator may inadvertently modify the permissions, which could lead to data exposure or loss.T1098, T1098.003, T1222

Splunk #

  • Detect New Open GCP Storage Buckets source: The following analytic identifies the creation of new open/public GCP Storage buckets. It leverages GCP PubSub events, specifically monitoring for the storage.setIamPermissions method and checks if the allUsers member is added. This…T1530

Kusto #

  • GCP Audit Logs - Storage Bucket Made Public source high: Detects when a Google Cloud Storage bucket is made publicly accessible by granting permissions to allUsers or allAuthenticatedUsers. Making buckets public can expose sensitive data to unauthorized access and may indicate a misconfiguration or malicious activity. Adversaries may make buckets public to exfiltrate data or as part of a data exposure attack. This rule monitors setIamPermissions operations that add public access roles to storage buckets.T1078, T1078.004, T1530, T1567, T1567.002

YARA-L #

Panther #

storage.getIamPermissions: getIamPermissions

#
ServiceName
storage.googleapis.com

Description

Test caller IAM permissions on a Cloud Storage resource.

Data Access audit logs are disabled by default.

Example Audit Log Entry #

{
  "insertId": "ztzeb3f1ebajd",
  "logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
  "protoPayload": {
    "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
    "authenticationInfo": {
      "oauthInfo": {
        "oauthClientId": "32555940559.apps.googleusercontent.com"
      },
      "principalEmail": "user@example.com"
    },
    "authorizationInfo": [
      {
        "granted": true,
        "permission": "storage.buckets.getIamPolicy",
        "resource": "projects/_/buckets/dwgen-dw739065",
        "resourceAttributes": {}
      }
    ],
    "methodName": "storage.getIamPermissions",
    "requestMetadata": {
      "callerIp": "203.0.113.10",
      "callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.storage.buckets.add-iam-policy-binding invocation-id/9d864b7794df4637a8361d6754dde9c0 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color  (Linux 6.1.0-41-amd64),gzip(gfe)",
      "destinationAttributes": {},
      "requestAttributes": {
        "auth": {},
        "time": "2026-06-29T13:19:43.038040091Z"
      }
    },
    "resourceLocation": {
      "currentLocations": [
        "us-central1"
      ]
    },
    "resourceName": "projects/_/buckets/dwgen-dw739065",
    "serviceName": "storage.googleapis.com",
    "status": {}
  },
  "receiveTimestamp": "2026-06-29T13:19:43.596886079Z",
  "resource": {
    "labels": {
      "bucket_name": "dwgen-dw739065",
      "location": "us-central1",
      "project_id": "example-project-id"
    },
    "type": "gcs_bucket"
  },
  "severity": "INFO",
  "timestamp": "2026-06-29T13:19:43.022114612Z"
}