Skip to content

compute.instances.setMetadata

GCP

compute.instances.setMetadata

service: GCP - Compute Engine
tactics:
techniques:

Event

Sets the instance metadata collection, which can include SSH keys and startup configuration. The API uses a metadata fingerprint for concurrency control; clients must preserve existing entries they intend to retain.

Security Context

Unauthorized SSH authorized-key changes can support persistence (T1098.004) when metadata-based SSH is effective. OS Login-enabled VMs do not accept SSH keys stored in metadata. Guest configuration, key validity, network access, and authentication outcomes matter. A metadata update alone does not prove SSH lateral movement or bypass of monitoring.

Log Source

Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.instances.setMetadata. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataPrincipal, delegation where present, caller context, and request timing.
protoPayload.methodName, resourceNameExact service method and target resource.
protoPayload.authorizationInfoRecorded permission checks; granted does not establish operation completion.
protoPayload.request, response, metadataRequested settings and available operation/delta details; presence and serialization vary.
operation.id, first, last; protoPayload.statusCorrelate start/completion records and inspect errors.
protoPayload.response.status, errorRUNNING is incomplete; DONE must still be checked for operation errors.

What to Investigate

  1. Confirm the actor, target, timing, and outcome against the approved change.
  2. Compare complete old/new metadata and fingerprint; distinguish adding the ssh-keys metadata property from appending an authorized key within its value.
  3. Check effective instance/project OS Login settings, guest environment, key usernames/expiry, and relevant organization policies.
  4. Correlate final operation outcome with guest key propagation and SSH authentication. Investigate startup configuration separately if it changed.

Sample Event

Synthetic scenario. The illustrative delta lists ssh-keys as an added metadata property; it does not expose a key value, prove a key was appended to an existing list, or show a login. The GceInstanceAuditMetadata wrapper and delta serialization remain unverified against a captured record. No universal metadata-value redaction rule is assumed.

Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.instances.add-metadata invocation-id/90000000000000000000000000000011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T15:03:48.448112233Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.instances.setMetadata",
"authorizationInfo": [
{
"permission": "compute.instances.setMetadata",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001",
"type": "compute.instances"
}
}
],
"resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001",
"request": {
"@type": "type.googleapis.com/compute.instances.setMetadata"
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "8200000000000000023",
"name": "operation-1776267828000-62fa20a8c0011-ab000011-cd000011",
"operationType": "setMetadata",
"targetId": "6100000000000000011",
"targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001",
"selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/operations/operation-1776267828000-62fa20a8c0011-ab000011-cd000011",
"user": "draco@fantasticlogs.cloud",
"status": "RUNNING",
"progress": 0,
"zone": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a",
"insertTime": "2026-04-15T08:03:48.501-07:00",
"startTime": "2026-04-15T08:03:48.519-07:00"
},
"metadata": {
"@type": "type.googleapis.com/google.cloud.audit.GceInstanceAuditMetadata",
"instanceMetadataDelta": {
"addedMetadataKeys": [
"ssh-keys"
]
}
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
}
},
"insertId": "evt0000000011",
"resource": {
"type": "gce_instance",
"labels": {
"project_id": "fantasticlogs-prod",
"instance_id": "6100000000000000011",
"zone": "us-central1-a"
}
},
"timestamp": "2026-04-15T15:03:48.600000000Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operation-1776267828000-62fa20a8c0011-ab000011-cd000011",
"producer": "compute.googleapis.com",
"first": true
},
"receiveTimestamp": "2026-04-15T15:03:48.778899001Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.