Skip to content

compute.projects.setCommonInstanceMetadata

GCP

compute.projects.setCommonInstanceMetadata

service: GCP - Compute Engine
tactics:
techniques:

Event

Sets the project metadata collection using a fingerprint for concurrency control. Project SSH keys can apply across eligible VMs, but instance settings and the guest environment determine their effect.

Security Context

Unauthorized authorized-key changes can support persistence (T1098.004). OS Login and block-project-ssh-keys can prevent project metadata keys from authorizing SSH. Reachability, a working guest agent, key validity, and guest authentication still matter; this event does not prove lateral movement.

Log Source

Cloud Audit Logs: compute.googleapis.com, method v1.compute.projects.setCommonInstanceMetadata. Admin Activity. This operation.first/RUNNING record does not prove completion; correlate final status/errors.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Compare the complete metadata before and after the change, preserving entries that should remain.
  3. Identify VMs accepting project SSH keys; check effective OS Login, block-project-ssh-keys, guest configuration, and network access.
  4. Follow the operation to completion, inspect errors, and correlate guest key changes and SSH logins.

Sample Event

Synthetic scenario. The example starts a project metadata update and illustrates ssh-keys as an added metadata property. No key value, appended key entry, prior custom-role grant, or successful login is shown. The metadata delta wrapper is unverified; universal request redaction is not assumed.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.project-info.add-metadata invocation-id/90000000000000000000001111101110 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T15:14:51.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.projects.setCommonInstanceMetadata",
"authorizationInfo": [
{
"permission": "compute.projects.setCommonInstanceMetadata",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod",
"type": "compute.projects"
}
}
],
"resourceName": "projects/fantasticlogs-prod",
"request": {
"@type": "type.googleapis.com/compute.projects.setCommonInstanceMetadata"
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "8200000000000000030",
"name": "operation-1776269691000-62fa30c92e201-ab001110-cd001110",
"operationType": "setMetadata",
"targetId": "555123456789",
"targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod",
"selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/operations/operation-1776269691000-62fa30c92e201-ab001110-cd001110",
"user": "draco@fantasticlogs.cloud",
"status": "RUNNING",
"progress": 0,
"insertTime": "2026-04-15T08:14:51.301-07:00",
"startTime": "2026-04-15T08:14:51.318-07:00"
},
"metadata": {
"@type": "type.googleapis.com/google.cloud.audit.GceProjectAuditMetadata",
"commonInstanceMetadataDelta": {
"addedMetadataKeys": [
"ssh-keys"
]
}
},
"resourceLocation": {
"currentLocations": [
"global"
]
}
},
"insertId": "evt001111101110",
"resource": {
"type": "gce_project",
"labels": {
"project_id": "fantasticlogs-prod"
}
},
"timestamp": "2026-04-15T15:14:51.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operation-1776269691000-62fa30c92e201-ab001110-cd001110",
"producer": "compute.googleapis.com",
"first": true
},
"receiveTimestamp": "2026-04-15T15:14:51.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.