compute.projects.setCommonInstanceMetadata
compute.projects.setCommonInstanceMetadata
Event
Sets the project metadata collection using a fingerprint for concurrency control. Project SSH keys can apply across eligible VMs, but instance settings and the guest environment determine their effect.
Security Context
Unauthorized authorized-key changes can support persistence (T1098.004). OS Login and block-project-ssh-keys can prevent project metadata keys from authorizing SSH. Reachability, a working guest agent, key validity, and guest authentication still matter; this event does not prove lateral movement.
Log Source
Cloud Audit Logs: compute.googleapis.com, method v1.compute.projects.setCommonInstanceMetadata. Admin Activity. This operation.first/RUNNING record does not prove completion; correlate final status/errors.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Compare the complete metadata before and after the change, preserving entries that should remain.
- Identify VMs accepting project SSH keys; check effective OS Login, block-project-ssh-keys, guest configuration, and network access.
- Follow the operation to completion, inspect errors, and correlate guest key changes and SSH logins.
Sample Event
Synthetic scenario. The example starts a project metadata update and illustrates ssh-keys as an added metadata property. No key value, appended key entry, prior custom-role grant, or successful login is shown. The metadata delta wrapper is unverified; universal request redaction is not assumed.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.project-info.add-metadata invocation-id/90000000000000000000001111101110 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:14:51.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "compute.googleapis.com", "methodName": "v1.compute.projects.setCommonInstanceMetadata", "authorizationInfo": [ { "permission": "compute.projects.setCommonInstanceMetadata", "granted": true, "resourceAttributes": { "service": "compute", "name": "projects/fantasticlogs-prod", "type": "compute.projects" } } ], "resourceName": "projects/fantasticlogs-prod", "request": { "@type": "type.googleapis.com/compute.projects.setCommonInstanceMetadata" }, "response": { "@type": "type.googleapis.com/operation", "id": "8200000000000000030", "name": "operation-1776269691000-62fa30c92e201-ab001110-cd001110", "operationType": "setMetadata", "targetId": "555123456789", "targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod", "selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/global/operations/operation-1776269691000-62fa30c92e201-ab001110-cd001110", "user": "draco@fantasticlogs.cloud", "status": "RUNNING", "progress": 0, "insertTime": "2026-04-15T08:14:51.301-07:00", "startTime": "2026-04-15T08:14:51.318-07:00" }, "metadata": { "@type": "type.googleapis.com/google.cloud.audit.GceProjectAuditMetadata", "commonInstanceMetadataDelta": { "addedMetadataKeys": [ "ssh-keys" ] } }, "resourceLocation": { "currentLocations": [ "global" ] } }, "insertId": "evt001111101110", "resource": { "type": "gce_project", "labels": { "project_id": "fantasticlogs-prod" } }, "timestamp": "2026-04-15T15:14:51.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "operation": { "id": "operation-1776269691000-62fa30c92e201-ab001110-cd001110", "producer": "compute.googleapis.com", "first": true }, "receiveTimestamp": "2026-04-15T15:14:51.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...