Skip to content

compute.firewalls.patch

GCP

compute.firewalls.patch

service: GCP - Compute Engine
techniques:

Event

Updates selected properties of an existing VPC firewall rule. A request allowing TCP ports 22 and 443 from 0.0.0.0/0 warrants review, but the previous configuration and effective targets are needed to establish a widening of access.

Security Context

Unauthorized weakening of a firewall can support T1686.001. Omitted PATCH properties are not evidence that target restrictions were removed. Other applicable policies, priorities, network paths, and workload listeners affect reachability. The API method does not establish attacker intent or lower detection likelihood.

Log Source

Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.firewalls.patch. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataPrincipal, delegation where present, caller context, and request timing.
protoPayload.methodName, resourceNameExact service method and target resource.
protoPayload.authorizationInfoRecorded permission checks; granted does not establish operation completion.
protoPayload.request, response, metadataRequested settings and available operation/delta details; presence and serialization vary.
operation.id, first, last; protoPayload.statusCorrelate start/completion records and inspect errors.
protoPayload.response.status, errorRUNNING is incomplete; DONE must still be checked for operation errors.

What to Investigate

  1. Confirm the actor, target, timing, and outcome against the approved change.
  2. Compare submitted properties with the prior and resulting rule, including target selectors, network, priority, disabled state, and direction.
  3. Determine affected workloads and effective firewall-policy evaluation; verify routing, external paths, and listening services.
  4. Inspect final operation status/errors and connection evidence. Establish unauthorized use separately from a configuration request.

Sample Event

Synthetic scenario. The sample requests an ingress allow configuration for TCP 22/443 from all IPv4 addresses. It contains no old source range or proof of reachable SSH. The request is normalized to REST property names, including allowed; this does not establish native audit-log serialization.

Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.firewall-rules.update invocation-id/90000000000000000000001111101011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T14:11:09.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.firewalls.patch",
"authorizationInfo": [
{
"permission": "compute.firewalls.update",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress",
"type": "compute.firewalls"
}
},
{
"permission": "compute.networks.updatePolicy",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/global/networks/default",
"type": "compute.networks"
}
}
],
"resourceName": "projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress",
"request": {
"name": "billywig-public-ingress",
"sourceRanges": [
"0.0.0.0/0"
],
"direction": "INGRESS",
"priority": 1000,
"allowed": [
{
"IPProtocol": "tcp",
"ports": [
"22",
"443"
]
}
]
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "8200000000000000021",
"name": "operation-1776265869000-62fa224b3a201-ab001011-cd001011",
"operationType": "patch",
"targetId": "6100000000000000010",
"targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/firewalls/billywig-public-ingress",
"selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/operations/operation-1776265869000-62fa224b3a201-ab001011-cd001011",
"user": "draco@fantasticlogs.cloud",
"status": "RUNNING",
"progress": 0,
"insertTime": "2026-04-15T07:11:09.301-07:00",
"startTime": "2026-04-15T07:11:09.318-07:00"
},
"resourceLocation": {
"currentLocations": [
"global"
]
}
},
"insertId": "evt001111101011",
"resource": {
"type": "gce_firewall_rule",
"labels": {
"project_id": "fantasticlogs-prod",
"firewall_rule_id": "6100000000000000010"
}
},
"timestamp": "2026-04-15T14:11:09.550000000Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operation-1776265869000-62fa224b3a201-ab001011-cd001011",
"producer": "compute.googleapis.com",
"first": true
},
"receiveTimestamp": "2026-04-15T14:11:09.567890123Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.