compute.firewalls.patch
compute.firewalls.patch
Event
Updates selected properties of an existing VPC firewall rule. A request allowing TCP ports 22 and 443 from 0.0.0.0/0 warrants review, but the previous configuration and effective targets are needed to establish a widening of access.
Security Context
Unauthorized weakening of a firewall can support T1686.001. Omitted PATCH properties are not evidence that target restrictions were removed. Other applicable policies, priorities, network paths, and workload listeners affect reachability. The API method does not establish attacker intent or lower detection likelihood.
Log Source
Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.firewalls.patch. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Principal, delegation where present, caller context, and request timing. |
protoPayload.methodName, resourceName | Exact service method and target resource. |
protoPayload.authorizationInfo | Recorded permission checks; granted does not establish operation completion. |
protoPayload.request, response, metadata | Requested settings and available operation/delta details; presence and serialization vary. |
operation.id, first, last; protoPayload.status | Correlate start/completion records and inspect errors. |
protoPayload.response.status, error | RUNNING is incomplete; DONE must still be checked for operation errors. |
What to Investigate
- Confirm the actor, target, timing, and outcome against the approved change.
- Compare submitted properties with the prior and resulting rule, including target selectors, network, priority, disabled state, and direction.
- Determine affected workloads and effective firewall-policy evaluation; verify routing, external paths, and listening services.
- Inspect final operation status/errors and connection evidence. Establish unauthorized use separately from a configuration request.
Sample Event
Synthetic scenario. The sample requests an ingress allow configuration for TCP 22/443 from all IPv4 addresses. It contains no old source range or proof of reachable SSH. The request is normalized to REST property names, including allowed; this does not establish native audit-log serialization.
Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.firewall-rules.update invocation-id/90000000000000000000001111101011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T14:11:09.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "compute.googleapis.com", "methodName": "v1.compute.firewalls.patch", "authorizationInfo": [ { "permission": "compute.firewalls.update", "granted": true, "resourceAttributes": { "service": "compute", "name": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress", "type": "compute.firewalls" } }, { "permission": "compute.networks.updatePolicy", "granted": true, "resourceAttributes": { "service": "compute", "name": "projects/fantasticlogs-prod/global/networks/default", "type": "compute.networks" } } ], "resourceName": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress", "request": { "name": "billywig-public-ingress", "sourceRanges": [ "0.0.0.0/0" ], "direction": "INGRESS", "priority": 1000, "allowed": [ { "IPProtocol": "tcp", "ports": [ "22", "443" ] } ] }, "response": { "@type": "type.googleapis.com/operation", "id": "8200000000000000021", "name": "operation-1776265869000-62fa224b3a201-ab001011-cd001011", "operationType": "patch", "targetId": "6100000000000000010", "targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress", "selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/operations/operation-1776265869000-62fa224b3a201-ab001011-cd001011", "user": "draco@fantasticlogs.cloud", "status": "RUNNING", "progress": 0, "insertTime": "2026-04-15T07:11:09.301-07:00", "startTime": "2026-04-15T07:11:09.318-07:00" }, "resourceLocation": { "currentLocations": [ "global" ] } }, "insertId": "evt001111101011", "resource": { "type": "gce_firewall_rule", "labels": { "project_id": "fantasticlogs-prod", "firewall_rule_id": "6100000000000000010" } }, "timestamp": "2026-04-15T14:11:09.550000000Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "operation": { "id": "operation-1776265869000-62fa224b3a201-ab001011-cd001011", "producer": "compute.googleapis.com", "first": true }, "receiveTimestamp": "2026-04-15T14:11:09.567890123Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.