compute.instances.setMetadata
compute.instances.setMetadata
Event
Sets the instance metadata collection, which can include SSH keys and startup configuration. The API uses a metadata fingerprint for concurrency control; clients must preserve existing entries they intend to retain.
Security Context
Unauthorized SSH authorized-key changes can support persistence (T1098.004) when metadata-based SSH is effective. OS Login-enabled VMs do not accept SSH keys stored in metadata. Guest configuration, key validity, network access, and authentication outcomes matter. A metadata update alone does not prove SSH lateral movement or bypass of monitoring.
Log Source
Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.instances.setMetadata. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Principal, delegation where present, caller context, and request timing. |
protoPayload.methodName, resourceName | Exact service method and target resource. |
protoPayload.authorizationInfo | Recorded permission checks; granted does not establish operation completion. |
protoPayload.request, response, metadata | Requested settings and available operation/delta details; presence and serialization vary. |
operation.id, first, last; protoPayload.status | Correlate start/completion records and inspect errors. |
protoPayload.response.status, error | RUNNING is incomplete; DONE must still be checked for operation errors. |
What to Investigate
- Confirm the actor, target, timing, and outcome against the approved change.
- Compare complete old/new metadata and fingerprint; distinguish adding the ssh-keys metadata property from appending an authorized key within its value.
- Check effective instance/project OS Login settings, guest environment, key usernames/expiry, and relevant organization policies.
- Correlate final operation outcome with guest key propagation and SSH authentication. Investigate startup configuration separately if it changed.
Sample Event
Synthetic scenario. The illustrative delta lists ssh-keys as an added metadata property; it does not expose a key value, prove a key was appended to an existing list, or show a login. The GceInstanceAuditMetadata wrapper and delta serialization remain unverified against a captured record. No universal metadata-value redaction rule is assumed.
Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.instances.add-metadata invocation-id/90000000000000000000000000000011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:03:48.448112233Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "compute.googleapis.com", "methodName": "v1.compute.instances.setMetadata", "authorizationInfo": [ { "permission": "compute.instances.setMetadata", "granted": true, "resourceAttributes": { "service": "compute", "name": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001", "type": "compute.instances" } } ], "resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001", "request": { "@type": "type.googleapis.com/compute.instances.setMetadata" }, "response": { "@type": "type.googleapis.com/operation", "id": "8200000000000000023", "name": "operation-1776267828000-62fa20a8c0011-ab000011-cd000011", "operationType": "setMetadata", "targetId": "6100000000000000011", "targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001", "selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/operations/operation-1776267828000-62fa20a8c0011-ab000011-cd000011", "user": "draco@fantasticlogs.cloud", "status": "RUNNING", "progress": 0, "zone": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a", "insertTime": "2026-04-15T08:03:48.501-07:00", "startTime": "2026-04-15T08:03:48.519-07:00" }, "metadata": { "@type": "type.googleapis.com/google.cloud.audit.GceInstanceAuditMetadata", "instanceMetadataDelta": { "addedMetadataKeys": [ "ssh-keys" ] } }, "resourceLocation": { "currentLocations": [ "us-central1-a" ] } }, "insertId": "evt0000000011", "resource": { "type": "gce_instance", "labels": { "project_id": "fantasticlogs-prod", "instance_id": "6100000000000000011", "zone": "us-central1-a" } }, "timestamp": "2026-04-15T15:03:48.600000000Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "operation": { "id": "operation-1776267828000-62fa20a8c0011-ab000011-cd000011", "producer": "compute.googleapis.com", "first": true }, "receiveTimestamp": "2026-04-15T15:03:48.778899001Z"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...